
Splunk Core Certified Consultant
The Splunk Core Certified Consultant certification validates expert-level ability to deploy and implement large Splunk installations. It is designed for consultants and architects who size, install, and advise on multi-tier Splunk architectures, clustering, and scalability. Earning it demonstrates you can lead complex deployments and maximize the value of the Splunk platform for your organization.
720 practice questions · Updated 2026-07-30
9Domains
37Objectives
195Concepts
720Questions
CORE-CERTIFIED-CONSULTANT Curriculum
Every domain, objective, and concept the CORE-CERTIFIED-CONSULTANT exam measures.
- SVA Definition
- SVA Components
- SVA Use Cases
- SVA Implementation Steps
- Standalone to Distributed Architecture
- Indexer Clustering
- Search Head Clustering
- Clustering Considerations
- Define high availability (HA)
- Define disaster recovery (DR)
- Differentiate HA and DR
- Identify Splunk HA mechanisms
- Identify Splunk DR mechanisms
- Apply HA and DR concepts to Splunk architecture
- Monitoring Console instance suitability
- MC Configuration Overview
- Single-Instance MC Setup
- Distributed Environment MC Setup
- MC Server Roles and Settings
- MC Inputs and Data Collection
- MC Health Check and Validation
- Server Roles in Monitoring Console
- Server Groups in Monitoring Console
- Mapping Server Roles to Groups
- Configuration of Server Roles and Groups
- Impact on Monitoring Views
- MC health check overview
- Health check execution process
- Health check result interpretation
- Extending health checks
- Identify authentication methods
- LDAP Overview
- LDAP Authentication Flow
- LDAP Configuration in Splunk
- LDAP Group Mapping
- LDAP Troubleshooting
- SAML Overview
- SSO Options
- SAML Configuration
- SAML Attributes and Roles
- Troubleshooting SAML
- Role definition
- Role capabilities
- Search filters and data access
- Role inheritance
- Role assignment and user access
- Role-based data security
- Ingestion methods overview
- Forwarder data ingestion
- Direct data inputs
- HTTP Event Collector (HEC)
- Data parsing and indexing pipeline
- Indexer acknowledgment and data integrity
- S2S Communication Overview
- S2S Protocol and Ports
- Forwarder Configuration
- Indexer Acknowledgment
- S2S Security and Authentication
- Troubleshooting S2S Issues
- Types of data inputs
- Configuration of data inputs
- Identify common data input issues
- Use Splunk internal logs for troubleshooting
- Validate input configuration
- Test data ingestion with sample data
- Monitor input health and performance
- Resolve common input errors
- Indexing artifacts overview
- Index directory structure
- Indexes.conf configuration file
- Bucket lifecycle and locations
- Journal and rawdata files
- TSIDX and bloom filter files
- Metadata files (meta, metadata)
- Fishbucket and other special indexes
- Default index locations
- Index artifacts in clustered environments
- Event processing pipeline stages
- Data input and parsing
- Indexing and storage
- Data pipeline transformations
- Pipeline configuration and optimization
- Text Parsing Pipeline
- Line Breaking and Event Boundaries
- Timestamp Extraction and Recognition
- Character Encoding and Validation
- Indexing Process and Inverted Index
- Index-Time vs Search-Time Processing
- Define data retention controls
- Configure index retention settings
- Implement cold-to-frozen archiving
- Manage frozen data
- Apply retention policies per index
- Monitor retention and storage usage
- Search Job Inspection Overview
- Accessing Search Job Inspector
- Interpreting Inspector Fields
- Understanding Search Phases
- Analyzing Search Performance Metrics
- Identifying Search Job Components
- Troubleshooting with Inspector
- Search Inner-Workings Overview
- Search Pipeline and Command Processing
- Role of Indexers and Search Heads
- Search Artifacts and Caching
- Identify search types
- Differentiate search types
- Search efficiency principles
- Search mode selection
- Index and bucket awareness
- Search command optimization
- Use of summary and data models
- Search job inspection
- Parallel and distributed search
- Sub-search definition
- Sub-search syntax
- Sub-search execution order
- Sub-search result format
- Sub-search use cases
- Sub-search limitations
- Sub-search alternatives
- Definition of a deployment app
- Structure of a deployment app
- Packaging a deployment app
- Deployment methods for apps
- Configuration files in a deployment app
- Best practices for deployment apps
- Deployment server role
- Deployment client registration
- Server classes
- Configuration deployment process
- Deployment monitoring and troubleshooting
- Deployment server configuration
- Deployment server app deployment
- Deployment client configuration
- Deployment server management
- Deployment server architecture
- Deployment server configuration
- Server classes and apps
- Deployment client management
- Monitoring and troubleshooting
- Indexer Cluster Architecture
- Cluster Master Configuration
- Peer Node Configuration
- Search Head Configuration
- Deployment Topologies
- Cluster Configuration Files
- Bucket lifecycle stages
- Bucket directory structure
- Bucket metadata
- Bucket aging and roll
- Bucket freezing and thawing
- Bucket replication in indexer clustering
- Identify indexer cluster failure modes
- Understand peer failure detection
- Describe recovery processes for peer failure
- Explain bucket restoration and rebalancing
- Analyze master failure scenarios
- Understand cluster state transitions
- Identify manual recovery procedures
- Multi-site clustering architecture
- Site replication factor
- Search factor across sites
- Cluster master in multi-site
- Peer node site assignment
- Replication and search behavior
- Failure and recovery scenarios
- Identify migration scenarios
- Plan migration steps
- Execute migration
- Validate migration
- Search Head Cluster Deployment Overview
- Search Head Cluster Configuration
- Search Head Cluster Management
- Search Head Cluster App and Configuration Deployment
- Search Head Cluster Troubleshooting
- Identify search head cluster use cases
- Identify search head cluster limitations
- Deployer role in Search Head Clustering
- Deployment of apps and configuration
- Deployment server vs. deployer
- Deployer configuration files
- Deployer push and validation
- Best practices for deployer usage
- Cluster Member Role
- Captain Role
- Captain Election Process
- Member and Captain Interaction
- RAFT consensus overview
- Roles in RAFT
- Election process
- Voting rules and quorum
- Election timeout and heartbeat
- Leader stability and term persistence
- Failure and re-election scenarios
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CORE-CERTIFIED-CONSULTANT, so none is invented.