Splunk Enterprise Certified Admin Exam Study Guide

Splunk-Enterprise-Certified-Admin

Splunk Enterprise Certified Admin Preparation Details

The Splunk Enterprise Certified Admin exam validates your ability to configure, monitor, and manage a Splunk Enterprise deployment in production environments. This guide walks through every domain in the official exam blueprint, from licensing and configuration files to distributed search and data onboarding.

Each objective below is paired with official Splunk documentation so you can study the exact concepts the exam covers. Whether you are preparing to administer a standalone instance or a distributed cluster, this reference will help you build a systematic study plan.

You can also explore more Splunk certification study guides on the Splunk category to keep building your skills.

Splunk Enterprise Certified Admin Materials

CourseraSplunk 9.x Enterprise Certified Admin Guide
UdemyThe Complete Splunk Enterprise Certified Admin Course
WhizlabsSplunk Basics Training Course

1.0 Splunk Admin Basics 5%

1.1 Identify Splunk components

Components of a Splunk Enterprise deployment

Components and the data pipeline

Splexicon:Component

2.0 License Management 5%

2.1 Identify license types

Types of Splunk Enterprise licenses

2.2 Understand license violations

About license violations

3.0 Splunk Configuration Files 5%

3.1 Describe Splunk configuration directory structure

Configuration file directories

3.2 Understand configuration layering

Configuration file precedence

3.3 Understand configuration precedence

Configuration file precedence

3.4 Use btool to examine configuration settings

Use btool to troubleshoot configurations

4.0 Splunk Indexes 10%

4.1 Describe index structure

How the indexer stores indexes

4.2 List types of index buckets

Buckets and indexer clusters

4.3 Check index data integrity

Manage data integrity

4.4 Describe indexes.conf options

indexes.conf

4.5 Describe the fishbucket

Splexicon:Fishbucket

4.6 Apply a data retention policy

Set a retirement and archiving policy

5.0 Splunk User Management 5%

5.1 Describe user roles in Splunk

About users and roles

5.2 Create a custom role

Create and manage roles with Splunk Web

5.3 Add Splunk users

Create and manage users with Splunk Web

6.0 Splunk Authentication Management 5%

6.1 Integrate Splunk with LDAP

Set up user authentication with LDAP

6.2 List other user authentication options

About user authentication

6.3 Describe the steps to enable multifactor authentication in Splunk

About multifactor authentication with Duo Security

7.0 Getting Data In 5%

7.1 Describe the basic settings for an input

inputs.conf

7.2 List Splunk forwarder types

Types of forwarders

7.3 Configure the forwarder

Configure forwarding with outputs.conf

7.4 Add an input to UF using CLI

Monitor files and directories with inputs.conf

8.0 Distributed Search 10%

8.1 Describe how distributed search works

About distributed search

8.2 Explain the roles of the search head and search peers

About distributed search

8.3 Configure a distributed search group

Create distributed search groups

8.4 List search head scaling options

About distributed search

9.0 Getting Data In – Staging 5%

9.1 List the three phases of the Splunk Indexing process

How data moves through Splunk deployments: The data pipeline

How indexing works

9.2 List Splunk input options

Getting started with getting data in

10.0 Configuring Forwarders 5%

10.1 Configure Forwarders

Configure the universal forwarder using configuration files

10.2 Identify additional Forwarder options

Configure forwarding with outputs.conf

11.0 Forwarder Management 10%

11.1 Explain the use of deployment management

About deployment server and forwarder management

11.2 Describe Splunk Deployment Server

About deployment server and forwarder management

11.3 Manage forwarders using deployment apps

Forwarder management overview

11.4 Configure deployment clients

Configure deployment clients

11.5 Configure client groups

Forwarder management overview

11.6 Monitor forwarder management activities

Forwarder management overview

12.0 Monitor Inputs 5%

12.1 Create file and directory monitor inputs

Monitor files and directories with inputs.conf

12.2 Use optional settings for monitor inputs

Monitor files and directories with inputs.conf

inputs.conf

12.3 Deploy a remote monitor input

Forwarder management overview

13.0 Network and Scripted Inputs 5%

13.1 Create network (TCP and UDP) inputs

Get data from TCP and UDP ports

13.2 Describe optional settings for network inputs

Get data from TCP and UDP ports

13.3 Create a basic scripted input

Get data from APIs and other remote data interfaces through scripted inputs

14.0 Agentless Inputs 5%

14.1 Creating Windows Management Instrumentation (WMI) inputs

Monitor data through Windows Management Instrumentation (WMI)

14.2 Describe HTTP Event Collector

Set up and use HTTP Event Collector in Splunk Web

15.0 Fine Tuning Inputs 5%

15.1 Understand the default processing that occurs during input phase

How data moves through Splunk deployments: The data pipeline

15.2 Configure input phase options, such as sourcetype fine-tuning and character set encoding

props.conf

Getting started with getting data in

16.0 Parsing Phase and Data 5%

16.1 Understand the default processing that occurs during parsing

How data moves through Splunk deployments: The data pipeline

16.2 Optimize and configure event line breaking

Configure event line breaking

16.3 Explain how timestamps and time zones are extracted or assigned to events

Configure timestamp recognition

16.4 Use Data Preview to validate event creation during the parsing phase

Prepare your data for preview

17.0 Manipulating Raw Data 5%

17.1 Explain how data transformations are defined and invoked

transforms.conf

props.conf

17.2 Use transformations with props.conf and transforms.conf to:

Mask or delete raw data as it is being indexed

Anonymize data

Override sourcetype or host based upon event values

Override source types on a per-event basis

Route events to specific indexes based on event content

Route and filter data

Prevent unwanted events from being indexed

Route and filter data

17.3 Use SEDCMD to modify raw data

Anonymize data

props.conf

Wrapping Up Splunk Enterprise Certified Admin

This guide covered every domain in the Splunk Enterprise Certified Admin blueprint, from licensing and configuration files through distributed search and raw data manipulation. Working through the linked documentation for each objective will give you a solid, hands-on foundation for the exam.

You can also explore more Splunk certification study guides on the Splunk category to keep building your skills. Have a question or tip? Leave a comment below.

Receive Updates on Splunk Enterprise Certified Admin Exam


Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.

Share the Splunk Enterprise Certified Admin Study Guide in Your Network

You may also like

Leave a Reply

Your email address will not be published. Required fields are marked *