How to become a Splunk Enterprise Certified Administrator ?

Walter Lee
3 min readFeb 28, 2021

I got a lot of questions after I passed my exam in 01/2021. So, like to write it up and share to help the readers more.

You need to pass below cert. exams in order: (

1/ SPLK-1001: Splunk Core Certified User
2/ SPLK-1002: Splunk Core Certified Power User
3/ SPLK-1003: Splunk Enterprise Certified Admin

The official track/doc is at

You can see the study guides, sample questions, how to register for exams, etc.

To study for these exams, you can try below:

1/ Splunk Fundamentals 1 (eLearning) -(Free)

There is a free pdf and videos. Make sure you remember the important highlights in this pdf. Often you will see questions to test your knowledge highlighted in this pdf. Some questions are pretty straight forward, but a few can be more tricky to test you really understand the concepts.

Sample q: p.7

2/ Splunk Fundamentals 2 — you can take Instructor-led or IOD ($2,000)

Check if your organization has any education allowance in your current Enterprise contract. You may be able to take the IOD for free with your company enterprise contract. Your Splunk account manager can help you check on this.

I took the IOD for free because of my organization. It is quite a lot to remember. I installed Splunk Enterprise free trial at (good for 60 days) and then practiced with a lot of labs.

Sample q: p.8
Walter Lee

GCP Expert and Champion, AWS Community Builder, MS Azure Trainer, CKA/S. Many X Certified in 4xClouds. Opinions are my own and not the views of my employer.