Splunk Enterprise Certified Admin Preparation Details
The Splunk Enterprise Certified Admin exam validates your ability to configure, monitor, and manage a Splunk Enterprise deployment in production environments. This guide walks through every domain in the official exam blueprint, from licensing and configuration files to distributed search and data onboarding.
Each objective below is paired with official Splunk documentation so you can study the exact concepts the exam covers. Whether you are preparing to administer a standalone instance or a distributed cluster, this reference will help you build a systematic study plan.
You can also explore more Splunk certification study guides on the Splunk category to keep building your skills.
Splunk Enterprise Certified Admin Materials
| Coursera | Splunk 9.x Enterprise Certified Admin Guide |
| Udemy | The Complete Splunk Enterprise Certified Admin Course |
| Whizlabs | Splunk Basics Training Course |
1.0 Splunk Admin Basics 5%
1.1 Identify Splunk components
Components of a Splunk Enterprise deployment
Components and the data pipeline
2.0 License Management 5%
2.1 Identify license types
Types of Splunk Enterprise licenses
2.2 Understand license violations
3.0 Splunk Configuration Files 5%
3.1 Describe Splunk configuration directory structure
Configuration file directories
3.2 Understand configuration layering
3.3 Understand configuration precedence
3.4 Use btool to examine configuration settings
Use btool to troubleshoot configurations
4.0 Splunk Indexes 10%
4.1 Describe index structure
How the indexer stores indexes
4.2 List types of index buckets
4.3 Check index data integrity
4.4 Describe indexes.conf options
4.5 Describe the fishbucket
4.6 Apply a data retention policy
Set a retirement and archiving policy
5.0 Splunk User Management 5%
5.1 Describe user roles in Splunk
5.2 Create a custom role
Create and manage roles with Splunk Web
5.3 Add Splunk users
Create and manage users with Splunk Web
6.0 Splunk Authentication Management 5%
6.1 Integrate Splunk with LDAP
Set up user authentication with LDAP
6.2 List other user authentication options
6.3 Describe the steps to enable multifactor authentication in Splunk
About multifactor authentication with Duo Security
7.0 Getting Data In 5%
7.1 Describe the basic settings for an input
7.2 List Splunk forwarder types
7.3 Configure the forwarder
Configure forwarding with outputs.conf
7.4 Add an input to UF using CLI
Monitor files and directories with inputs.conf
8.0 Distributed Search 10%
8.1 Describe how distributed search works
8.2 Explain the roles of the search head and search peers
8.3 Configure a distributed search group
Create distributed search groups
8.4 List search head scaling options
9.0 Getting Data In – Staging 5%
9.1 List the three phases of the Splunk Indexing process
How data moves through Splunk deployments: The data pipeline
9.2 List Splunk input options
Getting started with getting data in
10.0 Configuring Forwarders 5%
10.1 Configure Forwarders
Configure the universal forwarder using configuration files
10.2 Identify additional Forwarder options
Configure forwarding with outputs.conf
11.0 Forwarder Management 10%
11.1 Explain the use of deployment management
About deployment server and forwarder management
11.2 Describe Splunk Deployment Server
About deployment server and forwarder management
11.3 Manage forwarders using deployment apps
11.4 Configure deployment clients
11.5 Configure client groups
11.6 Monitor forwarder management activities
12.0 Monitor Inputs 5%
12.1 Create file and directory monitor inputs
Monitor files and directories with inputs.conf
12.2 Use optional settings for monitor inputs
Monitor files and directories with inputs.conf
12.3 Deploy a remote monitor input
13.0 Network and Scripted Inputs 5%
13.1 Create network (TCP and UDP) inputs
Get data from TCP and UDP ports
13.2 Describe optional settings for network inputs
Get data from TCP and UDP ports
13.3 Create a basic scripted input
Get data from APIs and other remote data interfaces through scripted inputs
14.0 Agentless Inputs 5%
14.1 Creating Windows Management Instrumentation (WMI) inputs
Monitor data through Windows Management Instrumentation (WMI)
14.2 Describe HTTP Event Collector
Set up and use HTTP Event Collector in Splunk Web
15.0 Fine Tuning Inputs 5%
15.1 Understand the default processing that occurs during input phase
How data moves through Splunk deployments: The data pipeline
15.2 Configure input phase options, such as sourcetype fine-tuning and character set encoding
Getting started with getting data in
16.0 Parsing Phase and Data 5%
16.1 Understand the default processing that occurs during parsing
How data moves through Splunk deployments: The data pipeline
16.2 Optimize and configure event line breaking
16.3 Explain how timestamps and time zones are extracted or assigned to events
Configure timestamp recognition
16.4 Use Data Preview to validate event creation during the parsing phase
17.0 Manipulating Raw Data 5%
17.1 Explain how data transformations are defined and invoked
17.2 Use transformations with props.conf and transforms.conf to:
Mask or delete raw data as it is being indexed
Override sourcetype or host based upon event values
Override source types on a per-event basis
Route events to specific indexes based on event content
Prevent unwanted events from being indexed
17.3 Use SEDCMD to modify raw data
Wrapping Up Splunk Enterprise Certified Admin
This guide covered every domain in the Splunk Enterprise Certified Admin blueprint, from licensing and configuration files through distributed search and raw data manipulation. Working through the linked documentation for each objective will give you a solid, hands-on foundation for the exam.
You can also explore more Splunk certification study guides on the Splunk category to keep building your skills. Have a question or tip? Leave a comment below.
Receive Updates on Splunk Enterprise Certified Admin Exam
Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.