Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
SPLUNK

Splunk Core Certified Consultant

CORE-CERTIFIED-CONSULTANT

The Splunk Core Certified Consultant certification validates expert-level ability to deploy and implement large Splunk installations. It is designed for consultants and architects who size, install, and advise on multi-tier Splunk architectures, clustering, and scalability. Earning it demonstrates you can lead complex deployments and maximize the value of the Splunk platform for your organization.

720 practice questions · Updated 2026-07-30

9Domains
37Objectives
195Concepts
720Questions

CORE-CERTIFIED-CONSULTANT Curriculum

Every domain, objective, and concept the CORE-CERTIFIED-CONSULTANT exam measures.

  1. SVA Definition
  2. SVA Components
  3. SVA Use Cases
  4. SVA Implementation Steps
  1. Standalone to Distributed Architecture
  2. Indexer Clustering
  3. Search Head Clustering
  4. Clustering Considerations
  1. Define high availability (HA)
  2. Define disaster recovery (DR)
  3. Differentiate HA and DR
  4. Identify Splunk HA mechanisms
  5. Identify Splunk DR mechanisms
  6. Apply HA and DR concepts to Splunk architecture

  1. Monitoring Console instance suitability
  1. MC Configuration Overview
  2. Single-Instance MC Setup
  3. Distributed Environment MC Setup
  4. MC Server Roles and Settings
  5. MC Inputs and Data Collection
  6. MC Health Check and Validation
  1. Server Roles in Monitoring Console
  2. Server Groups in Monitoring Console
  3. Mapping Server Roles to Groups
  4. Configuration of Server Roles and Groups
  5. Impact on Monitoring Views
  1. MC health check overview
  2. Health check execution process
  3. Health check result interpretation
  4. Extending health checks

Identify authentication methods

1 concepts · 12 questions
  1. Identify authentication methods
  1. LDAP Overview
  2. LDAP Authentication Flow
  3. LDAP Configuration in Splunk
  4. LDAP Group Mapping
  5. LDAP Troubleshooting

List SAML and SSO options

5 concepts · 27 questions
  1. SAML Overview
  2. SSO Options
  3. SAML Configuration
  4. SAML Attributes and Roles
  5. Troubleshooting SAML
  1. Role definition
  2. Role capabilities
  3. Search filters and data access
  4. Role inheritance
  5. Role assignment and user access
  6. Role-based data security

  1. Ingestion methods overview
  2. Forwarder data ingestion
  3. Direct data inputs
  4. HTTP Event Collector (HEC)
  5. Data parsing and indexing pipeline
  6. Indexer acknowledgment and data integrity
  1. S2S Communication Overview
  2. S2S Protocol and Ports
  3. Forwarder Configuration
  4. Indexer Acknowledgment
  5. S2S Security and Authentication
  6. Troubleshooting S2S Issues
  1. Types of data inputs
  2. Configuration of data inputs
  1. Identify common data input issues
  2. Use Splunk internal logs for troubleshooting
  3. Validate input configuration
  4. Test data ingestion with sample data
  5. Monitor input health and performance
  6. Resolve common input errors

List indexing artifacts and locations

10 concepts · 29 questions
  1. Indexing artifacts overview
  2. Index directory structure
  3. Indexes.conf configuration file
  4. Bucket lifecycle and locations
  5. Journal and rawdata files
  6. TSIDX and bloom filter files
  7. Metadata files (meta, metadata)
  8. Fishbucket and other special indexes
  9. Default index locations
  10. Index artifacts in clustered environments
  1. Event processing pipeline stages
  2. Data input and parsing
  3. Indexing and storage
  4. Data pipeline transformations
  5. Pipeline configuration and optimization
  1. Text Parsing Pipeline
  2. Line Breaking and Event Boundaries
  3. Timestamp Extraction and Recognition
  4. Character Encoding and Validation
  5. Indexing Process and Inverted Index
  6. Index-Time vs Search-Time Processing

List data retention controls

6 concepts · 15 questions
  1. Define data retention controls
  2. Configure index retention settings
  3. Implement cold-to-frozen archiving
  4. Manage frozen data
  5. Apply retention policies per index
  6. Monitor retention and storage usage

List the different search types

2 concepts · 13 questions
  1. Identify search types
  2. Differentiate search types
  1. Search efficiency principles
  2. Search mode selection
  3. Index and bucket awareness
  4. Search command optimization
  5. Use of summary and data models
  6. Search job inspection
  7. Parallel and distributed search

Describe how sub-searches work

7 concepts · 18 questions
  1. Sub-search definition
  2. Sub-search syntax
  3. Sub-search execution order
  4. Sub-search result format
  5. Sub-search use cases
  6. Sub-search limitations
  7. Sub-search alternatives

Describe a deployment app

6 concepts · 25 questions
  1. Definition of a deployment app
  2. Structure of a deployment app
  3. Packaging a deployment app
  4. Deployment methods for apps
  5. Configuration files in a deployment app
  6. Best practices for deployment apps
  1. Deployment server role
  2. Deployment client registration
  3. Server classes
  4. Configuration deployment process
  5. Deployment monitoring and troubleshooting
  1. Deployment server configuration
  2. Deployment server app deployment
  3. Deployment client configuration
  4. Deployment server management
  1. Deployment server architecture
  2. Deployment server configuration
  3. Server classes and apps
  4. Deployment client management
  5. Monitoring and troubleshooting

  1. Indexer Cluster Architecture
  2. Cluster Master Configuration
  3. Peer Node Configuration
  4. Search Head Configuration
  5. Deployment Topologies
  6. Cluster Configuration Files
  1. Bucket lifecycle stages
  2. Bucket directory structure
  3. Bucket metadata
  4. Bucket aging and roll
  5. Bucket freezing and thawing
  6. Bucket replication in indexer clustering
  1. Identify indexer cluster failure modes
  2. Understand peer failure detection
  3. Describe recovery processes for peer failure
  4. Explain bucket restoration and rebalancing
  5. Analyze master failure scenarios
  6. Understand cluster state transitions
  7. Identify manual recovery procedures
  1. Multi-site clustering architecture
  2. Site replication factor
  3. Search factor across sites
  4. Cluster master in multi-site
  5. Peer node site assignment
  6. Replication and search behavior
  7. Failure and recovery scenarios

List migration procedures

4 concepts · 14 questions
  1. Identify migration scenarios
  2. Plan migration steps
  3. Execute migration
  4. Validate migration

  1. Search Head Cluster Deployment Overview
  2. Search Head Cluster Configuration
  3. Search Head Cluster Management
  4. Search Head Cluster App and Configuration Deployment
  5. Search Head Cluster Troubleshooting
  1. Deployer role in Search Head Clustering
  2. Deployment of apps and configuration
  3. Deployment server vs. deployer
  4. Deployer configuration files
  5. Deployer push and validation
  6. Best practices for deployer usage
  1. Cluster Member Role
  2. Captain Role
  3. Captain Election Process
  4. Member and Captain Interaction
  1. RAFT consensus overview
  2. Roles in RAFT
  3. Election process
  4. Voting rules and quorum
  5. Election timeout and heartbeat
  6. Leader stability and term persistence
  7. Failure and re-election scenarios
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CORE-CERTIFIED-CONSULTANT, so none is invented.