
Splunk Enterprise Certified Admin
The Splunk Enterprise Certified Admin certification validates your ability to manage and maintain the day-to-day health of a Splunk Enterprise environment. You'll demonstrate expertise in license management, indexers, search heads, configuration, monitoring, and data ingest. This credential is ideal for administrators who support Splunk Enterprise deployments and want to advance their careers beyond searches and dashboards.
432 practice questions · Updated 2026-07-30
5Domains
24Objectives
135Concepts
432Questions
SPLK-1003 Curriculum
Every domain, objective, and concept the SPLK-1003 exam measures.
- Identify Splunk components
- License types overview
- License tiers and entitlements
- License usage and limits
- License management in Splunk Web
- License enforcement and warnings
- Identify license violation types
- Interpret license violation warnings
- Monitor license usage
- Respond to license violations
- Prevent license violations
- Configuration directory hierarchy
- System vs. app vs. user directories
- Default vs. local vs. app directories
- Configuration file types and locations
- Directory precedence and merging
- App directory structure
- User-specific configuration directories
- Environment variable references
- Configuration file hierarchy
- Configuration file types and stanzas
- Configuration file merging and precedence
- App and user context in configuration
- Configuration file reload and restart
- Troubleshooting configuration layering
- Configuration file precedence order
- Precedence within a single configuration file
- Precedence across apps and directories
- Using precedence to override settings
- Troubleshooting configuration precedence
- btool overview
- btool syntax and basic usage
- btool check and validate configurations
- btool list and display settings
- btool inspect and trace configuration precedence
- btool troubleshooting and debugging
- Index structure
- Index bucket types
- Index data integrity
- indexes.conf options
- Fishbucket
- Data retention policy
- Understanding Splunk user roles
- Creating a custom role
- Adding Splunk users
- LDAP Integration Overview
- Configuring LDAP Authentication
- LDAP Group-to-Role Mapping
- Other Authentication Options
- Multifactor Authentication Overview
- Enabling Multifactor Authentication
- Basic Input Settings
- Three Phases of Splunk Indexing
- Splunk Input Options
- HTTP Event Collector (HEC)
- Default Input Processing
- Sourcetype Fine-Tuning
- Character Set Encoding Configuration
- Splunk forwarder types
- Forwarder configuration basics
- Adding inputs via CLI
- Deploying remote monitor inputs
- File monitor input creation
- Directory monitor input creation
- Monitor input optional settings
- TCP Input Creation
- UDP Input Creation
- Network Input Optional Settings
- Scripted input fundamentals
- Creating a basic scripted input
- Configuring scripted input execution
- Script output and data formatting
- WMI input fundamentals
- Creating a WMI input
- Configuring WMI input parameters
- Troubleshooting scripted and WMI inputs
- Distributed Search Architecture
- Search Head Role
- Search Peer Role
- Distributed Search Group Configuration
- Search Head Scaling Options
- Configure Forwarders
- Identify Additional Forwarder Options
- Explain the Use of Deployment Management
- Describe Splunk Deployment Server
- Manage Forwarders Using Deployment Apps
- Configure Deployment Clients
- Configure Client Groups
- Monitor Forwarder Management Activities
- Default Parsing Pipeline
- Line Breaking Rules
- Timestamp Extraction
- Event Truncation and Size Limits
- Metadata Assignment
- Character Set and Encoding Handling
- Parsing Queue and Indexing Interaction
- Event line breaking fundamentals
- Line breaking configuration options
- Using LINE_BREAKER regex
- Line merging techniques
- Testing and validating line breaking
- Optimizing line breaking performance
- Timestamp Extraction
- Timestamp Formats
- Time Zone Handling
- Timestamp Assignment for Events Without Timestamps
- Timestamp Configuration Options
- Data Preview overview
- Accessing Data Preview
- Interpreting event extraction
- Validating event timestamps
- Validating event breaking
- Adjusting parsing settings
- Reviewing extracted fields
- Saving and proceeding
- Definition of data transformations
- Invocation of data transformations
- Transforms.conf configuration
- Types of data transformations
- Order of transformation execution
- Understanding props.conf and transforms.conf
- Configuring TRANSFORMS in props.conf
- Writing transforms.conf stanzas
- Masking raw data during indexing
- Deleting raw data during indexing
- Overriding sourcetype based on event values
- Overriding host based on event values
- Routing events to specific indexes based on content
- Preventing unwanted events from being indexed
- Testing and validating transforms
- SEDCMD syntax and placement
- Regex-based substitution
- Sed expression flags
- Order of processing
- Testing and validation
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for SPLK-1003, so none is invented.