
Splunk Cloud Certified Admin
The Splunk Cloud Certified Admin certification validates your ability to manage and configure a Splunk Cloud environment on a daily basis. It covers data inputs, forwarder configuration, user accounts, basic monitoring, and problem isolation. This credential is ideal for administrators who support Splunk Cloud deployments, whether they are new to the platform or migrating from on-premises Splunk Enterprise.
928 practice questions · Updated 2025-04-08
13Domains
44Objectives
282Concepts
928Questions
CLOUD-CERTIFIED-ADMIN Curriculum
Every domain, objective, and concept the CLOUD-CERTIFIED-ADMIN exam measures.
- Cloud topology overview
- Deployment components
- Multi-tenant architecture
- Data flow
- Scalability and redundancy
- Network and security boundaries
- Identify administrator tasks
- Manage users and roles
- Manage data inputs
- Monitor system health
- Handle troubleshooting and support
- Manage apps and add-ons
- Ensure compliance and security
- Deployment Model
- Upgrade and Maintenance
- Scalability and Resource Management
- Compliance and Certifications
- Customization and Flexibility
- Pricing and Licensing
- Data Ingestion and Forwarder Management
- Support and SLAs
- Definition of Self-Service Cloud
- Definition of Managed Cloud
- Key differences in management and operations
- Differences in customization and control
- Differences in support and service level agreements
- Differences in cost and pricing model
- Differences in scalability and performance
- Differences in security and compliance
- Differences in upgrade and patching process
- Differences in monitoring and health checks
- Differences in data ingestion and indexing
- Differences in add-ons and apps installation
- Differences in API and integration capabilities
- Differences in backup and disaster recovery
- Differences in user and role management
- Differences in deployment time and effort
- Differences in compliance with Splunk Cloud certifications
- Differences in feature availability
- Differences in upgrade windows and maintenance schedules
- Differences in customer responsibility for data security
- Definition of an index
- Index structure
- Index types
- Index creation
- Index configuration
- Index creation prerequisites
- Index creation process
- Index settings configuration
- Index naming conventions
- Index validation
- Delete events from an index
- Delete buckets from an index
- Use the delete command syntax
- Understand delete permissions and roles
- Verify deletion results
- Monitor indexing activities
- Identify indexing issues
- Use monitoring dashboards
- Check indexer health
- Monitor data input and parsing
- Review indexing logs
- Set up alerts for indexing
- Role-based access control overview
- Creating and editing roles
- Assigning capabilities to roles
- Setting search scope for roles
- Managing role inheritance
- Assigning roles to users
- Best practices for role administration
- LDAP Integration
- Active Directory Integration
- SAML Integration
- Role Mapping and User Provisioning
- Authentication Configuration Verification
- Identify configuration file types
- Locate configuration directories
- Understand configuration file precedence
- Use btool for configuration inspection
- Edit configuration files safely
- Configuration file precedence order
- Directory precedence within same level
- File precedence within same directory
- Stanza precedence within a file
- Attribute precedence within a stanza
- Default vs. custom configuration
- Use of btool to verify precedence
- Index-time processing
- Search-time processing
- Differences between index-time and search-time
- Configuration files for index-time
- Configuration files for search-time
- Identify forwarder types
- Describe forwarder functions
- Compare forwarder use cases
- Role of forwarders in data ingestion
- Forwarder types
- Forwarder deployment scenarios
- Forwarder data flow
- Forwarder management
- Forwarder roles and types
- Forwarder installation and configuration
- Outputs configuration for Splunk Cloud
- Inputs configuration for data collection
- Deployment server and apps
- Forwarder management and monitoring
- Load balancing and failover
- Security and authentication
- Verify forwarder connectivity
- Troubleshoot connection issues
- Use Splunk Web to test forwarder connection
- Use CLI commands to test forwarder connection
- Forwarder configuration files
- Inputs and outputs stanzas
- Forwarding protocols
- Queue and buffer settings
- Compression and acknowledgments
- Load balancing and failover
- TLS/SSL certificate configuration
- Monitoring and troubleshooting forwarders
- Deployment Server Purpose
- Deployment Server Components
- Deployment Server Architecture
- Server Classes
- Deployment Apps
- Forwarder management overview
- Forwarder configuration
- Forwarder monitoring
- Forwarder troubleshooting
- Deployment client configuration
- Deployment client apps and updates
- Deployment client monitoring and troubleshooting
- Deployment apps overview
- Creating deployment apps
- Configuring deployment apps
- Deploying apps to forwarders
- Managing app updates
- Troubleshooting deployment apps
- Splunk data input pipeline
- Input types and sources
- Input configuration methods
- Data parsing and preprocessing
- Indexing and storage
- Monitoring input health
- File and directory monitor input basics
- Configure file monitor inputs
- Configure directory monitor inputs
- Set monitor input properties
- Use wildcards in monitor inputs
- Handle file rotation and checkpointing
- Troubleshoot monitor inputs
- Monitor input optional settings overview
- Setting the source type for monitor inputs
- Setting the host for monitor inputs
- Setting the index for monitor inputs
- Configuring the sourcetype and index via props.conf
- Using whitelist and blacklist filters
- Setting the character set for monitor inputs
- Configuring the maximum event size
- Setting the time before a file is considered complete
- Using the CRC table to track file offsets
- Configuring the seek pointer for monitor inputs
- Handling file rotation and renaming
- Setting the number of threads for reading files
- Configuring the read timeout
- Using the 'ignoreOlderThan' setting
- Setting the 'followTail' option
- Configuring the 'crcSalt' setting
- Applying optional settings via the UI and inputs.conf
- TCP input configuration
- UDP input configuration
- Network input settings and options
- Verifying network inputs
- Scripted input fundamentals
- Creating a scripted input
- Configuring script execution
- Output formatting
- Troubleshooting scripted inputs
- Optional settings overview
- Source type and index settings
- Host and metadata settings
- Protocol-specific options
- Input parsing and timestamp settings
- Connection and buffer settings
- SSL and security settings
- Monitoring and troubleshooting settings
- Windows input types
- Windows event log inputs
- Windows performance monitor inputs
- Windows registry inputs
- Windows file system inputs
- Windows input configuration
- Windows input use cases
- HEC Overview
- HEC Configuration
- Token Management
- Data Transmission
- Event Formatting
- Batch and Compression
- Error Handling and Retries
- HEC Security
- Troubleshooting HEC
- Default input phase processing
- Parsing and metadata extraction
- Timestamp extraction and time zone handling
- Indexing and event creation
- Sourcetype fine-tuning
- Character set encoding
- Input phase options
- Default parsing pipeline
- Line breaking and event boundaries
- Timestamp extraction and assignment
- Character set and encoding handling
- Truncation and maximum event size
- Metadata extraction (source, sourcetype, host)
- Parsing queue and resource management
- Event line breaking basics
- Line breaking configuration options
- Using LINE_BREAKER regex
- Line merging behavior
- Truncation and max event size
- Testing line breaking in Data Preview
- Optimizing line breaking performance
- Timestamp Extraction
- Timestamp Formats
- Timestamp Assignment
- Time Zone Handling
- Time Zone Configuration
- Default Time Zone Behavior
- Access Data Preview
- Navigate Data Preview Interface
- Validate Event Creation
- Inspect Parsed Events
- Examine Field Extractions
- Identify Parsing Issues
- Apply Parsing Adjustments
- Definition of data transformations
- Invocation of data transformations
- props.conf TRANSFORMS attribute
- transforms.conf transform definition
- Regex-based field extraction
- Setting destination keys
- Conditional transforms with SOURCE_KEY
- Transform chaining and ordering
- Testing and troubleshooting transforms
- SEDCMD overview
- SEDCMD syntax
- Sed substitution commands
- Sed deletion commands
- Sed transformation commands
- Regex in SEDCMD
- SEDCMD flags
- SEDCMD vs other transforms
- SEDCMD configuration in props.conf
- Testing and troubleshooting SEDCMD
- Installation prerequisites
- Installation methods
- Installation steps
- Post-installation verification
- Definition of private apps
- Private app characteristics
- Private app installation methods
- Private app management
- App installation methods
- App management interface
- App permissions and visibility
- App updates and versioning
- App uninstallation and cleanup
- App troubleshooting
- Problem Isolation Fundamentals
- Data Input Verification
- Search and Indexing Checks
- Configuration Review
- Resource Utilization Assessment
- Log and Error Analysis
- Documentation and Evidence Gathering
- Identify support channels
- Submit a support case
- Understand case lifecycle
- Use support resources
- Escalate issues
- Collaborate with support
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CLOUD-CERTIFIED-ADMIN, so none is invented.