Training + Certification Discussions

Splunk Certification : Sample questions and commonly asked scenarios

koshyk
Super Champion

Friends,
I couldn't find much material/documents to prepare for Splunk Certification.
Is there anyway I can get some previous questions/scenario's that are being asked for Splunk Certification lab?

Thanks in advance

Tags (2)
1 Solution

lguinn2
Legend

You could take a look at the description for the Architect Certification Lab

As of 16-Sep-2013, the description says

Installation and Infrastructure

- Install a search head, deployment server and indexers

- Perform a scripted installation of universal forwarders

Configuration, Collection, and Comprehension

- Deploy all specified configurations via deployment server

- Gather data from forwarders and send to multiple indexes depending on use case

- Configure and confirm index-time knowledge

- Create search time field extractions

Searching and Reporting

- Create searches and dashboards for each required use case

Since this is a practicum and not a multiple-choice test, you need to be able to do these things, not answer questions. During the exam, you will be able to access documentation and answers.splunk.com

Practice doing the tasks that you learned in class - setting up indexers, using the deployment server, creating indexes, etc.

Publishing any detailed scenario is giving too much away.

View solution in original post

lguinn2
Legend

You could take a look at the description for the Architect Certification Lab

As of 16-Sep-2013, the description says

Installation and Infrastructure

- Install a search head, deployment server and indexers

- Perform a scripted installation of universal forwarders

Configuration, Collection, and Comprehension

- Deploy all specified configurations via deployment server

- Gather data from forwarders and send to multiple indexes depending on use case

- Configure and confirm index-time knowledge

- Create search time field extractions

Searching and Reporting

- Create searches and dashboards for each required use case

Since this is a practicum and not a multiple-choice test, you need to be able to do these things, not answer questions. During the exam, you will be able to access documentation and answers.splunk.com

Practice doing the tasks that you learned in class - setting up indexers, using the deployment server, creating indexes, etc.

Publishing any detailed scenario is giving too much away.

koshyk
Super Champion

thank you lguinn.

koshyk
Super Champion

PS: I have done the courses (pre-req), so the question is specifically for preparation material and previous questions etc..

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...