Splunk Enterprise Security Certified Admin Preparation Details
The Splunk Enterprise Security Certified Admin exam validates your ability to install, configure, and administer Splunk Enterprise Security for a SOC. This legacy certification covers dashboards, correlation searches, threat intelligence, and data onboarding across an ES deployment. You can also explore more Splunk certification study guides on the Splunk Certification to keep building your skills.
Splunk Enterprise Security Certified Admin Materials
| Coursera | SIEM Splunk Hands-On Guide |
| Udemy | Splunk SIEM: Fundamentals to Advanced Analytics |
| Whizlabs | Splunk Basics Training Course |
1.0 ES Introduction 5%
Topics Covered
1.1 Overview of ES features and concepts
About Splunk Enterprise Security
Splunk Enterprise Security Features
Available dashboards in Splunk Enterprise Security
2.0 Monitoring and Investigation 10%
Topics Covered
2.1 Security posture
Available dashboards in Splunk Enterprise Security
2.2 Incident review
Overview of Incident Review in Splunk Enterprise Security
Managing Incident Review in Splunk Enterprise Security
Take action on a notable on Incident Review in Splunk Enterprise Security
2.3 Notable events management
Investigate a notable on Incident Review in Splunk Enterprise Security
Managing Incident Review in Splunk Enterprise Security
Take action on a notable on Incident Review in Splunk Enterprise Security
2.4 Investigations
Investigations in Splunk Enterprise Security
Start investigations in Splunk Enterprise Security
Manage investigations in Splunk Enterprise Security
Using the workbench in an Enterprise Security investigation
3.0 Security Intelligence 5%
Topics Covered
3.1 Overview of security intel tools
Available dashboards in Splunk Enterprise Security
Configure threat intelligence sources in Splunk Enterprise Security
User and entity behavior analytics (UEBA) overview in Splunk Enterprise Security
4.0 Forensics, Glass Tables, and Navigation Control 10%
Topics Covered
4.1 Explore forensics dashboards
Available dashboards in Splunk Enterprise Security
Using Enterprise Security for security investigation and monitoring
4.2 Examine glass tables
Overview of the glass table editor in ITSI
Tutorial: Build a glass table to monitor your infrastructure
4.3 Configure navigation and dashboard permissions
Create and manage views in Splunk Enterprise Security
Configure dashboard permissions
5.0 ES Deployment 10%
Topics Covered
5.1 Identify deployment topologies
Deployment considerations for Splunk Enterprise Security
Install Splunk Enterprise Security in a search head cluster environment
Install Splunk Enterprise Security on an on-prem search head
5.2 Examine the deployment checklist
Deployment considerations for Splunk Enterprise Security
Install Splunk Enterprise Security on an on-prem search head
Configure and deploy indexes for Splunk Enterprise Security
5.3 Understand indexing strategy for ES
Configure and deploy indexes for Splunk Enterprise Security
5.4 Understand ES Data Models
Overview of the Splunk Common Information Model
Splunk Common Information Model (CIM)
6.0 Installation and Configuration 15%
Topics Covered
6.1 Prepare a Splunk environment for installation
Install Splunk Enterprise Security on an on-prem search head
Deployment considerations for Splunk Enterprise Security
6.2 Download and install ES on a search head
Install Splunk Enterprise Security
Install Splunk Enterprise Security on an on-prem search head
Install Splunk Enterprise Security in a search head cluster environment
6.3 Understand ES Splunk user accounts and roles
Configure users and roles in Splunk Enterprise Security
Configure and administer Splunk Enterprise Security
6.4 Post-install configuration tasks
Install Splunk Enterprise Security
Upgrade Splunk Enterprise Security
Configure and deploy indexes for Splunk Enterprise Security
7.0 Validating ES Data 10%
Topics Covered
7.1 Plan ES inputs
Configure and deploy indexes for Splunk Enterprise Security
Overview of the Splunk Common Information Model
7.2 Configure technology add-ons
About the Splunk Add-on Builder
Splunk Common Information Model (CIM)
8.0 Custom Add-ons 5%
Topics Covered
8.1 Design a new add-on for custom data
About the Splunk Add-on Builder
8.2 Use the Add-on Builder to build a new add-on
9.0 Tuning Correlation Searches 10%
Topics Covered
9.1 Configure correlation search scheduling and sensitivity
Configure correlation searches in Splunk Enterprise Security
Part 4: Schedule the correlation search
9.2 Tune ES correlation searches
Correlation search overview for Splunk Enterprise Security
Configure correlation searches in Splunk Enterprise Security
10.0 Creating Correlation Searches 10%
Topics Covered
10.1 Create a custom correlation search
Correlation search overview for Splunk Enterprise Security
Configure correlation searches in Splunk Enterprise Security
10.2 Configuring adaptive responses
Configure adaptive response actions for detections in Splunk Enterprise Security
Set up Adaptive Response actions in Splunk Enterprise Security
Configure adaptive response action relays in Splunk Enterprise Security
10.3 Search export/import
Export content from Splunk Enterprise Security as an app
Managing content in Splunk Enterprise Security
11.0 Lookups and Identity Management 5%
Topics Covered
11.1 Identify ES-specific lookups
Create and manage lookups in Splunk Enterprise Security
Manage internal lookups in Splunk Enterprise Security
11.2 Understand and configure lookup lists
Manage identity lookup configuration policies in Splunk Enterprise Security
Create and manage lookups in Splunk Enterprise Security
12.0 Threat Intelligence Framework 5%
Topics Covered
12.1 Understand and configure threat intelligence
Configure threat intelligence sources in Splunk Enterprise Security
Using threat intelligence in Splunk Enterprise Security
12.2 Configure user activity analysis
User and entity behavior analytics (UEBA) overview in Splunk Enterprise Security
Behavior-based detections for UEBA in Splunk Enterprise Security
Wrapping Up Splunk Enterprise Security Certified Admin
This guide walked through every domain of the Splunk Enterprise Security Certified Admin exam, from ES installation and data onboarding to correlation searches and threat intelligence. Reviewing each objective alongside the linked Splunk documentation will help you build hands-on confidence with the ES app before exam day. You can also explore more Splunk certification study guides on the Splunk Certification to keep building your skills. Have a question or tip? Leave a comment below.
Receive Updates on Splunk Enterprise Security Certified Admin Exam
Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.