Splunk Cloud Certified Admin Exam Study Guide (SPLK-1005)

Splunk-Cloud-Certified-Admin

Splunk Cloud Certified Admin (SPLK-1005) Preparation Details

The Splunk Cloud Certified Admin (SPLK-1005) exam tests your ability to configure inputs, forwarders, indexes, and users within a Splunk Cloud Platform deployment. This guide maps every domain and skill from the official exam blueprint to verified Splunk documentation so you can study each topic in order. You can also explore more Splunk certification study guides on the Splunk Certifications to keep building your skills.

Splunk Cloud Certified Admin Materials

CourseraSplunk 9.x Enterprise Certified Admin Guide
UdemySplunk Cloud Certified Admin

1.0 Splunk Cloud Overview 5%

1.1 Describe Cloud topology

Splunk Cloud Platform Service Details

Welcome to the Splunk Cloud Platform Admin Manual

Topology components

1.2 Describe tasks managed by the Splunk cloud administrator

Welcome to the Splunk Cloud Platform Admin Manual

Introduction to the Cloud Monitoring Console

Splunk Cloud Platform Service Details

1.3 List the primary differences between Splunk Cloud and Splunk Enterprise

Splunk Cloud Platform Service Details

Welcome to the Splunk Cloud Platform Admin Manual

1.4 List differences between Self-Service Cloud and Managed Cloud

Splunk Cloud Platform Service Details

Welcome to the Splunk Cloud Platform Admin Manual

2.0 Index Management 5%

2.1 Define a Splunk index

Manage Splunk Cloud Platform indexes

2.2 Create indexes in cloud

Manage Splunk Cloud Platform indexes

2.3 Delete data from an index

Manage Splunk Cloud Platform indexes

2.4 Monitor indexing activities

Introduction to the Cloud Monitoring Console

Use the monitoring console to view indexing performance

Manage Splunk Cloud Platform indexes

3.0 User Authentication and Authorization 5%

3.1 Administer Splunk user roles

About users and roles

3.2 Integrate Splunk with LDAP, Active Directory, or SAML

Set up user authentication with LDAP

Configure single sign-on with SAML

4.0 Splunk Configuration Files 5%

4.1 Review Splunk configuration files and directories

Configuration file precedence

List of configuration files

4.2 Review configuration file precedence

Configuration file precedence

4.3 Review index and search time processes

Index time versus search time

5.0 Getting Data in Cloud 15%

5.1 List Splunk forwarder types

Types of forwarders

5.2 Describe the role of forwarders

About forwarding and receiving

Types of forwarders

5.3 Configure a forwarder to Splunk Cloud

How to forward data to Splunk Cloud Platform

Install and configure the Splunk Cloud Platform universal forwarder credentials package

5.4 Test the forwarder connection

Troubleshoot forwarder/receiver connection

5.5 Describe optional forwarder settings

Configure forwarders with outputs.conf

6.0 Forwarder Management 5%

6.1 Describe Splunk Deployment Server

About deployment server and forwarder management

6.2 Explain the use of forwarder management

About deployment server and forwarder management

6.3 Configure forwarders to be deployment clients

Configure deployment clients

6.4 Managing forwarders using deployment apps

Create deployment apps

Deploy apps to clients

7.0 Monitor Inputs 15%

7.1 Describe the Splunk process for inputting data

How Splunk Enterprise handles your data

Overview of event processing

7.2 Create file and directory monitor inputs

Monitor files and directories

Monitor files and directories with inputs.conf

7.3 Use optional settings for monitor inputs

Monitor files and directories with inputs.conf

inputs.conf

8.0 Network and Other Inputs 10%

8.1 Create network (TCP and UDP) inputs

Get data from TCP and UDP ports

8.2 Create a basic scripted input

Get data from APIs and other remote data interfaces through scripted inputs

8.3 Describe optional settings for network inputs

Get data from TCP and UDP ports

inputs.conf

8.4 Identify Windows input types and uses

Monitor Windows data with the Splunk platform

Monitor Windows event log data with Splunk Cloud Platform

8.5 Use the HTTP Event Collector (HEC) to get data into Splunk

Set up and use HTTP Event Collector in Splunk Web

Format events for HTTP Event Collector

9.0 Fine-tuning Inputs 5%

9.1 Describe the default processing that occurs during the input phase

Overview of event processing

How Splunk Enterprise handles your data

9.2 Configure input phase options, such as sourcetype fine-tuning and character set encoding

Configure character set encoding

Configure rule-based source type recognition

10.0 Parsing Phase and Data Preview 10%

10.1 Describe the default processing that occurs during parsing

Overview of event processing

Index time versus search time

10.2 Optimize and configure event line breaking

Configure event line breaking

10.3 Explain how timestamps and time zones are extracted or assigned to events

Configure timestamp recognition

Specify time zones for timestamps

10.4 Use Data Preview to validate event creation during the parsing phase

Prepare your data for preview

11.0 Manipulating Raw Data 10%

11.1 Explain how data transformations are defined and invoked

transforms.conf

11.2 Use transformations with props.conf and transforms.conf to modify raw data

transforms.conf

Anonymize data

11.3 Use SEDCMD to modify raw data

Anonymize data

12.0 Installing and Managing Apps 5%

12.1 Review the process for installing apps

Install apps on your Splunk Cloud Platform deployment

12.2 Describe private apps

Manage private apps on your Splunk Cloud Platform deployment

12.3 Describe how apps are managed

Manage app and add-on objects

Install apps on your Splunk Cloud Platform deployment

13.0 Working with Splunk Cloud Support 5%

13.1 Isolate problems before contacting Splunk Cloud Support

What’s in the Troubleshooting Manual?

Generate a diagnostic file

13.2 Define the process for working with Splunk Cloud Support

Contact Support

How to file a great Support case

Wrapping Up Splunk Cloud Certified Admin

This guide walked through all 13 domains of the Splunk Cloud Certified Admin (SPLK-1005) blueprint, from cloud topology and index management through forwarders, inputs, parsing, and Support case handling. Working through each linked topic in order will build the practical administration skills the exam expects. You can also explore more Splunk certification study guides on the Splunk Certifications to keep building your skills. Have a question or tip? Leave a comment below.

Receive Updates on Splunk Cloud Certified Admin Exam


Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.

Share the Splunk Cloud Certified Admin Study Guide in Your Network

You may also like

Leave a Reply

Your email address will not be published. Required fields are marked *