Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Splunk
Exam Format
Registration
Validity
SPLK-1005 Exam Topics and Domains
SPLK-1005 is organized into 13 weighted domains. Expect to work with Splunk Cloud Platform, inputs.conf, props.conf, Splunk forwarders, and more.
Splunk Cloud Overview
Describe Cloud topology
- Understand the architecture of Splunk Cloud
- Identify the components and their roles in cloud topology
Describe tasks managed by the Splunk cloud administrator
- Identify tasks that cloud administrators are responsible for
- Understand limitations compared to on-prem administrators
List the primary differences between Splunk Cloud and Splunk Enterprise
- Compare and contrast Splunk Cloud with Splunk Enterprise
- Understand key architectural and operational differences
List differences between Self-Service Cloud and Managed Cloud
- Distinguish between Self-Service and Managed Cloud offerings
- Understand when to use each service tier
Index Management
Define a Splunk index
- Define what a Splunk index is
- Understand the role of indexes in data organization
Create indexes in cloud
- Create new indexes in Splunk Cloud
- Configure index settings appropriately
Delete data from an index
- Understand how to delete data from indexes
- Know the implications and limitations of data deletion
Monitor indexing activities
- Monitor indexing activities and performance
- Identify and resolve indexing issues
User Authentication and Authorization
Administer Splunk user roles
- Create and manage user roles
- Assign appropriate permissions to roles
Integrate Splunk with LDAP, Active Directory, or SAML
- Configure external authentication methods
- Integrate Splunk Cloud with enterprise identity systems
Splunk Configuration Files
Review Splunk configuration files and directories
- Identify key Splunk configuration files
- Understand the directory structure and organization
Review configuration file precedence
- Understand configuration file precedence
- Resolve configuration conflicts
Review index and search time processes
- Understand the difference between index-time and search-time processing
- Know when to apply configurations at each phase
Getting Data in Cloud
List Splunk forwarder types
- Identify different types of Splunk forwarders
- Understand when to use each forwarder type
Describe the role of forwarders
- Describe the role of forwarders in data collection
- Understand forwarder capabilities and features
Configure a forwarder to Splunk Cloud
- Configure forwarders to send data to Splunk Cloud
- Implement secure forwarder connections
Test the forwarder connection
- Verify forwarder connectivity to Splunk Cloud
- Troubleshoot connection issues
Describe optional forwarder settings
- Configure optional forwarder settings
- Optimize forwarder performance and reliability
Forwarder Management
Describe Splunk Deployment Server
- Understand the role of the Deployment Server
- Identify key components and concepts
Explain the use of forwarder management
- Explain the benefits of centralized forwarder management
- Understand forwarder management capabilities
Configure forwarders to be deployment clients
- Configure forwarders as deployment clients
- Verify deployment client registration
Managing forwarders using deployment apps
- Create and manage deployment apps
- Target apps to specific forwarders
Monitor Inputs
Describe the Splunk process for inputting data
- Describe the Splunk data input process
- Understand the data pipeline phases
Create file and directory monitor inputs
- Configure file and directory monitor inputs
- Understand monitor input options
Use optional settings for monitor inputs
- Configure optional monitor input settings
- Optimize monitor input performance
Network and Other Inputs
Create network (TCP and UDP) inputs
- Configure TCP and UDP network inputs
- Understand network input use cases
Create a basic scripted input
- Configure scripted inputs
- Schedule script execution
Describe optional settings for network inputs
- Configure optional network input settings
- Optimize network input configuration
Identify Windows input types and uses
- Identify Windows-specific input types
- Configure Windows inputs
Use the HTTP Event Collector (HEC) to get data into Splunk
- Configure HTTP Event Collector
- Send data using HEC
Fine-tuning Inputs
Describe the default processing that occurs during the input phase
- Understand default input phase processing
- Identify metadata assigned during input
Configure input phase options, such as sourcetype fine-tuning and character set encoding
- Configure input phase options
- Override default metadata assignments
Parsing Phase and Data Preview
Describe the default processing that occurs during parsing
- Understand parsing phase processing
- Identify default parsing operations
Optimize and configure event line breaking
- Configure event line breaking
- Optimize event boundary detection
Explain how timestamps and time zones are extracted or assigned to events
- Configure timestamp extraction
- Handle timezone variations
Use Data Preview to validate event creation during the parsing phase
- Use Data Preview to validate parsing
- Test parsing configuration before deployment
Manipulating Raw Data
Explain how data transformations are defined and invoked
- Define data transformations
- Understand how transformations are invoked
Use transformations with props.conf and transforms.conf to modify raw data
- Configure data transformations
- Modify raw data using transformations
Use SEDCMD to modify raw data
- Use SEDCMD to modify raw data
- Apply regular expressions for data transformation
Installing and Managing Apps
Review the process for installing apps
- Install apps in Splunk Cloud
- Understand cloud-specific app installation requirements
Describe private apps
- Understand private apps
- Install and manage private apps
Describe how apps are managed
- Manage apps in Splunk Cloud
- Update and remove apps
Working with Splunk Cloud Support
Isolate problems before contacting Splunk Cloud Support
- Isolate problems before contacting support
- Gather relevant troubleshooting information
Define the process for working with Splunk Cloud Support
- Engage with Splunk Cloud Support effectively
- Understand support processes and requirements
How do I earn this certification?
Passing SPLK-1005 earns the Splunk Cloud Certified Admin certification. It sits in the Cloud Administration track.
- SPLK-3002 - Splunk IT Service Intelligence Certified AdminAdvanced admin certification for ITSI
- SPLK-3003 - Splunk Enterprise Security Certified AdminSecurity operations specialization
- SPLK-1002 - Splunk Core Certified Power UserCore platform power user skills
- SPLK-1003 - Splunk Enterprise Certified AdminOn-premises administration skills
- SPLK-2002 - Splunk Enterprise Certified ArchitectAdvance to architecture role
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for SPLK-1005 is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
- ACTIVE
- Last content update: 2024-12-01
- HTTP Event Collector (HEC) Enhanced in 9.2 Updated HEC capabilities covered in Domain 8 • Release date: 2024-10-20
- Deployment Server 9.2 Enhanced forwarder management features in Domain 6 • Release date: 2024-10-20
- Data Preview Enhanced UI in 9.2 Updated interface for Domain 10 topics • Release date: 2024-10-20
- SAML Authentication Enhanced in 9.2 New security features relevant to Domain 3 • Release date: 2024-10-20
Who should take this exam?
This exam is typically taken by Splunk Cloud administrators and Platform administrators migrating to cloud.
- Hands-on experience with Splunk Cloud Platform
- Understanding of data input and forwarder management
- Familiarity with Splunk configuration files