Splunk Enterprise Security Certified Admin Exam Blueprint

65Questions
60 minDuration
70%Passing Score
$130Price
3 yearsValid For
Practice Splunk Enterprise Security Certified Admin on QuizForge

Credential type: certification examination · verified on the issuer's site September 19, 2026 issuer page

Exam Domains

1.0 ES Introduction 5%
  • 1.1Overview of ES features and concepts
2.0 Monitoring and Investigation 10%
  • 2.1Security posture
  • 2.2Incident review
  • 2.3Notable events management
  • 2.4Investigations
3.0 Security Intelligence 5%
  • 3.1Overview of security intel tools
4.0 Forensics, Glass Tables, and Navigation Control 10%
  • 4.1Explore forensics dashboards
  • 4.2Examine glass tables
  • 4.3Configure navigation and dashboard permissions
5.0 ES Deployment 10%
  • 5.1Identify deployment topologies
  • 5.2Examine the deployment checklist
  • 5.3Understand indexing strategy for ES
  • 5.4Understand ES Data Models
6.0 Installation and Configuration 15%
  • 6.1Prepare a Splunk environment for installation
  • 6.2Download and install ES on a search head
  • 6.3Understand ES Splunk user accounts and roles
  • 6.4Post-install configuration tasks
7.0 Validating ES Data 10%
  • 7.1Plan ES inputs
  • 7.2Configure technology add-ons
8.0 Custom Add-ons 5%
  • 8.1Design a new add-on for custom data
  • 8.2Use the Add-on Builder to build a new add-on
9.0 Tuning Correlation Searches 10%
  • 9.1Configure correlation search scheduling and sensitivity
  • 9.2Tune ES correlation searches
10.0 Creating Correlation Searches 10%
  • 10.1Create a custom correlation search
  • 10.2Configuring adaptive responses
  • 10.3Search export/import
11.0 Lookups and Identity Management 5%
  • 11.1Identify ES-specific lookups
  • 11.2Understand and configure lookup lists
12.0 Threat Intelligence Framework 5%
  • 12.1Understand and configure threat intelligence
  • 12.2Configure user activity analysis

Exam Details

Question TypesMultiple Choice, Multiple Response
FormatLinear
Online ProctoringAvailable
ID RequirementsGovernment-issued photo ID required. Name on ID must match registration exactly.
RenewalRequired -- Recertify by passing the current version of the exam before expiry.
PrerequisitesThere are no prerequisite exams for this certification. (recommended)
Retake Policy30-day waiting period between failed attempts. No limit on total attempts.

Official Study Resources

official study guideAdministering Splunk Enterprise Security