Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
SPLUNK

Splunk Core Certified Consultant

The Splunk Core Certified Consultant certification validates expert-level ability to deploy and implement large Splunk installations. It is designed for consultants and architects who size, install, and advise on multi-tier Splunk architectures, clustering, and scalability. Earning it demonstrates you can lead complex deployments and maximize the value of the Splunk platform for your organization.

Exam format86 multiple choice questions
Duration120 minutes
DeliveryPearson VUE
Free questions720

Content last reviewed 30 July 2026 · Up to date

The certification

What Splunk Core Certified Consultant proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

9domains
37objectives
195concepts
$130 USDexam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The Splunk Core Certified Consultant certification validates your ability to deploy and implement large Splunk installations with expert-level knowledge of multi-tier architectures, clustering, and scalability. As a consultant, you will be expected to properly size, install, and implement Splunk environments, and advise on how to make the most of the solutions.

This certification is the highest level of Splunk core training and certification available, designed for those who wish to join the uppermost ranks of Splunk expertise. It covers the full deployment methodology, from planning and data collection to managing distributed deployments with indexer and search head clustering. Earning this credential demonstrates that you can lead complex Splunk implementations and drive maximum value from the platform.

Who it’s for

This certification is for Splunk experts, Splunk PS partners, and independent platform consultants who want to deepen their expertise in deploying and implementing large Splunk environments. It is designed for those who wish to join the uppermost ranks of Splunk certification and gain unparalleled knowledge about the Splunk platform. Candidates typically have hands-on experience with Splunk Enterprise and are comfortable with advanced concepts such as clustering, multi-tier architectures, and scalability. The track includes a week-long bootcamp and practical labs to build both technical and soft skills needed to succeed as a Splunk consultant.

Recommended experience

Hands-on experience with Splunk Enterprise, including deployment, administration, and architecture, is strongly recommended. Completion of the Core Consultant Labs and Core Implementation coursework is required before taking the exam. Experience with Splunk Enterprise deployment and administration; Knowledge of multi-tier Splunk architectures, clustering, and scalability; Completion of Core Consultant Labs and Core Implementation coursework; Familiarity with Splunk deployment methodology and best practices

The syllabus

What you’ll learn

Every domain and objective Splunk measures, with the weight they carry on the exam.

The official Splunk exam outline · checked 30 July 2026 · See the source

Deploying Splunk
  • Define Splunk Validated Architectures (SVA)
  • Articulate how and why Splunk grows from standalone environment to distributed environment with indexer and search head clustering
  • Explain the difference between high availability and disaster recovery and how both can be addressed in Splunk
3 objectives · 64 free questions · 14 pages
Monitoring Console
  • Describe which instances are suitable to configure as the Monitoring Console
  • Articulate how to configure the MC for a single or distributed environment
  • Examine how the MC uses the server roles and groups
  • Describe how MC health checks are performed and can be extended
4 objectives · 57 free questions · 13 pages
Access and Roles
  • Identify authentication methods
  • Describe LDAP concepts and configuration
  • List SAML and SSO options
  • Define roles and articulate how roles are used to secure data
4 objectives · 70 free questions · 16 pages
Data Collection
  • Articulate the different ways data can be ingested by an indexer
  • Articulate how one Splunk instance communicates with another Splunk instance (S2S)
  • Describe the types and configuration of data inputs
  • Describe ways to troubleshoot data inputs
4 objectives · 92 free questions · 20 pages
Indexing
  • List indexing artifacts and locations
  • Describe event processing and data pipelines
  • Describe the underlying text parsing and indexing process
  • List data retention controls
4 objectives · 89 free questions · 19 pages
Search
  • Describe how to use search job inspection; explain the inner-workings of a search
  • List the different search types
  • Describe how to maximize search efficiency
  • Describe how sub-searches work
4 objectives · 86 free questions · 19 pages
Configuration Management
  • Describe a deployment app
  • Articulate how a deployment server works
  • Describe deployment system configuration
  • Articulate how to manage deployment server
4 objectives · 63 free questions · 14 pages
Indexer Clustering
  • Describe deployment and component configuration
  • Describe the life cycle of data using buckets
  • Determine failure modes and recovery processes
  • Articulate how multi-site clustering works
  • List migration procedures
5 objectives · 98 free questions · 22 pages
Search Head Clustering
  • Articulate how to manage and deploy a search head cluster
  • Determine when a search head cluster may be needed and when a search head cluster would not be recommended
  • Describe content management using the deployer
  • Describe the role of the cluster members and the Captain
  • Articulate how captain election works (RAFT)
5 objectives · 101 free questions · 22 pages
On the day

The exam itself

Everything Splunk publishes about sitting it, and nothing we inferred.

Prerequisites

One of: Splunk Core Certified Power User, Splunk Core Certified Advanced Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Certified Architect

CertificationSplunk Core Certified Consultant
Exam format86 multiple choice questions
Duration120 minutes
DeliveryPearson VUE
LanguagesEnglish
Pricing$130 USD
After you pass

Where this credential goes next

The path Splunk lays out, how the credential is kept, and where to book.

Step-by-step path to Splunk Core Certified Consultant

PrerequisiteOne of: Splunk Core Certified Power User, Splunk Core Certified Advanced Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Certified Architect
Splunk Core Certified Consultant badgeCredential earnedSplunk Core Certified Consultant Certification
Renewal and maintenance

Splunk certifications must be renewed every three years. You can renew by pursuing additional certifications, completing continuing education courses, or re-taking the certification exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. Splunk maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by Splunk

Exam registration

Register for the exam through Pearson VUE, Splunk’s authorized testing partner.

Schedule your exam

Visit the official Splunk certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the Splunk Core Certified Consultant exam relate to the Splunk Enterprise Certified Architect certification?

The Splunk Enterprise Certified Architect certification is one of the accepted prerequisite certifications for the Splunk Core Certified Consultant exam. It covers best practices for planning, data collection, and sizing of distributed deployments, which are foundational for the consultant-level expertise.

Do I need to hold a lower-level Splunk certification before taking the Splunk Core Certified Consultant exam?

Yes, you must hold one of the following certifications: Splunk Core Certified Power User, Splunk Core Certified Advanced Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Certified Architect. These are mandatory prerequisites.

Is there a hands-on lab component in the Splunk Core Certified Consultant exam?

The exam format is 86 multiple choice questions. However, the certification track includes a week-long bootcamp with practical labs to build the technical and soft skills needed to be a Splunk consultant.

What is the retake policy for the Splunk Core Certified Consultant exam?

Splunk's retake policy is not explicitly published on the exam page. Candidates should refer to the Splunk Certification Candidate Handbook for detailed retake policies.

What job roles does the Splunk Core Certified Consultant credential map to?

This credential is designed for Splunk experts, Splunk PS partners, and independent platform consultants who lead large-scale Splunk deployments and advise on architecture and scalability.

Can I recertify by passing a different Splunk exam?

Yes, Splunk certifications can be renewed by pursuing additional certifications, completing continuing education courses, or re-taking the certification exam every three years.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 720 questions, free, no account needed.