Splunk Enterprise Certified Architect Preparation Details
The Splunk Enterprise Certified Architect (SPLK-2002) exam validates expert-level skills in planning, deploying, and troubleshooting large-scale, clustered Splunk Enterprise deployments. Candidates are tested on capacity planning, clustering, forwarder design, and performance tuning. This guide maps every domain to current Splunk documentation. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills.
Splunk Enterprise Certified Architect Materials
| Coursera | Splunk Administration & Performance Optimization |
| Udemy | SPLK-2002: Splunk Enterprise Certified Architect Exam |
1.0 Introduction 2%
1.1 Describe a deployment plan
Components of a Splunk Enterprise deployment
Introduction to capacity planning for Splunk Enterprise
1.2 Define the deployment process
About deployment server and forwarder management
Forwarder deployment topologies
2.0 Project Requirements 5%
2.1 Identify critical information about environment, volume, users, and requirements
Introduction to capacity planning for Splunk Enterprise
Components of a Splunk Enterprise deployment
2.2 Apply checklists and resources to aid in collecting requirements
Estimate your storage requirements
3.0 Infrastructure Planning: Index Design 5%
3.1 Understand design and size indexes
Estimate your storage requirements
3.2 Estimate non-smart store related storage requirements
Estimate your storage requirements
3.3 Identify relevant apps
Where to get more apps and add-ons
Update common peer configurations and apps
4.0 Infrastructure Planning: Resource Planning 7%
4.1 List sizing considerations
Introduction to capacity planning for Splunk Enterprise
Estimate your storage requirements
4.2 Identify disk storage requirements
Estimate your storage requirements
4.3 Define hardware requirements for various Splunk components
Components of a Splunk Enterprise deployment
Universal forwarder deployment prerequisites
4.4 Describe ES considerations for sizing and topology
Considerations for scaling deployments
Deployment considerations for Splunk Enterprise Security
4.5 Describe ITSI considerations for sizing and topology
Introduction to capacity planning for Splunk Enterprise
4.6 Describe security, privacy, and integrity measures
About securing Splunk Enterprise
More ways to secure Splunk Enterprise
5.0 Clustering Overview 5%
5.1 Identify non-smart store related storage and disk usage requirements
About indexer clusters and index replication
Estimate your storage requirements
5.2 Identify search head clustering requirements
6.0 Forwarder and Deployment Best Practices 6%
6.1 Identify best practices for forwarder tier design
Forwarder deployment topologies
Intermediate data routing using universal and heavy forwarders
6.2 Understand configuration management for all Splunk components, using Splunk deployment tools
About deployment server and forwarder management
Update common peer configurations and apps
Manage common configurations across all peers
7.0 Performance Monitoring and Tuning 5%
7.1 Use limits.conf to improve performance
7.2 Use indexes.conf to manage bucket size
7.3 Tune props.conf
7.4 Improve search performance
8.0 Splunk Troubleshooting Methods and Tools 5%
8.1 Splunk diagnostic resources and tools
Use btool to troubleshoot configurations
Introduction to troubleshooting Splunk Enterprise
What Splunk software logs about itself
9.0 Clarifying the Problem 5%
9.1 Identify Splunk’s internal log files
What Splunk software logs about itself
9.2 Identify Splunk’s internal indexes
10.0 Licensing and Crash Problems 5%
10.1 License issues
10.2 Crash issues
What Splunk software logs about itself
Introduction to troubleshooting Splunk Enterprise
Advanced help troubleshooting Splunk software for Windows
11.0 Configuration Problems 5%
11.1 Input issues
Troubleshoot the input process
Use btool to troubleshoot configurations
12.0 Search Problems 5%
12.1 Search issues
12.2 Job inspector
13.0 Deployment Problems 5%
13.1 Forwarding issues
Troubleshoot forwarder/receiver connection
Troubleshoot the universal forwarder
13.2 Deployment server issues
Troubleshoot performance issues
About deployment server and forwarder management
14.0 Large-scale Splunk Deployment Overview 5%
14.1 Identify Splunk server roles in clusters
About indexer clusters and index replication
Components of a Splunk Enterprise deployment
14.2 License Master configuration in a clustered environment
15.0 Single-site Indexer Cluster 5%
15.1 Splunk single-site indexer cluster configuration
Peer node configuration overview
16.0 Multisite Indexer Cluster 5%
16.1 Splunk multisite indexer cluster overview
Multisite indexer cluster deployment overview
16.2 Multisite indexer cluster configuration
Configure multisite indexer clusters with server.conf
Configure multisite indexer clusters with the CLI
16.3 Cluster migration and upgrade considerations
Migrate an indexer cluster from single-site to multisite
17.0 Indexer Cluster Management and Administration 7%
17.1 Indexer cluster storage utilization options
Indexer cluster operations and SmartStore
17.2 Peer offline and decommission
17.3 Master app bundles
Update common peer configurations and apps
Manage common configurations across all peers
17.4 Monitoring Console for indexer cluster environment
Use the monitoring console to view indexer cluster status
Indexing: Indexer Clustering: Status
Indexing: Indexer Clustering: Service Activity
18.0 Search Head Cluster 5%
18.1 Splunk search head cluster overview
Search head clustering architecture
18.2 Search head cluster configuration
19.0 Search Head Cluster Management and Administration 5%
19.1 Search head cluster deployer
19.2 Captaincy transfer
19.3 Search head member addition and decommissioning
20.0 KV Store Collection and Lookup Management 3%
20.1 KV Store collection in Splunk clusters
Wrapping Up Splunk Enterprise Certified Architect
This guide covered every domain of the Splunk Enterprise Certified Architect (SPLK-2002) blueprint, from deployment planning and index design through indexer and search head clustering, performance tuning, and troubleshooting. Use the linked documentation to build hands-on familiarity with each objective before exam day. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills. Have a question or tip? Leave a comment below.
Receive Updates on Splunk Enterprise Certified Architect Exam
Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.