Splunk SOAR Certified Automation Developer Preparation Details
The Splunk SOAR Certified Automation Developer exam validates your ability to install, configure, and administer a SOAR deployment while building and debugging playbooks. This legacy, professional-level exam covers deployment, case management, the Visual Playbook Editor, custom coding, and REST API integration across 18 domains. Candidates preparing for this exam should be comfortable working across both Splunk SOAR (On-premises) and Splunk SOAR (Cloud) documentation, since concepts and terminology overlap between the two products. You can also explore more Splunk certification study guides on the Splunk Certification category to keep building your skills.
Splunk SOAR Certified Automation Developer Materials
1.0 Deployment, Installation, and Initial Configuration 5%
1.1 Describe SOAR operating concepts
Splunk SOAR (Cloud) introduction
1.2 Identify documentation and community resources
Splunk SOAR Certified Automation Developer
1.3 Identify installation and upgrade options
How can Splunk SOAR (On-premises) be installed?
Splunk SOAR (On-premises) upgrade overview and prerequisites
Upgrade a Splunk SOAR (On-premises) instance
Upgrade a Splunk SOAR (On-premises) cluster
1.4 Describe SOAR architecture
About Splunk SOAR (On-premises)
1.5 Configure licenses, administration, and product settings
Obtain and configure a Splunk SOAR (On-premises) license
View your Splunk SOAR (Cloud) license
Manage dashboard widgets in Splunk SOAR (On-premises)
2.0 User Management 5%
2.1 Configure authentication options
Configure single sign-on authentication for Splunk SOAR (On-premises)
Configure single sign-on authentication for Splunk SOAR (Cloud)
2.2 Add users
Manage Splunk SOAR (On-premises) users
Manage Splunk SOAR (Cloud) users
2.3 Add roles
Manage roles and permissions in Splunk SOAR (On-premises)
Manage roles and permissions in Splunk SOAR (Cloud)
3.0 Apps, Assets, and Playbooks 5%
3.1 Configure apps
Configure or upgrade the service with Splunk App for SOAR
Install Splunk App for SOAR on Splunk Enterprise
3.2 Configure assets
Add and configure apps and assets to provide actions in Splunk SOAR (Cloud)
Assess app and asset connectivity and ingestion
3.3 Configure data ingestion assets
View how much data is ingested in Splunk SOAR (Cloud) using ingestion summary
View ingested container statistics using Ingestion Status
Add and configure apps and assets to provide actions in Splunk SOAR (On-premises)
3.4 Configure labels and SLAs
Configure labels to apply to containers
Create custom severity names and control severity inheritance
3.5 Manage playbooks
Use playbooks to automate analyst workflows in Splunk SOAR (Cloud)
Write better playbooks by following these guidelines
Create a new playbook in Splunk SOAR (On-premises)
4.0 Analyst Queue 5%
4.1 Use the Analyst Queue
Start with Investigation in Splunk SOAR (On-premises)
4.2 Use search features
Search within Splunk SOAR (On-premises)
Configure search in Splunk SOAR (On-premises)
4.3 Create filters
Filter indicator records in Splunk SOAR (On-premises)
Search within Splunk SOAR (On-premises)
4.4 Use the indicator view
Filter indicator records in Splunk SOAR (Cloud)
Create custom CEF fields in Splunk SOAR (Cloud)
5.0 The Investigation Page 10%
5.1 Use the Investigation page to work on events
Start with Investigation in Splunk SOAR (On-premises)
Start with Investigation in Splunk SOAR (Cloud)
5.2 Manually run actions and examine action results
Add an action block to your Splunk SOAR (Cloud) playbook
5.3 Manually run playbooks
Start with Investigation in Splunk SOAR (On-premises)
Use playbooks to automate analyst workflows in Splunk SOAR (Cloud)
5.4 Use the file tab to store related files
Mark files and events as evidence in Splunk SOAR (Cloud)
Mark files and events as evidence in Splunk SOAR (On-premises)
6.0 Case Management and Workbooks 5%
6.1 Use case management for complex investigations
Create cases in Splunk SOAR (Cloud)
Understanding SOAR case management features
6.2 Use workbooks
Define a workflow in a case using workbooks in Splunk SOAR (Cloud)
6.3 Mark items as evidence
Mark files and events as evidence in Splunk SOAR (Cloud)
Create case reports to download and share in Splunk SOAR (Cloud)
7.0 Customizations 5%
7.1 Customize severity levels
Create custom severity names and control severity inheritance
Create custom severity names and control severity inheritance
7.2 Customize CEF fields
Create custom CEF fields in Splunk SOAR (On-premises)
Create custom CEF fields in Splunk SOAR (Cloud)
7.3 Customize status values
Create custom status labels in Splunk SOAR (Cloud)
7.4 Customize workbooks
Define a workflow in a case using workbooks in Splunk SOAR (Cloud)
7.5 Add global custom fields to containers
Create custom fields to filter Splunk SOAR (Cloud) events
Configure labels to apply to containers
8.0 System Maintenance 5%
8.1 Run reports
Create Executive Summary reports and view all reports in Splunk SOAR (On-premises)
Create Executive Summary reports and view all reports in Splunk SOAR (Cloud)
Create case reports to download and share in Splunk SOAR (Cloud)
8.2 Use system health displays
Monitor the health of your Splunk SOAR (On-premises) system
Monitor the health of your Splunk SOAR (Cloud) system
8.3 Examine health logs
Learn about the Splunk System Logs in SOAR in Splunk App for SOAR
About the Content Pack for SOAR System Logs
9.0 Introduction to Playbooks 5%
9.1 Understand automation best practices
Write better playbooks by following these guidelines
Use playbooks to automate analyst workflows in Splunk SOAR (Cloud)
9.2 Describe playbook capabilities
Use playbooks to automate analyst workflows in Splunk SOAR (On-premises)
Splunk SOAR Visual Playbook Editor Data Sheet
9.3 Determine available app actions
Add an action block to your Splunk SOAR (Cloud) playbook
Add and configure apps and assets to provide actions in Splunk SOAR (Cloud)
9.4 Use I2A2 design methodology
Investigating Incidents with Splunk SOAR
Write better playbooks by following these guidelines
10.0 Visual Playbook Editor 5%
10.1 Use the visual playbook editor
Create a new playbook in Splunk SOAR (On-premises)
Use keyboard shortcuts in the playbook editor
Use playbooks to automate analyst workflows in Splunk SOAR (Cloud)
10.2 Execute actions from a playbook
Add an action block to your Splunk SOAR (Cloud) playbook
Add a new block to your Splunk SOAR (Cloud) playbook
10.3 Test new playbooks
Debug playbooks in Splunk SOAR (Cloud)
Use keyboard shortcuts in the playbook editor
11.0 Logic, Filters, and User Interaction 5%
11.1 Use decision blocks
Use decisions to send artifacts to a specific downstream action in your Splunk SOAR (Cloud) playbook
11.2 Use filter blocks to process data
Use filters in your Splunk SOAR (Cloud) playbook to specify a subset of artifacts
Use filters in your Splunk SOAR (On-premises) playbook to specify a subset of artifacts
11.3 Describe the use of different join options
Run other playbooks inside your playbook in Splunk SOAR (Cloud)
11.4 Interact with users during playbook execution
Require user input using the Prompt block in your Splunk SOAR (Cloud) playbook
Require user input using the Prompt block in your Splunk SOAR (On-premises) playbook
12.0 Formatted Output and Data Access 5%
12.1 Use Format blocks to structure data
Customize the format of your Splunk SOAR (Cloud) playbook content
Customize the format of your Splunk SOAR (On-premises) playbook content
12.2 Understand the structure of action results
12.3 Compose datapaths to access data
12.4 Use the utility block to modify containers
Add functionality to your playbook in Splunk SOAR (Cloud) using the Utility block
13.0 Modular Playbook Development 5%
13.1 Design modular solutions with interacting playbooks
Run other playbooks inside your playbook in Splunk SOAR (Cloud)
13.2 Invoke child playbooks from a parent
Run other playbooks inside your playbook in Splunk SOAR (On-premises)
13.3 Exchange data between playbooks
Add functionality to your playbook in Splunk SOAR (On-premises) using the Utility block
Write better playbooks by following these guidelines
14.0 Custom Lists and Data Routing 5%
14.1 Create custom lists
Create custom lists for use in Splunk SOAR (On-premises) playbook comparisons
Create custom lists for use in Splunk SOAR (Cloud) playbook comparisons
14.2 Access lists from playbooks
Create custom lists for use in Splunk SOAR (On-premises) playbooks
Create custom lists for use in Splunk SOAR (Cloud) playbooks
14.3 Use filters to control data flow
Use filters in your Splunk SOAR (Cloud) playbook to specify a subset of artifacts
15.0 Configuring External Splunk Search 5%
15.1 Describe the benefits of externalizing search to Splunk
Configure search in Splunk SOAR (On-premises)
Configure search in Splunk SOAR (Cloud)
15.2 Configure the SOAR instance for externalization
Configure search in Splunk SOAR (Cloud)
15.3 Configure the Splunk instance for externalization
Configure a Splunk asset in Splunk SOAR to pull data from the Splunk platform
15.4 Use reindex to push existing content to the Splunk instance
The Splunk platform as a SOAR data source
15.5 Use the Splunk app for Phantom Reporting
About Splunk App for SOAR Export
Learn about the Splunk System Logs in SOAR in Splunk App for SOAR
16.0 Integrating SOAR into Splunk 10%
16.1 Install the Splunk App for SOAR Export
Install the Splunk App for SOAR Export on Splunk Enterprise
Check prerequisites for Splunk App for SOAR Export on Splunk Cloud Platform
16.2 Send Enterprise Security notables to SOAR
Connect Splunk App for SOAR Export and the Splunk Platform to Splunk SOAR
About Splunk App for SOAR Export
16.3 Install and configure the Splunk app in SOAR
Configure a Splunk asset in Splunk SOAR to pull data from the Splunk platform
Configure or upgrade the service with Splunk App for SOAR
16.4 Use Splunk search from playbooks
Add an action block to your Splunk SOAR (Cloud) playbook
17.0 Custom Coding 5%
17.1 Describe when and when not to use the global block
Add custom code to your Splunk SOAR (Cloud) playbook with the code block
Add custom code to your Splunk SOAR (On-premises) playbook with the code block
17.2 Use custom function blocks
Add custom code to your Splunk SOAR (Cloud) playbook with a custom function
Add custom code to your Splunk SOAR (On-premises) playbook with a custom function
17.3 Write and test custom SOAR code
Write better playbooks by following these guidelines
Debug playbooks in Splunk SOAR (Cloud)
18.0 Using REST 5%
18.1 Describe the capabilities of SOAR REST API
Using the REST API reference for Splunk SOAR (On-premises)
Using the REST API reference for Splunk SOAR (Cloud)
18.2 Use Django queries to search for data in SOAR
Use REST handlers to allow external services to call into Splunk SOAR
18.3 Use SOAR REST from other systems to access SOAR data
Use REST handlers to allow external services to call into Splunk SOAR (On-premises)
Using the REST API reference for Splunk SOAR (On-premises)
Wrapping Up Splunk SOAR Certified Automation Developer
This guide maps every domain of the Splunk SOAR Certified Automation Developer blueprint, from initial deployment through REST API integration, to official Splunk SOAR documentation. Working through each objective in order builds a practical foundation in playbook design, case management, and system administration. Use the linked materials alongside hands-on practice in a SOAR instance to reinforce what you learn. You can also explore more Splunk certification study guides on the Splunk Certification category to keep building your skills. Have a question or tip? Leave a comment below.
Receive Updates on Splunk SOAR Certified Automation Developer Exam
Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.