SPLK-1005 · ● Active · Professional · Splunk (Cisco)
Validates ability to deploy, configure, manage, and troubleshoot Splunk Cloud instances in production environments. Covers Cloud-specific architecture, administration, data ingestion, user management, monitoring, and security/compliance.
Exam facts
| Field | Value |
|---|---|
| Cost | USD $130 |
| Duration | 75 minutes |
| Questions | 60 (all scored) |
| Passing | 700 / 1000 scaled |
| Format | Multiple choice + multiple response |
| Delivery | Pearson VUE |
| Languages | English |
| Valid | 3 years |
| Renewal | Retake exam OR complete higher Splunk certification |
| Prerequisites | Splunk Core Certified Power User (recommended) |
| Released | 2024 |
| Retiring | N/A |
Vendor source — Splunk Cloud Certified Admin ↗
Test blueprint — Splunk Test Blueprint - Cloud Admin PDF ↗
Exam registration — Pearson VUE - Splunk Certifications ↗
About
The Splunk Cloud Certified Admin qualification validates hands-on expertise in administering Splunk Cloud deployments. Launched in 2024, this credential is designed for IT operations teams, cloud engineers, and data platform administrators migrating from on-premises Splunk Enterprise or adopting Splunk Cloud as their primary SIEM and observability platform. Unlike Enterprise Admin (SPLK-1003), Cloud Admin addresses Cloud-native architecture, Workload Pool pricing, Cloud Edge Processors, federated search, and Cloud-specific security controls. Core focus: data input management, forwarder configuration, user/role provisioning, index lifecycle, monitoring/alerting, and compliance in multi-tenant cloud environments.
Domain context — Observability
One-line platform for collecting, indexing, and analyzing machine-generated data at scale. Splunk dominates the SIEM/observability market; Cloud Admin certification is foundational for role advancement in cloud-native SOC, SRE, and IT Ops verticals.
Read full deep dive — Splunk Cloud Ecosystem → (file not yet created)
Topics covered
Based on the official exam blueprint:
- Splunk Cloud Architecture & Deployment (15%) — Cloud vs. Enterprise differences, deployment models, multi-tenancy, Cloud resource provisioning, Workload Pool model
- Data Input & Ingestion (20%) — Forwarder configuration, HTTP Event Collector (HEC), Splunk Cloud data pipelines, input routing, parsing rules, index assignment
- User & Role Management (15%) — Identity and access control, SAML/LDAP integration, role-based access, permission model, user provisioning workflows
- Index Management & Data Lifecycle (12%) — Index creation/deletion, data routing, bucket management, retention policies, archive/rollover strategies
- Monitoring, Alerting & Reporting (13%) — Health checks, alert configuration, trigger conditions, notification routing, dashboard design, scheduled reports
- Splunk Cloud Edge Processor (10%) — Edge Processor deployment, use cases, configuration, data filtering at the edge
- Security & Compliance (10%) — Cloud security posture, encryption (data in transit/at rest), audit logging, compliance frameworks (SOC 2, HIPAA, PCI), backup/disaster recovery
- Troubleshooting & Problem Resolution (5%) — Log ingestion diagnostics, performance tuning, common misconfigurations, Cloud-specific support tools
Source: Official exam blueprint ↗
Common skills at Observability · Professional
Shared content for the Observability domain at Professional level — not specific to this cert.
- Event data pipeline architecture (collection → indexing → search)
- Log aggregation and parsing (regex, structured extraction, field aliasing)
- Alerting framework design (detection logic, thresholds, escalation)
- Multi-source data correlation and root-cause analysis
- Time-series data and anomaly detection fundamentals
- Cloud platform security and compliance auditing
Recommended courses at Observability · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| Splunk Official | Splunk Cloud Administration Fundamentals | Free trial / Paid | ↗ |
| Splunk Official | Splunk Cloud Certification Track | Varies | ↗ |
| Udemy | SPLK-1005 Splunk Cloud Certified Admin | $12–$80 | ↗ |
| Pluralsight | Splunk Cloud Administration | $35–$49/month | ↗ |
Course-selection rule: Each course must be specifically for SPLK-1005 and Cloud Admin topics (not Enterprise Admin or general Splunk). Splunk's official training is strongly recommended due to Cloud-specific coverage.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| Splunk Test Drive | Splunk Cloud Free Sandbox + Labs | Free | ↗ |
| ExamTopics | SPLK-1005 Community Q&A | Free / Freemium | ↗ |
| Udemy | SPLK-1005 Practice Tests | $12–$50 | ↗ |
Books
| Title | Author | Publisher | Year | URL |
|---|---|---|---|---|
| Splunk Cloud Administration | (Official) | Splunk Press | 2024 | ↗ |
Book rule: No independent third-party study guides for SPLK-1005 yet (as of May 2026). Official Splunk documentation and the test blueprint serve as primary reference material. The exam is recent and certification ecosystem is still maturing; candidates rely on Splunk Education courses and hands-on Cloud deployments.
Typical job titles at Observability · Professional
Splunk Cloud Engineer · Splunk Cloud Administrator · Cloud SIEM Engineer · Senior Splunk Administrator (Cloud focus) · Observability Engineer (Splunk Cloud) · Cloud Operations Engineer
(Job titles drawn from current job-board postings and vendor sites listing SPLK-1005 as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $125,000 – $185,000 | Glassdoor ↗ · Levels.fyi ↗ · ZipRecruiter ↗ |
| ZAR | R2,200,000 – R3,200,000 | No region-specific Splunk Cloud role data; use general Cloud Engineer conversion from USD ranges |
| GBP | £95,000 – £140,000 | No region-specific Splunk Cloud role data; use general Cloud Engineer conversion from USD ranges |
Salary rule: SPLK-1005 is a new (2024) and relatively niche certification. Salary data reflects generic "Splunk Engineer" and "Cloud Engineer" roles. Region-specific ZAR and GBP data unavailable for Cloud-specific roles; use USD baseline and regional cloud engineer benchmarks. Salaries vary significantly by geography, enterprise SIEM adoption rates, and whether Splunk Cloud is a primary platform (higher in NA/EU; lower in developing markets).
Skills validated
Cert-specific — what this exam actually tests, distinct from the shared "Common skills" above.
- Splunk Cloud architecture and deployment patterns
- Splunk Cloud vs. Enterprise administration differences
- HTTP Event Collector (HEC) configuration and security
- Universal Forwarder and Heavy Forwarder management in Cloud contexts
- Workload Pool pricing model and resource allocation
- Splunk Cloud Edge Processor deployment and troubleshooting
- SAML/LDAP authentication integration in Cloud
- Index lifecycle and data retention policies
- Federated search (Cloud + on-premises hybrid)
- Splunk Cloud security posture and compliance controls
- Monitoring, alerting, and troubleshooting Cloud deployments
- Disaster recovery and backup strategies in Cloud
Related certifications
- Prerequisite for: Splunk Enterprise Certified Admin (SPLK-1003) ↗ (file not yet created) · Splunk Core Certified Power User (SPLK-1004) ↗ (file not yet created)
- Stacks with: Other Splunk Cloud or Enterprise certifications (ES Admin, Architect)
- Equivalents at this level: Azure Sentinel Administrator · AWS CloudWatch + Security Hub (no single cert equivalent)
- Vendor overview: Splunk Vendor Deep Dive ↗ (file not yet created)
Sources
- Splunk Cloud Certified Admin official page
- Splunk Test Blueprint - Cloud Admin PDF
- Splunk Training & Certification
- Pearson VUE - Splunk Certifications
- Glassdoor - Splunk Engineer Salaries
- Levels.fyi - Splunk Salaries
- ZipRecruiter - Splunk Engineer Salary
Last verified: 2026-05-01
Parent ecosystem: Splunk Cloud Ecosystem (file not yet created)
Parent domain: Observability (file not yet created)
Vendor overview: Splunk Vendor Overview (file not yet created)