SPLK-2003 · ● Legacy · Professional · Splunk (Cisco)
Legacy status: This certification was reclassified as Legacy by Splunk as of January 1, 2026. Exam content will no longer be actively maintained or updated to reflect product changes or releases. However, the certification remains valid and relevant for professionals working with existing SOAR deployments.
Exam facts
| Field | Value |
|---|---|
| Cost | USD $125 (standard); $25 at Splunk .conf events |
| Duration | 90 minutes |
| Questions | 60 (multiple-choice + multiple-response) |
| Passing | ~70% (Splunk does not publish exact threshold) |
| Format | Multiple choice / Multiple response |
| Delivery | Pearson VUE (proctored center or OnVUE online) |
| Languages | English |
| Valid | 3 years from exam pass date |
| Renewal | Pass higher-level cert or retake exam |
| Prerequisites | None (hands-on SOAR experience recommended) |
| Released | 2019 (as Phantom Admin); rebranded to SOAR Certified Automation Developer |
| Retiring | No announced retirement date (legacy status means no new releases) |
Vendor source — Splunk SOAR Certified Automation Developer ↗
Official exam guide — Splunk Certification Exam Study Guide ↗
Exam blueprint — Test Blueprint: SOAR Automation Developer ↗
Pearson VUE registration — Splunk Exams ↗
About
The Splunk SOAR Certified Automation Developer (formerly Splunk Phantom Certified Admin) demonstrates the ability to install, configure, and operate Splunk SOAR servers, integrate them with Splunk Enterprise and Enterprise Security, and design, create, test, and debug security automation playbooks. This professional-level cert targets SOC engineers, security operations specialists, and incident response practitioners responsible for orchestrating multi-tool security workflows. Released in 2019 as part of Splunk's acquisition of Phantom (a leading open SOAR platform), it reclassified to Legacy status in January 2026 as Splunk consolidates SOAR certification offerings.
Domain context — Security/SOAR
Security Orchestration, Automation, and Response (SOAR) is a specialized cybersecurity domain focused on automating repetitive incident response tasks, orchestrating third-party tool integrations, and reducing alert fatigue in Security Operations Centers (SOCs). SOAR platforms like Splunk SOAR connect 300+ security and IT tools, enabling analysts to respond to threats in minutes rather than hours.
Read full deep dive — Splunk Ecosystem →
Topics covered
The exam blueprint reflects the full lifecycle of SOAR administration and playbook development:
- Deployment, Installation, and Initial Configuration (5%) — Server setup, prerequisites, configuration
- User Management and Multi-tenancy (5%) — Role-based access control, tenant isolation
- Apps, Assets, and Playbooks (5%) — Integrated apps, asset management, playbook library
- Analyst Queue (5%) — Managing incident triage and work assignment
- The Investigation Page (10%) — Evidence collection, timeline, forensic workflows
- Case Management and Workbooks (5%) — Case lifecycle, workbook templates
- Customizations (5%) — Custom apps, fields, automation extensions
- System Maintenance (5%) — Backups, updates, monitoring, health checks
- Introduction to Playbooks (5%) — Playbook concepts and design patterns
- Visual Playbook Editor (5%) — Drag-and-drop workflow design, palette tools
- Logic, Filters, and User Interaction (5%) — Conditional branching, prompt actions, approval workflows
- Formatted Output and Data Access (5%) — Result formatting, artifacts, data output
- Modular Playbook Development (5%) — Reusable components, sub-playbooks, templates
- Custom Lists and Data Routing (5%) — Custom data models, routing logic
- Configuring External Splunk Search (5%) — Splunk query integration, scheduled searches
- Integrating SOAR into Splunk (10%) — Alert-to-case workflows, ES integration
- Custom Coding (5%) — Python custom code blocks, libraries
- Using REST (5%) — REST API calls, authentication, response parsing
Source: Official exam blueprint ↗
Common skills at Security/SOAR · Professional
Shared competencies for the Security/SOAR domain at Professional level — not specific to this cert.
- Playbook architecture design — orchestrating multi-step incident response workflows across security tools
- API integration patterns — REST/webhook connectors to SIEM, threat intelligence, ticketing, and communication platforms
- Conditional logic and automation — if-then rules, parallel execution, loop constructs, error handling
- Python scripting for security — custom code within playbooks to enrich data, parse logs, and handle edge cases
- Case management and triage — intake, assignment, escalation, and closure workflows
- Third-party tool integration — connecting security stacks (Splunk ES, ServiceNow, Slack, PagerDuty, threat feeds, etc.)
- Alert fatigue reduction — tuning detection logic, implementing smart filtering, and playbook-driven deduplication
Recommended courses at Security/SOAR · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| Splunk Education (Official) | Introduction to Splunk SOAR (eLearning) | Free | ↗ |
| Splunk Education (Official) | Developing SOAR Playbooks | ~$600–800 | ↗ |
| Splunk Education (Official) | Advanced SOAR Implementation | ~$1000–1200 | ↗ |
| Udemy | Splunk SOAR Certified Dev SPLK-2003: Practice Tests 2026 | $15–50 | ↗ |
| Udemy | Splunk SOAR Certified Automation Developer Practice Tests | $15–50 | ↗ |
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| Splunk (Official) | Sample questions in Certification Study Guide | Free | ↗ |
| CertFun | Free SPLK-2003 Sample Questions | Free | ↗ |
| ExamTopics | SPLK-2003 Free Practice Exam | Free | ↗ |
| CertLibrary | SPLK-2003 Practice Test & Study Materials | $30–50 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| Security Orchestration, Automation, and Response for Security Analysts | Benjamin Kovacevic | Packt Publishing | 2021 | 978-1-80324-291-0 | ↗ |
Note: No dedicated study guide exists for SPLK-2003 specifically. "The Essential Guide to SOAR" and "A Beginner's Guide to SOAR" are available from Splunk but are marketing/educational overviews rather than exam prep books. The Packt title covers SOAR concepts across multiple platforms including Splunk.
Typical job titles at Security/SOAR · Professional
SOAR Engineer · Security Operations Automation Engineer · Detection Engineering Lead (SOAR focus) · Senior SOC Engineer (Splunk SOAR specialist) · Incident Response Automation Specialist · Security Platform Engineer (SOAR track)
(Job titles drawn from current job-board postings that list Splunk SOAR or SOAR automation expertise as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $115,864 – $137,828 | Glassdoor ↗ · ZipRecruiter ↗ |
| ZAR | No region-specific data available — use general South African cybersecurity engineer salary | PayScale, CareerJunction (no SOAR-specific data as of May 2026) |
| GBP | £39,798 – £50,000 | Glassdoor UK ↗ · IT Jobs Watch ↗ |
Notes:
- SOAR roles in the US typically command $115K–$138K annually for mid-to-senior engineers.
- UK market shows SOAR engineers at £40K–£50K, comparable to general SOC engineer roles.
- South African market has limited dedicated SOAR data; align with cybersecurity platform engineer benchmarks (generally R600K–R900K ZAR for mid-level roles).
Skills validated
Cert-specific — what this exam actually tests, distinct from the shared "Common skills" above.
- Splunk SOAR server architecture and deployment models
- Playbook design patterns and visual editor proficiency
- Python custom code integration within playbooks
- REST API integration and authentication handling
- SOAR-to-Splunk ES bidirectional communication (alerts → cases → evidence)
- App development and custom action creation
- Multi-tenant configuration and role-based access control
- Case management and investigative workflows
- Common SOAR integrations (ServiceNow, Slack, PagerDuty, DNS/IP enrichment tools)
- Splunk SOAR pricing and licensing models (important for admin role)
Related certifications
- Ecosystem: Splunk Ecosystem Overview ↗
- Stacks with: Splunk Enterprise Certified Admin (SPLK-1003) ↗ — admins often hold both SOAR + Enterprise certs
- Related role: Splunk Enterprise Certified Architect (SPLK-2002) ↗ — architects design enterprise SOAR integrations
- Replaced legacy name: Splunk Phantom Certified Admin (renamed SOAR Certified Automation Developer in 2019)
- Status note: This cert is now Legacy (as of Jan 2026); Splunk is consolidating SOAR certification tracks
- Alternative SOAR certs: Splunk SOAR Certified Automation Developer (SPLK-2003 — this cert), Microsoft Sentinel SOAR pathway, Google Chronicle SOAR pathway (for cross-platform context)
Sources
- Splunk SOAR Certified Automation Developer Track ↗
- Splunk Certification Exam Study Guide ↗
- Test Blueprint: SOAR Automation Developer ↗
- Pearson VUE Splunk Certification Exams ↗
- Splunk Education Developing SOAR Playbooks ↗
- Splunk Education Advanced SOAR Implementation ↗
- Splunk SOAR OnVUE Online Testing ↗
- Glassdoor: SOAR Engineer Salary (US) ↗
- Glassdoor: SOAR Engineer Salary (UK) ↗
- ZipRecruiter: SOAR Engineer Salary (US) ↗
- IT Jobs Watch: SOC Engineer Salaries (UK) ↗
- Packt: Security Orchestration, Automation, and Response for Security Analysts ↗
Last verified: 2026-05-01 Parent ecosystem: Splunk Ecosystem Parent domain: Security/SOAR Vendor overview: Splunk Vendor Overview