Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
SPLUNK

Splunk Enterprise Certified Architect

SPLK-2002

The Splunk Enterprise Certified Architect certification validates your ability to plan, deploy, and manage complex Splunk Enterprise environments. It covers best practices for data collection, sizing, and distributed deployment, as well as managing and troubleshooting indexer and search head clustering. This expert-level credential is for architects who design resilient, scalable Splunk deployments that deliver reliable insights.

648 practice questions · Updated 2026-07-30

6Domains
33Objectives
201Concepts
648Questions

SPLK-2002 Curriculum

Every domain, objective, and concept the SPLK-2002 exam measures.

Gather Requirements

6 concepts · 24 questions
  1. Identify environment characteristics
  2. Assess data volume and growth
  3. Profile user roles and access needs
  4. Clarify functional and non-functional requirements
  5. Apply requirements gathering checklists
  6. Utilize resources for requirement collection

Plan Deployment

2 concepts · 21 questions
  1. Deployment Plan Overview
  2. Deployment Process Steps

Size and Estimate Storage

5 concepts · 12 questions
  1. Index Design Fundamentals
  2. Index Size Estimation
  3. Non-Smart Store Storage Estimation
  4. Sizing Considerations
  5. Disk Storage Requirements

Define Hardware Requirements

3 concepts · 6 questions
  1. Hardware Requirements for Splunk Components
  2. Sizing and Topology for Splunk Enterprise Security (ES)
  3. Sizing and Topology for Splunk IT Service Intelligence (ITSI)

Identify Apps and Security

4 concepts · 14 questions
  1. Identify relevant apps
  2. Describe security measures
  3. Describe privacy measures
  4. Describe integrity measures

  1. Search head clustering prerequisites
  2. Search head cluster member requirements
  3. Deployment server and search head cluster integration
  4. Search head cluster and indexer connectivity
  5. Search head cluster and authentication
  6. Search head cluster and license master
  7. Search head cluster and forwarder requirements
  8. Search head cluster and knowledge objects
  9. Search head cluster and search factor
  10. Search head cluster and replication factor
  11. Search head cluster and captaincy
  12. Search head cluster and rolling upgrades
  1. Forwarder Tier Design Principles
  2. Forwarder Types and Roles
  3. Data Routing and Load Balancing
  4. Forwarder Scaling and Capacity Planning
  5. Security and Compliance in Forwarder Design
  6. Monitoring and Troubleshooting Forwarders
  7. Forwarder Deployment Patterns
  1. Configuration management overview
  2. Configuration file types and precedence
  3. Configuration directories and apps
  4. Using the CLI for configuration
  5. Using configuration files for settings
  6. Configuration deployment and propagation
  7. Troubleshooting configuration issues
  1. Identify cluster master role
  2. Identify indexer role in clusters
  3. Identify search head role in clusters
  4. Identify deployment server role
  5. Identify license master role
  6. Identify monitoring console role
  7. Identify cluster member roles
  1. License Master role in clustering
  2. License Master configuration steps
  3. License usage monitoring
  4. License violation handling
  5. License Master redundancy

  1. Single-site indexer cluster architecture
  2. Cluster configuration prerequisites
  3. Master node configuration
  4. Peer node configuration
  5. Search head configuration
  6. Cluster bundle management
  7. Replication and search factor settings
  8. Cluster health monitoring
  9. Troubleshooting common cluster issues
  1. Multisite indexer cluster architecture
  2. Site and replication factor configuration
  3. Cluster master and site awareness
  4. Data replication and search behavior
  5. Multisite cluster deployment considerations

Multisite indexer cluster configuration

8 concepts · 14 questions
  1. Multisite indexer cluster architecture
  2. Multisite cluster configuration prerequisites
  3. Configuring multisite indexer cluster settings
  4. Multisite cluster master configuration
  5. Multisite cluster peer configuration
  6. Multisite cluster search head configuration
  7. Verifying multisite cluster health and replication
  8. Troubleshooting multisite cluster issues
  1. Cluster migration planning
  2. Upgrade prerequisites
  3. Rolling upgrade procedure
  4. Downtime upgrade procedure
  5. Post-upgrade validation
  6. Rollback considerations
  1. Storage utilization options overview
  2. Volume-based storage utilization
  3. Replication factor and storage
  4. Search factor and storage
  5. Bucket management and storage
  6. Storage capacity planning
  7. Monitoring storage utilization

Peer offline and decommission

6 concepts · 22 questions
  1. Peer offline detection
  2. Impact of peer offline
  3. Peer decommissioning process
  4. Decommission vs. offline
  5. Bucket rebalancing after decommission
  6. Monitoring peer status

Master app bundles

5 concepts · 18 questions
  1. Purpose of master app bundles
  2. Bundle creation and content
  3. Bundle distribution and replication
  4. Bundle versioning and updates
  5. Troubleshooting bundle issues
  1. Monitoring Console overview
  2. Accessing Monitoring Console
  3. Indexer cluster dashboards
  4. Interpreting cluster health metrics
  5. Monitoring replication and search
  6. Alerting and thresholds
  7. Troubleshooting with Monitoring Console

Splunk search head cluster overview

6 concepts · 26 questions
  1. Search head cluster definition
  2. Search head cluster components
  3. Search head cluster roles
  4. Search head cluster benefits
  5. Search head cluster limitations
  6. Search head cluster deployment overview

Search head cluster configuration

8 concepts · 14 questions
  1. Search head cluster configuration overview
  2. Prerequisites for search head clustering
  3. Initial search head cluster setup
  4. Adding and removing search head cluster members
  5. Search head cluster captaincy management
  6. Search head cluster configuration files
  7. Search head cluster deployment and replication
  8. Search head cluster monitoring and troubleshooting

Search head cluster deployer

4 concepts · 21 questions
  1. Deployer role and function
  2. Deployer setup and configuration
  3. App and configuration deployment
  4. Deployment best practices

Captaincy transfer

5 concepts · 24 questions
  1. Captaincy transfer overview
  2. Initiating captaincy transfer
  3. Automatic captaincy transfer
  4. Verifying captaincy transfer
  5. Impact on cluster operations
  1. Prerequisites for adding a search head
  2. Adding a search head to a cluster
  3. Verifying search head addition
  4. Pre-decommissioning checks
  5. Decommissioning a search head
  6. Post-decommissioning cleanup

KV Store collection in Splunk clusters

4 concepts · 22 questions
  1. KV Store replication in Search Head Clusters
  2. KV Store configuration in clustered environments
  3. KV Store data consistency and conflict resolution
  4. Monitoring and troubleshooting KV Store in clusters

Use limits.conf to improve performance

6 concepts · 15 questions
  1. Understanding limits.conf
  2. Key settings for performance
  3. Tuning search limits
  4. Tuning indexing limits
  5. Tuning output and input limits
  6. Applying changes and best practices

Use indexes.conf to manage bucket size

5 concepts · 10 questions
  1. Understanding bucket size in Splunk
  2. Configuring bucket size via indexes.conf
  3. Impact of bucket size on search performance
  4. Impact of bucket size on storage and retention
  5. Best practices for bucket size tuning

Tune props.conf

7 concepts · 20 questions
  1. props.conf overview
  2. Key settings for performance
  3. Tuning timestamp extraction
  4. Tuning event breaking
  5. Tuning segmentation and indexing
  6. Using transforms for preprocessing
  7. Testing and validating changes

Improve search performance

5 concepts · 16 questions
  1. Search performance factors
  2. Search optimization techniques
  3. Search job inspection
  4. Search concurrency and limits
  5. Distributed search tuning

Diagnostic Resources and Logs

6 concepts · 18 questions
  1. Splunk diagnostic resources
  2. Splunk diagnostic tools
  3. Internal log files
  4. Log file locations
  5. Internal indexes
  6. Index usage and monitoring

Common Issues and Troubleshooting

8 concepts · 31 questions
  1. License issue identification
  2. License troubleshooting steps
  3. Crash issue detection
  4. Crash troubleshooting techniques
  5. Input issue diagnosis
  6. Input troubleshooting actions
  7. Search issue identification
  8. Search troubleshooting methods

Performance and Monitoring

6 concepts · 22 questions
  1. Job Inspector Overview
  2. Accessing Job Inspector
  3. Interpreting Job Inspector Metrics
  4. Analyzing Search Components
  5. Identifying Performance Bottlenecks
  6. Using Job Inspector for Troubleshooting

Forwarding and Deployment

6 concepts · 21 questions
  1. Diagnosing forwarding issues
  2. Resolving forwarding configuration errors
  3. Monitoring forwarder health and performance
  4. Troubleshooting deployment server connectivity
  5. Resolving deployment app and policy issues
  6. Verifying deployment server operations
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for SPLK-2002, so none is invented.