
Splunk Enterprise Certified Architect
The Splunk Enterprise Certified Architect certification validates your ability to plan, deploy, and manage complex Splunk Enterprise environments. It covers best practices for data collection, sizing, and distributed deployment, as well as managing and troubleshooting indexer and search head clustering. This expert-level credential is for architects who design resilient, scalable Splunk deployments that deliver reliable insights.
648 practice questions · Updated 2026-07-30
6Domains
33Objectives
201Concepts
648Questions
SPLK-2002 Curriculum
Every domain, objective, and concept the SPLK-2002 exam measures.
- Identify environment characteristics
- Assess data volume and growth
- Profile user roles and access needs
- Clarify functional and non-functional requirements
- Apply requirements gathering checklists
- Utilize resources for requirement collection
- Deployment Plan Overview
- Deployment Process Steps
- Index Design Fundamentals
- Index Size Estimation
- Non-Smart Store Storage Estimation
- Sizing Considerations
- Disk Storage Requirements
- Hardware Requirements for Splunk Components
- Sizing and Topology for Splunk Enterprise Security (ES)
- Sizing and Topology for Splunk IT Service Intelligence (ITSI)
- Identify relevant apps
- Describe security measures
- Describe privacy measures
- Describe integrity measures
- Search head clustering prerequisites
- Search head cluster member requirements
- Deployment server and search head cluster integration
- Search head cluster and indexer connectivity
- Search head cluster and authentication
- Search head cluster and license master
- Search head cluster and forwarder requirements
- Search head cluster and knowledge objects
- Search head cluster and search factor
- Search head cluster and replication factor
- Search head cluster and captaincy
- Search head cluster and rolling upgrades
- Forwarder Tier Design Principles
- Forwarder Types and Roles
- Data Routing and Load Balancing
- Forwarder Scaling and Capacity Planning
- Security and Compliance in Forwarder Design
- Monitoring and Troubleshooting Forwarders
- Forwarder Deployment Patterns
- Configuration management overview
- Configuration file types and precedence
- Configuration directories and apps
- Using the CLI for configuration
- Using configuration files for settings
- Configuration deployment and propagation
- Troubleshooting configuration issues
- Identify cluster master role
- Identify indexer role in clusters
- Identify search head role in clusters
- Identify deployment server role
- Identify license master role
- Identify monitoring console role
- Identify cluster member roles
- License Master role in clustering
- License Master configuration steps
- License usage monitoring
- License violation handling
- License Master redundancy
- Single-site indexer cluster architecture
- Cluster configuration prerequisites
- Master node configuration
- Peer node configuration
- Search head configuration
- Cluster bundle management
- Replication and search factor settings
- Cluster health monitoring
- Troubleshooting common cluster issues
- Multisite indexer cluster architecture
- Site and replication factor configuration
- Cluster master and site awareness
- Data replication and search behavior
- Multisite cluster deployment considerations
- Multisite indexer cluster architecture
- Multisite cluster configuration prerequisites
- Configuring multisite indexer cluster settings
- Multisite cluster master configuration
- Multisite cluster peer configuration
- Multisite cluster search head configuration
- Verifying multisite cluster health and replication
- Troubleshooting multisite cluster issues
- Cluster migration planning
- Upgrade prerequisites
- Rolling upgrade procedure
- Downtime upgrade procedure
- Post-upgrade validation
- Rollback considerations
- Storage utilization options overview
- Volume-based storage utilization
- Replication factor and storage
- Search factor and storage
- Bucket management and storage
- Storage capacity planning
- Monitoring storage utilization
- Peer offline detection
- Impact of peer offline
- Peer decommissioning process
- Decommission vs. offline
- Bucket rebalancing after decommission
- Monitoring peer status
- Purpose of master app bundles
- Bundle creation and content
- Bundle distribution and replication
- Bundle versioning and updates
- Troubleshooting bundle issues
- Monitoring Console overview
- Accessing Monitoring Console
- Indexer cluster dashboards
- Interpreting cluster health metrics
- Monitoring replication and search
- Alerting and thresholds
- Troubleshooting with Monitoring Console
- Search head cluster definition
- Search head cluster components
- Search head cluster roles
- Search head cluster benefits
- Search head cluster limitations
- Search head cluster deployment overview
- Search head cluster configuration overview
- Prerequisites for search head clustering
- Initial search head cluster setup
- Adding and removing search head cluster members
- Search head cluster captaincy management
- Search head cluster configuration files
- Search head cluster deployment and replication
- Search head cluster monitoring and troubleshooting
- Deployer role and function
- Deployer setup and configuration
- App and configuration deployment
- Deployment best practices
- Captaincy transfer overview
- Initiating captaincy transfer
- Automatic captaincy transfer
- Verifying captaincy transfer
- Impact on cluster operations
- Prerequisites for adding a search head
- Adding a search head to a cluster
- Verifying search head addition
- Pre-decommissioning checks
- Decommissioning a search head
- Post-decommissioning cleanup
- KV Store replication in Search Head Clusters
- KV Store configuration in clustered environments
- KV Store data consistency and conflict resolution
- Monitoring and troubleshooting KV Store in clusters
- Understanding limits.conf
- Key settings for performance
- Tuning search limits
- Tuning indexing limits
- Tuning output and input limits
- Applying changes and best practices
- Understanding bucket size in Splunk
- Configuring bucket size via indexes.conf
- Impact of bucket size on search performance
- Impact of bucket size on storage and retention
- Best practices for bucket size tuning
- props.conf overview
- Key settings for performance
- Tuning timestamp extraction
- Tuning event breaking
- Tuning segmentation and indexing
- Using transforms for preprocessing
- Testing and validating changes
- Search performance factors
- Search optimization techniques
- Search job inspection
- Search concurrency and limits
- Distributed search tuning
- Splunk diagnostic resources
- Splunk diagnostic tools
- Internal log files
- Log file locations
- Internal indexes
- Index usage and monitoring
- License issue identification
- License troubleshooting steps
- Crash issue detection
- Crash troubleshooting techniques
- Input issue diagnosis
- Input troubleshooting actions
- Search issue identification
- Search troubleshooting methods
- Job Inspector Overview
- Accessing Job Inspector
- Interpreting Job Inspector Metrics
- Analyzing Search Components
- Identifying Performance Bottlenecks
- Using Job Inspector for Troubleshooting
- Diagnosing forwarding issues
- Resolving forwarding configuration errors
- Monitoring forwarder health and performance
- Troubleshooting deployment server connectivity
- Resolving deployment app and policy issues
- Verifying deployment server operations
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for SPLK-2002, so none is invented.