Splunk SOAR Certified Automation Developer

Splunk · SPLK-2003 · Professional

Splunk · Splunk Ecosystem

Splunk SOAR Certified Automation Developer

SPLK-2003legacyProfessional
Official Splunk source · splunk.com

SPLK-2003 · ● Legacy · Professional · Splunk (Cisco)

Legacy status: This certification was reclassified as Legacy by Splunk as of January 1, 2026. Exam content will no longer be actively maintained or updated to reflect product changes or releases. However, the certification remains valid and relevant for professionals working with existing SOAR deployments.


Exam facts

FieldValue
CostUSD $125 (standard); $25 at Splunk .conf events
Duration90 minutes
Questions60 (multiple-choice + multiple-response)
Passing~70% (Splunk does not publish exact threshold)
FormatMultiple choice / Multiple response
DeliveryPearson VUE (proctored center or OnVUE online)
LanguagesEnglish
Valid3 years from exam pass date
RenewalPass higher-level cert or retake exam
PrerequisitesNone (hands-on SOAR experience recommended)
Released2019 (as Phantom Admin); rebranded to SOAR Certified Automation Developer
RetiringNo announced retirement date (legacy status means no new releases)

Vendor source — Splunk SOAR Certified Automation Developer ↗

Official exam guide — Splunk Certification Exam Study Guide ↗

Exam blueprint — Test Blueprint: SOAR Automation Developer ↗

Pearson VUE registration — Splunk Exams ↗


About

The Splunk SOAR Certified Automation Developer (formerly Splunk Phantom Certified Admin) demonstrates the ability to install, configure, and operate Splunk SOAR servers, integrate them with Splunk Enterprise and Enterprise Security, and design, create, test, and debug security automation playbooks. This professional-level cert targets SOC engineers, security operations specialists, and incident response practitioners responsible for orchestrating multi-tool security workflows. Released in 2019 as part of Splunk's acquisition of Phantom (a leading open SOAR platform), it reclassified to Legacy status in January 2026 as Splunk consolidates SOAR certification offerings.


Domain context — Security/SOAR

Security Orchestration, Automation, and Response (SOAR) is a specialized cybersecurity domain focused on automating repetitive incident response tasks, orchestrating third-party tool integrations, and reducing alert fatigue in Security Operations Centers (SOCs). SOAR platforms like Splunk SOAR connect 300+ security and IT tools, enabling analysts to respond to threats in minutes rather than hours.

Read full deep dive — Splunk Ecosystem →


Topics covered

The exam blueprint reflects the full lifecycle of SOAR administration and playbook development:

  • Deployment, Installation, and Initial Configuration (5%) — Server setup, prerequisites, configuration
  • User Management and Multi-tenancy (5%) — Role-based access control, tenant isolation
  • Apps, Assets, and Playbooks (5%) — Integrated apps, asset management, playbook library
  • Analyst Queue (5%) — Managing incident triage and work assignment
  • The Investigation Page (10%) — Evidence collection, timeline, forensic workflows
  • Case Management and Workbooks (5%) — Case lifecycle, workbook templates
  • Customizations (5%) — Custom apps, fields, automation extensions
  • System Maintenance (5%) — Backups, updates, monitoring, health checks
  • Introduction to Playbooks (5%) — Playbook concepts and design patterns
  • Visual Playbook Editor (5%) — Drag-and-drop workflow design, palette tools
  • Logic, Filters, and User Interaction (5%) — Conditional branching, prompt actions, approval workflows
  • Formatted Output and Data Access (5%) — Result formatting, artifacts, data output
  • Modular Playbook Development (5%) — Reusable components, sub-playbooks, templates
  • Custom Lists and Data Routing (5%) — Custom data models, routing logic
  • Configuring External Splunk Search (5%) — Splunk query integration, scheduled searches
  • Integrating SOAR into Splunk (10%) — Alert-to-case workflows, ES integration
  • Custom Coding (5%) — Python custom code blocks, libraries
  • Using REST (5%) — REST API calls, authentication, response parsing

Source: Official exam blueprint ↗


Common skills at Security/SOAR · Professional

Shared competencies for the Security/SOAR domain at Professional level — not specific to this cert.

  • Playbook architecture design — orchestrating multi-step incident response workflows across security tools
  • API integration patterns — REST/webhook connectors to SIEM, threat intelligence, ticketing, and communication platforms
  • Conditional logic and automation — if-then rules, parallel execution, loop constructs, error handling
  • Python scripting for security — custom code within playbooks to enrich data, parse logs, and handle edge cases
  • Case management and triage — intake, assignment, escalation, and closure workflows
  • Third-party tool integration — connecting security stacks (Splunk ES, ServiceNow, Slack, PagerDuty, threat feeds, etc.)
  • Alert fatigue reduction — tuning detection logic, implementing smart filtering, and playbook-driven deduplication

Recommended courses at Security/SOAR · Professional

ProviderTitleCostURL
Splunk Education (Official)Introduction to Splunk SOAR (eLearning)Free
Splunk Education (Official)Developing SOAR Playbooks~$600–800
Splunk Education (Official)Advanced SOAR Implementation~$1000–1200
UdemySplunk SOAR Certified Dev SPLK-2003: Practice Tests 2026$15–50
UdemySplunk SOAR Certified Automation Developer Practice Tests$15–50

Practice exams

ProviderTitleCostURL
Splunk (Official)Sample questions in Certification Study GuideFree
CertFunFree SPLK-2003 Sample QuestionsFree
ExamTopicsSPLK-2003 Free Practice ExamFree
CertLibrarySPLK-2003 Practice Test & Study Materials$30–50

Books

TitleAuthorPublisherYearISBNURL
Security Orchestration, Automation, and Response for Security AnalystsBenjamin KovacevicPackt Publishing2021978-1-80324-291-0

Note: No dedicated study guide exists for SPLK-2003 specifically. "The Essential Guide to SOAR" and "A Beginner's Guide to SOAR" are available from Splunk but are marketing/educational overviews rather than exam prep books. The Packt title covers SOAR concepts across multiple platforms including Splunk.


Typical job titles at Security/SOAR · Professional

SOAR Engineer · Security Operations Automation Engineer · Detection Engineering Lead (SOAR focus) · Senior SOC Engineer (Splunk SOAR specialist) · Incident Response Automation Specialist · Security Platform Engineer (SOAR track)

(Job titles drawn from current job-board postings that list Splunk SOAR or SOAR automation expertise as required or preferred.)


Salary

RegionRangeSource
USD$115,864 – $137,828Glassdoor ↗ · ZipRecruiter ↗
ZARNo region-specific data available — use general South African cybersecurity engineer salaryPayScale, CareerJunction (no SOAR-specific data as of May 2026)
GBP£39,798 – £50,000Glassdoor UK ↗ · IT Jobs Watch ↗

Notes:

  • SOAR roles in the US typically command $115K–$138K annually for mid-to-senior engineers.
  • UK market shows SOAR engineers at £40K–£50K, comparable to general SOC engineer roles.
  • South African market has limited dedicated SOAR data; align with cybersecurity platform engineer benchmarks (generally R600K–R900K ZAR for mid-level roles).

Skills validated

Cert-specific — what this exam actually tests, distinct from the shared "Common skills" above.

  • Splunk SOAR server architecture and deployment models
  • Playbook design patterns and visual editor proficiency
  • Python custom code integration within playbooks
  • REST API integration and authentication handling
  • SOAR-to-Splunk ES bidirectional communication (alerts → cases → evidence)
  • App development and custom action creation
  • Multi-tenant configuration and role-based access control
  • Case management and investigative workflows
  • Common SOAR integrations (ServiceNow, Slack, PagerDuty, DNS/IP enrichment tools)
  • Splunk SOAR pricing and licensing models (important for admin role)

Related certifications

  • Ecosystem: Splunk Ecosystem Overview ↗
  • Stacks with: Splunk Enterprise Certified Admin (SPLK-1003) ↗ — admins often hold both SOAR + Enterprise certs
  • Related role: Splunk Enterprise Certified Architect (SPLK-2002) ↗ — architects design enterprise SOAR integrations
  • Replaced legacy name: Splunk Phantom Certified Admin (renamed SOAR Certified Automation Developer in 2019)
  • Status note: This cert is now Legacy (as of Jan 2026); Splunk is consolidating SOAR certification tracks
  • Alternative SOAR certs: Splunk SOAR Certified Automation Developer (SPLK-2003 — this cert), Microsoft Sentinel SOAR pathway, Google Chronicle SOAR pathway (for cross-platform context)

Sources


Last verified: 2026-05-01 Parent ecosystem: Splunk Ecosystem Parent domain: Security/SOAR Vendor overview: Splunk Vendor Overview


Rate this cert
Was this helpful?
Comments ()
0/2000