Splunk Enterprise Certified Admin Exam Blueprint

65Questions
57 minDuration
70%Passing Score
$130Price
3 yearsValid For
Practice Splunk Enterprise Certified Admin on QuizForge

Credential type: certification examination · verified on the issuer's site September 18, 2026 issuer page

Exam Domains

1.1 Identify Splunk components 5%
2.1 Identify license types 5%
3.1 Describe Splunk configuration directory structure 5%
4.1 Describe index structure 10%
5.1 Describe user roles in Splunk 5%
6.1 Integrate Splunk with LDAP 5%
7.1 Describe the basic settings for an input 5%
8.1 Describe how distributed search works 10%
9.1 List the three phases of the Splunk Indexing process 5%
10.1 Configure Forwarders 5%
11.1 Explain the use of deployment management 10%
12.1 Create file and directory monitor inputs 5%
13.1 Create network (TCP and UDP) inputs 5%
14.1 Creating Windows Management Instrumentation (WMI) inputs 5%
15.1 Understand the default processing that occurs during input phase 5%
16.1 Understand the default processing that occurs during parsing 5%
17.1 Explain how data transformations are defined and invoked 5%

Exam Details

Question TypesMultiple Choice, Multiple Response
FormatLinear
Online ProctoringAvailable
ID RequirementsGovernment-issued photo ID required. Name on ID must match registration exactly.
RenewalRequired -- Recertify by passing the current version of the exam before expiry.
Retake Policy30-day waiting period between failed attempts. No limit on total attempts.