Credential type: certification examination · verified on the issuer's site September 19, 2026 issuer page
Exam Domains
1.0 ES Introduction
5%
- 1.1Overview of ES features and concepts
2.0 Monitoring and Investigation
10%
- 2.1Security posture
- 2.2Incident review
- 2.3Notable events management
- 2.4Investigations
3.0 Security Intelligence
5%
- 3.1Overview of security intel tools
4.0 Forensics, Glass Tables, and Navigation Control
10%
- 4.1Explore forensics dashboards
- 4.2Examine glass tables
- 4.3Configure navigation and dashboard permissions
5.0 ES Deployment
10%
- 5.1Identify deployment topologies
- 5.2Examine the deployment checklist
- 5.3Understand indexing strategy for ES
- 5.4Understand ES Data Models
6.0 Installation and Configuration
15%
- 6.1Prepare a Splunk environment for installation
- 6.2Download and install ES on a search head
- 6.3Understand ES Splunk user accounts and roles
- 6.4Post-install configuration tasks
7.0 Validating ES Data
10%
- 7.1Plan ES inputs
- 7.2Configure technology add-ons
8.0 Custom Add-ons
5%
- 8.1Design a new add-on for custom data
- 8.2Use the Add-on Builder to build a new add-on
9.0 Tuning Correlation Searches
10%
- 9.1Configure correlation search scheduling and sensitivity
- 9.2Tune ES correlation searches
10.0 Creating Correlation Searches
10%
- 10.1Create a custom correlation search
- 10.2Configuring adaptive responses
- 10.3Search export/import
11.0 Lookups and Identity Management
5%
- 11.1Identify ES-specific lookups
- 11.2Understand and configure lookup lists
12.0 Threat Intelligence Framework
5%
- 12.1Understand and configure threat intelligence
- 12.2Configure user activity analysis