Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Splunk
Exam Format
Registration
Validity
SPLK-3002 Exam Topics and Domains
SPLK-3002 is organized into 16 weighted domains. Expect to work with Event Analytics, Glass Table Editor, Multi-KPI Alert Engine, Service Analyzer, and more.
Introducing ITSI
ITSI Fundamentals
- Understand ITSI core functionality and purpose
- Navigate the ITSI interface effectively
- Identify key ITSI components and their uses
Glass Tables
Glass Table Fundamentals
- Understand glass table architecture and purpose
- Use glass tables for service monitoring
Glass Table Configuration
- Design effective glass tables
- Configure visualizations and widgets
- Implement interactive features
Managing Notable Events
Notable Events Concepts
- Understand notable event framework
- Configure multi-KPI alerts
- Manage event lifecycle
Notable Events Workflow
- Manage notable event lifecycle
- Create custom event views
- Implement event workflows
Investigating Issues with Deep Dives
Deep Dive Concepts
- Understand deep dive architecture
- Use deep dives for troubleshooting
Custom Deep Dives
- Create custom deep dives
- Configure swim lanes effectively
- Implement troubleshooting workflows
Installing and Configuring ITSI
ITSI Deployment
- Plan ITSI deployment
- Understand hardware requirements
- Identify deployment components
ITSI Installation and Data
- Install ITSI successfully
- Configure data inputs
- Integrate custom data sources
Designing Services
Service Design Planning
- Plan service implementations
- Design service hierarchies
- Identify and manage entities
Data Audit and Base Searches
Data Audit Process
- Perform data audits
- Identify KPIs from data
Base Search Design
- Design efficient base searches
- Optimize search performance
Implementing Services
Service Implementation
- Implement services from design
- Configure service properties
KPI Configuration
KPI Creation and Thresholds
- Create and configure KPIs
- Implement various threshold types
- Configure time policies
Entities and Modules
Entity Management
- Import and manage entities
- Use entities in KPI configuration
Module Usage
- Deploy and configure modules
- Use content packs effectively
Templates and Dependencies
Service Templates
- Create and manage service templates
- Apply templates to services
Service Dependencies
- Configure service dependencies
- Understand dependency impact on health scores
Anomaly Detection
Anomaly Detection Configuration
- Configure anomaly detection
- Manage anomaly events
- Tune detection sensitivity
Correlation and Multi KPI Searches
Correlation Searches
- Create correlation searches
- Configure multi-KPI alerts
- Manage event storage
Aggregation Policies
Aggregation Policy Configuration
- Create aggregation policies
- Configure smart mode
- Optimize event aggregation
Access Control
User Access Management
- Configure access controls
- Manage teams and permissions
- Implement security best practices
Administration and Maintenance
Backup and Maintenance
- Perform backup and restore
- Configure maintenance windows
Advanced Administration
- Create custom modules
- Troubleshoot ITSI issues
- Perform system maintenance
How do I earn this certification?
Passing SPLK-3002 earns the Splunk IT Service Intelligence Certified Admin certification. It sits in the IT Service Intelligence track.
- SPLK-4001 - Splunk Core Certified Consultant
- SPLK-3001 - Splunk Enterprise Security Certified Admin
- SPLK-3001 - Splunk Enterprise Security Certified Admin Complementary security monitoring skills
- SPLK-2001 - Splunk Certified DeveloperCustom app and integration development
- SPLK-3003 - Splunk Core Certified Advanced Power UserAdvanced search and dashboard skills
- SPLK-5001 - Splunk O11y Cloud Certified Metrics UserCloud observability and metrics monitoring
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
Use the official PlanetCert Practice Test alongside the study plan below to prepare efficiently for SPLK-3002.
What's changed on this exam?
- ACTIVE
- Last content update: 2024-06-16
- Glass Tables Beta to GA Increased focus on glass table configuration in exam • Release date: 2024-03-01
- Service Analyzer Enhanced UI New navigation patterns may be tested • Release date: 2024-06-01
- KPI Base Searches Performance Optimized Best practices for base search design emphasized • Release date: 2024-04-15
Who should take this exam?
This exam is typically taken by Splunk platform administrators and IT operations professionals.
- Working knowledge and experience as either Splunk Cloud or Splunk Enterprise Administrator
- At least 6 months of hands-on Splunk experience
- Understanding of IT service management principles
- Experience with IT operations and monitoring