Splunk Enterprise Certified Architect Study Guide (SPLK-2002)

Splunk-Enterprise-Certified-Architect

Splunk Enterprise Certified Architect Preparation Details

The Splunk Enterprise Certified Architect (SPLK-2002) exam validates expert-level skills in planning, deploying, and troubleshooting large-scale, clustered Splunk Enterprise deployments. Candidates are tested on capacity planning, clustering, forwarder design, and performance tuning. This guide maps every domain to current Splunk documentation. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills.

Splunk Enterprise Certified Architect Materials

CourseraSplunk Administration & Performance Optimization
UdemySPLK-2002: Splunk Enterprise Certified Architect Exam

1.0 Introduction 2%

1.1 Describe a deployment plan

Components of a Splunk Enterprise deployment

Deployment topologies

Introduction to capacity planning for Splunk Enterprise

1.2 Define the deployment process

About deployment server and forwarder management

Forwarder deployment topologies

Deployment topologies

2.0 Project Requirements 5%

2.1 Identify critical information about environment, volume, users, and requirements

Introduction to capacity planning for Splunk Enterprise

Reference hardware

Components of a Splunk Enterprise deployment

2.2 Apply checklists and resources to aid in collecting requirements

Estimate your storage requirements

Reference hardware

Deployment topologies

3.0 Infrastructure Planning: Index Design 5%

3.1 Understand design and size indexes

About managing indexes

How indexing works

Estimate your storage requirements

3.2 Estimate non-smart store related storage requirements

Estimate your storage requirements

About SmartStore

Configure index storage

3.3 Identify relevant apps

Apps and add-ons

Where to get more apps and add-ons

Update common peer configurations and apps

4.0 Infrastructure Planning: Resource Planning 7%

4.1 List sizing considerations

Introduction to capacity planning for Splunk Enterprise

Reference hardware

Estimate your storage requirements

4.2 Identify disk storage requirements

Estimate your storage requirements

Reference hardware

Configure index storage

4.3 Define hardware requirements for various Splunk components

Reference hardware

Components of a Splunk Enterprise deployment

Universal forwarder deployment prerequisites

4.4 Describe ES considerations for sizing and topology

Considerations for scaling deployments

Deployment considerations for Splunk Enterprise Security

Reference hardware

4.5 Describe ITSI considerations for sizing and topology

Plan your ITSI deployment

Introduction to capacity planning for Splunk Enterprise

Reference hardware

4.6 Describe security, privacy, and integrity measures

About securing Splunk Enterprise

More ways to secure Splunk Enterprise

5.0 Clustering Overview 5%

5.1 Identify non-smart store related storage and disk usage requirements

About indexer clusters and index replication

Estimate your storage requirements

Configure index storage

5.2 Identify search head clustering requirements

About search head clustering

Reference hardware

Deploy a search head cluster

6.0 Forwarder and Deployment Best Practices 6%

6.1 Identify best practices for forwarder tier design

Forwarder deployment topologies

About the universal forwarder

Intermediate data routing using universal and heavy forwarders

6.2 Understand configuration management for all Splunk components, using Splunk deployment tools

About deployment server and forwarder management

Update common peer configurations and apps

Manage common configurations across all peers

7.0 Performance Monitoring and Tuning 5%

7.1 Use limits.conf to improve performance

limits.conf

Write better searches

7.2 Use indexes.conf to manage bucket size

indexes.conf

Configure index storage

7.3 Tune props.conf

props.conf

7.4 Improve search performance

Write better searches

View search job properties

8.0 Splunk Troubleshooting Methods and Tools 5%

8.1 Splunk diagnostic resources and tools

Use btool to troubleshoot configurations

Generate a diagnostic file

Introduction to troubleshooting Splunk Enterprise

What Splunk software logs about itself

9.0 Clarifying the Problem 5%

9.1 Identify Splunk’s internal log files

What Splunk software logs about itself

About access logs

9.2 Identify Splunk’s internal indexes

How indexing works

About managing indexes

10.0 Licensing and Crash Problems 5%

10.1 License issues

About license violations

Configure a license manager

10.2 Crash issues

What Splunk software logs about itself

Introduction to troubleshooting Splunk Enterprise

Advanced help troubleshooting Splunk software for Windows

11.0 Configuration Problems 5%

11.1 Input issues

Troubleshoot the input process

I can’t find my data!

Use btool to troubleshoot configurations

12.0 Search Problems 5%

12.1 Search issues

I can’t find my data!

Write better searches

12.2 Job inspector

View search job properties

13.0 Deployment Problems 5%

13.1 Forwarding issues

Troubleshoot forwarder/receiver connection

Troubleshoot the universal forwarder

13.2 Deployment server issues

Troubleshoot performance issues

About deployment server and forwarder management

14.0 Large-scale Splunk Deployment Overview 5%

14.1 Identify Splunk server roles in clusters

About indexer clusters and index replication

About search head clustering

Components of a Splunk Enterprise deployment

14.2 License Master configuration in a clustered environment

Configure a license manager

Configure a license peer

15.0 Single-site Indexer Cluster 5%

15.1 Splunk single-site indexer cluster configuration

Enable the peer nodes

Add a peer to the cluster

Peer node configuration overview

16.0 Multisite Indexer Cluster 5%

16.1 Splunk multisite indexer cluster overview

Multisite indexer cluster deployment overview

Multisite indexer clusters

16.2 Multisite indexer cluster configuration

Configure multisite indexer clusters with server.conf

Configure multisite indexer clusters with the CLI

16.3 Cluster migration and upgrade considerations

Migrate an indexer cluster from single-site to multisite

17.0 Indexer Cluster Management and Administration 7%

17.1 Indexer cluster storage utilization options

About SmartStore

Indexer cluster operations and SmartStore

Configure SmartStore

17.2 Peer offline and decommission

Take a peer offline

17.3 Master app bundles

Update common peer configurations and apps

Manage common configurations across all peers

17.4 Monitoring Console for indexer cluster environment

Use the monitoring console to view indexer cluster status

Indexing: Indexer Clustering: Status

Indexing: Indexer Clustering: Service Activity

18.0 Search Head Cluster 5%

18.1 Splunk search head cluster overview

About search head clustering

Search head clustering architecture

18.2 Search head cluster configuration

Deploy a search head cluster

19.0 Search Head Cluster Management and Administration 5%

19.1 Search head cluster deployer

Deploy a search head cluster

19.2 Captaincy transfer

Control captaincy

19.3 Search head member addition and decommissioning

Add a cluster member

Remove a cluster member

20.0 KV Store Collection and Lookup Management 3%

20.1 KV Store collection in Splunk clusters

About the app key value store

Configure KV Store lookups

Back up and restore KV store

Wrapping Up Splunk Enterprise Certified Architect

This guide covered every domain of the Splunk Enterprise Certified Architect (SPLK-2002) blueprint, from deployment planning and index design through indexer and search head clustering, performance tuning, and troubleshooting. Use the linked documentation to build hands-on familiarity with each objective before exam day. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills. Have a question or tip? Leave a comment below.

Receive Updates on Splunk Enterprise Certified Architect Exam


Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.

Share the Splunk Enterprise Certified Architect Study Guide in Your Network

You may also like

Leave a Reply

Your email address will not be published. Required fields are marked *