Splunk Cloud Platform

How is Splunk Cloud admin certification different from Splunk sys admin?

chints0357
Explorer

How is Splunk Cloud admin certification different from Splunk sys admin?

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

There are several differences between Splunk Enterprise and Splunk Cloud when it comes to administration.

1) You have no access to the file system/CLI

2) You have no access to the Cluster Manager

3) You have no access to the indexers

4) All admin tasks are performed via a search head UI or by installing an app.

5) All apps must pass vetting before they can be installed.  You will be able to install most(?) apps yourself, but some must be installed by Splunk Support.  Other apps are not supported on Splunk Cloud at all.

6) You have full control over your Splunk Enterprise configuration, but have limited control over your Splunk Cloud stack.  Some changes must be made by Splunk Support, while other changes cannot be done at all.

I'm sure I'm forgetting some things, but I hope you get the idea.

For more information, see https://docs.splunk.com/Documentation/SplunkCloud/9.0.2303/Admin/Intro

Splunk offers a class for Splunk Cloud admins.  See https://education.splunk.com/catalog?category=splunk-cloud-administration&_ga=2.91430044.745781403.1.....

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

After all that, I realized that you were asking about the certification, not administration.

The two certifications are very similar, but the Splunk Cloud Certified Admin cert focuses on tasks cloud admins can perform and ignores those they cannot (see my previous answer).  For specifics see the Certifications Exam Study Guide at https://www.splunk.com/en_us/resources/splunk-certification-exam-study-guide.html?301=/pdfs/training...

---
If this reply helps you, Karma would be appreciated.

chints0357
Explorer

Thanks, will explore further.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There are several differences between Splunk Enterprise and Splunk Cloud when it comes to administration.

1) You have no access to the file system/CLI

2) You have no access to the Cluster Manager

3) You have no access to the indexers

4) All admin tasks are performed via a search head UI or by installing an app.

5) All apps must pass vetting before they can be installed.  You will be able to install most(?) apps yourself, but some must be installed by Splunk Support.  Other apps are not supported on Splunk Cloud at all.

6) You have full control over your Splunk Enterprise configuration, but have limited control over your Splunk Cloud stack.  Some changes must be made by Splunk Support, while other changes cannot be done at all.

I'm sure I'm forgetting some things, but I hope you get the idea.

For more information, see https://docs.splunk.com/Documentation/SplunkCloud/9.0.2303/Admin/Intro

Splunk offers a class for Splunk Cloud admins.  See https://education.splunk.com/catalog?category=splunk-cloud-administration&_ga=2.91430044.745781403.1.....

---
If this reply helps you, Karma would be appreciated.
0 Karma

chints0357
Explorer

Yes.

Thanks for the clarifications.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...