Splunk SOAR Certified Automation Developer Exam Study Guide

Splunk-SOAR-Certified-Automation-Developer

Splunk SOAR Certified Automation Developer Preparation Details

The Splunk SOAR Certified Automation Developer exam validates your ability to install, configure, and administer a SOAR deployment while building and debugging playbooks. This legacy, professional-level exam covers deployment, case management, the Visual Playbook Editor, custom coding, and REST API integration across 18 domains. Candidates preparing for this exam should be comfortable working across both Splunk SOAR (On-premises) and Splunk SOAR (Cloud) documentation, since concepts and terminology overlap between the two products. You can also explore more Splunk certification study guides on the Splunk Certification category to keep building your skills.

Splunk SOAR Certified Automation Developer Materials

CourseraSOAR for Enterprise Security
UdemySplunk SOAR Certified Dev Practice Tests 2026

1.0 Deployment, Installation, and Initial Configuration 5%

1.1 Describe SOAR operating concepts

About Splunk SOAR (Cloud)

Splunk SOAR (Cloud) introduction

Splunk SOAR Features

1.2 Identify documentation and community resources

Administer SOAR (On-premises)

Course Catalog

Splunk SOAR Certified Automation Developer

1.3 Identify installation and upgrade options

How can Splunk SOAR (On-premises) be installed?

Splunk SOAR (On-premises) upgrade overview and prerequisites

Upgrade a Splunk SOAR (On-premises) instance

Upgrade a Splunk SOAR (On-premises) cluster

1.4 Describe SOAR architecture

Splunk SOAR apps overview

Cloud Deployment (S0)

About Splunk SOAR (On-premises)

1.5 Configure licenses, administration, and product settings

Obtain and configure a Splunk SOAR (On-premises) license

View your Splunk SOAR (Cloud) license

Manage dashboard widgets in Splunk SOAR (On-premises)

2.0 User Management 5%

2.1 Configure authentication options

Configure single sign-on authentication for Splunk SOAR (On-premises)

Configure single sign-on authentication for Splunk SOAR (Cloud)

2.2 Add users

Manage Splunk SOAR (On-premises) users

Manage Splunk SOAR (Cloud) users

2.3 Add roles

Manage roles and permissions in Splunk SOAR (On-premises)

Manage roles and permissions in Splunk SOAR (Cloud)

3.0 Apps, Assets, and Playbooks 5%

3.1 Configure apps

Configure or upgrade the service with Splunk App for SOAR

Install Splunk App for SOAR on Splunk Enterprise

Splunk SOAR apps overview

3.2 Configure assets

Add and configure apps and assets to provide actions in Splunk SOAR (Cloud)

Assess app and asset connectivity and ingestion

3.3 Configure data ingestion assets

View how much data is ingested in Splunk SOAR (Cloud) using ingestion summary

View ingested container statistics using Ingestion Status

Add and configure apps and assets to provide actions in Splunk SOAR (On-premises)

3.4 Configure labels and SLAs

Configure labels to apply to containers

Create custom severity names and control severity inheritance

3.5 Manage playbooks

Use playbooks to automate analyst workflows in Splunk SOAR (Cloud)

Write better playbooks by following these guidelines

Create a new playbook in Splunk SOAR (On-premises)

4.0 Analyst Queue 5%

4.1 Use the Analyst Queue

Start with Investigation in Splunk SOAR (On-premises)

Splunk SOAR Features

4.2 Use search features

Search within Splunk SOAR (On-premises)

Configure search in Splunk SOAR (On-premises)

4.3 Create filters

Filter indicator records in Splunk SOAR (On-premises)

Search within Splunk SOAR (On-premises)

4.4 Use the indicator view

Filter indicator records in Splunk SOAR (Cloud)

Create custom CEF fields in Splunk SOAR (Cloud)

5.0 The Investigation Page 10%

5.1 Use the Investigation page to work on events

Start with Investigation in Splunk SOAR (On-premises)

Start with Investigation in Splunk SOAR (Cloud)

5.2 Manually run actions and examine action results

Add an action block to your Splunk SOAR (Cloud) playbook

Understanding datapaths

5.3 Manually run playbooks

Start with Investigation in Splunk SOAR (On-premises)

Use playbooks to automate analyst workflows in Splunk SOAR (Cloud)

5.4 Use the file tab to store related files

Mark files and events as evidence in Splunk SOAR (Cloud)

Mark files and events as evidence in Splunk SOAR (On-premises)

6.0 Case Management and Workbooks 5%

6.1 Use case management for complex investigations

Create cases in Splunk SOAR (Cloud)

Managing cases in SOAR

Understanding SOAR case management features

6.2 Use workbooks

Define a workflow in a case using workbooks in Splunk SOAR (Cloud)

6.3 Mark items as evidence

Mark files and events as evidence in Splunk SOAR (Cloud)

Create case reports to download and share in Splunk SOAR (Cloud)

7.0 Customizations 5%

7.1 Customize severity levels

Create custom severity names and control severity inheritance

Create custom severity names and control severity inheritance

7.2 Customize CEF fields

Create custom CEF fields in Splunk SOAR (On-premises)

Create custom CEF fields in Splunk SOAR (Cloud)

Understanding datapaths

7.3 Customize status values

Create custom status labels in Splunk SOAR (Cloud)

7.4 Customize workbooks

Define a workflow in a case using workbooks in Splunk SOAR (Cloud)

7.5 Add global custom fields to containers

Create custom fields to filter Splunk SOAR (Cloud) events

Configure labels to apply to containers

8.0 System Maintenance 5%

8.1 Run reports

Create Executive Summary reports and view all reports in Splunk SOAR (On-premises)

Create Executive Summary reports and view all reports in Splunk SOAR (Cloud)

Create case reports to download and share in Splunk SOAR (Cloud)

8.2 Use system health displays

Monitor the health of your Splunk SOAR (On-premises) system

Monitor the health of your Splunk SOAR (Cloud) system

8.3 Examine health logs

Learn about the Splunk System Logs in SOAR in Splunk App for SOAR

About the Content Pack for SOAR System Logs

9.0 Introduction to Playbooks 5%

9.1 Understand automation best practices

Write better playbooks by following these guidelines

Use playbooks to automate analyst workflows in Splunk SOAR (Cloud)

9.2 Describe playbook capabilities

Use playbooks to automate analyst workflows in Splunk SOAR (On-premises)

Splunk SOAR Visual Playbook Editor Data Sheet

9.3 Determine available app actions

Add an action block to your Splunk SOAR (Cloud) playbook

Add and configure apps and assets to provide actions in Splunk SOAR (Cloud)

9.4 Use I2A2 design methodology

Investigating Incidents with Splunk SOAR

Write better playbooks by following these guidelines

10.0 Visual Playbook Editor 5%

10.1 Use the visual playbook editor

Create a new playbook in Splunk SOAR (On-premises)

Use keyboard shortcuts in the playbook editor

Use playbooks to automate analyst workflows in Splunk SOAR (Cloud)

10.2 Execute actions from a playbook

Add an action block to your Splunk SOAR (Cloud) playbook

Add a new block to your Splunk SOAR (Cloud) playbook

10.3 Test new playbooks

Debug playbooks in Splunk SOAR (Cloud)

Use keyboard shortcuts in the playbook editor

11.0 Logic, Filters, and User Interaction 5%

11.1 Use decision blocks

Use decisions to send artifacts to a specific downstream action in your Splunk SOAR (Cloud) playbook

11.2 Use filter blocks to process data

Use filters in your Splunk SOAR (Cloud) playbook to specify a subset of artifacts

Use filters in your Splunk SOAR (On-premises) playbook to specify a subset of artifacts

11.3 Describe the use of different join options

Run other playbooks inside your playbook in Splunk SOAR (Cloud)

11.4 Interact with users during playbook execution

Require user input using the Prompt block in your Splunk SOAR (Cloud) playbook

Require user input using the Prompt block in your Splunk SOAR (On-premises) playbook

12.0 Formatted Output and Data Access 5%

12.1 Use Format blocks to structure data

Customize the format of your Splunk SOAR (Cloud) playbook content

Customize the format of your Splunk SOAR (On-premises) playbook content

12.2 Understand the structure of action results

Understanding datapaths

12.3 Compose datapaths to access data

Understanding datapaths

12.4 Use the utility block to modify containers

Add functionality to your playbook in Splunk SOAR (Cloud) using the Utility block

13.0 Modular Playbook Development 5%

13.1 Design modular solutions with interacting playbooks

Run other playbooks inside your playbook in Splunk SOAR (Cloud)

13.2 Invoke child playbooks from a parent

Run other playbooks inside your playbook in Splunk SOAR (On-premises)

13.3 Exchange data between playbooks

Add functionality to your playbook in Splunk SOAR (On-premises) using the Utility block

Write better playbooks by following these guidelines

14.0 Custom Lists and Data Routing 5%

14.1 Create custom lists

Create custom lists for use in Splunk SOAR (On-premises) playbook comparisons

Create custom lists for use in Splunk SOAR (Cloud) playbook comparisons

14.2 Access lists from playbooks

Create custom lists for use in Splunk SOAR (On-premises) playbooks

Create custom lists for use in Splunk SOAR (Cloud) playbooks

14.3 Use filters to control data flow

Use filters in your Splunk SOAR (Cloud) playbook to specify a subset of artifacts

15.0 Configuring External Splunk Search 5%

15.1 Describe the benefits of externalizing search to Splunk

Configure search in Splunk SOAR (On-premises)

Configure search in Splunk SOAR (Cloud)

15.2 Configure the SOAR instance for externalization

Configure search in Splunk SOAR (Cloud)

15.3 Configure the Splunk instance for externalization

Configure a Splunk asset in Splunk SOAR to pull data from the Splunk platform

15.4 Use reindex to push existing content to the Splunk instance

The Splunk platform as a SOAR data source

15.5 Use the Splunk app for Phantom Reporting

About Splunk App for SOAR Export

Learn about the Splunk System Logs in SOAR in Splunk App for SOAR

16.0 Integrating SOAR into Splunk 10%

16.1 Install the Splunk App for SOAR Export

Install the Splunk App for SOAR Export on Splunk Enterprise

Check prerequisites for Splunk App for SOAR Export on Splunk Cloud Platform

16.2 Send Enterprise Security notables to SOAR

Connect Splunk App for SOAR Export and the Splunk Platform to Splunk SOAR

About Splunk App for SOAR Export

16.3 Install and configure the Splunk app in SOAR

Configure a Splunk asset in Splunk SOAR to pull data from the Splunk platform

Configure or upgrade the service with Splunk App for SOAR

16.4 Use Splunk search from playbooks

Add an action block to your Splunk SOAR (Cloud) playbook

17.0 Custom Coding 5%

17.1 Describe when and when not to use the global block

Add custom code to your Splunk SOAR (Cloud) playbook with the code block

Add custom code to your Splunk SOAR (On-premises) playbook with the code block

17.2 Use custom function blocks

Add custom code to your Splunk SOAR (Cloud) playbook with a custom function

Add custom code to your Splunk SOAR (On-premises) playbook with a custom function

17.3 Write and test custom SOAR code

Write better playbooks by following these guidelines

Debug playbooks in Splunk SOAR (Cloud)

18.0 Using REST 5%

18.1 Describe the capabilities of SOAR REST API

Using the REST API reference for Splunk SOAR (On-premises)

Using the REST API reference for Splunk SOAR (Cloud)

18.2 Use Django queries to search for data in SOAR

Use REST handlers to allow external services to call into Splunk SOAR

REST CEF

18.3 Use SOAR REST from other systems to access SOAR data

Use REST handlers to allow external services to call into Splunk SOAR (On-premises)

Using the REST API reference for Splunk SOAR (On-premises)

Wrapping Up Splunk SOAR Certified Automation Developer

This guide maps every domain of the Splunk SOAR Certified Automation Developer blueprint, from initial deployment through REST API integration, to official Splunk SOAR documentation. Working through each objective in order builds a practical foundation in playbook design, case management, and system administration. Use the linked materials alongside hands-on practice in a SOAR instance to reinforce what you learn. You can also explore more Splunk certification study guides on the Splunk Certification category to keep building your skills. Have a question or tip? Leave a comment below.

Receive Updates on Splunk SOAR Certified Automation Developer Exam


Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.

Share the Splunk SOAR Certified Automation Developer Study Guide in Your Network

You may also like

Leave a Reply

Your email address will not be published. Required fields are marked *