Perform a search on the site.

Your currency

Splunk® Enterprise Admin: managing and securing data infrastructure

Your Splunk platform must remain usable as volumes and requirements evolve. Connect configuration, architecture and operational monitoring to inform your decisions. Strengthen your ability to organise a data infrastructure aligned with expected services.

Duration
5 days 35 hours
Code
ASR007FR Code
Certification
Splunk® Enterprise Certified Admin Certification
Splunk® Enterprise Certified Admin

Accredited training for the Splunk® Enterprise Certified Admin certification.

Presentation


In data-driven organisations, maintaining a healthy, high-performing analytics platform is a major operational priority. Daily management of Splunk Enterprise environment components requires specialist skills, from licence administration to search head configuration. This intermediate-level course is specifically designed to validate administrators' technical ability to take responsibility for overall infrastructure health.

This intensive 5-day programme provides comprehensive immersion in the data lifecycle, from ingestion through forwarders to optimised storage in indexers. You will explore advanced parsing techniques, data normalisation through the CIM model and multi-tier retention strategies. Critical security issues, including data encryption and integration with external directory services, are also covered.

By the end of the course, your new expertise will enable you to ensure a stable, secure Splunk environment while resolving performance bottlenecks. You will also be ready to take the exam for the Splunk Enterprise Certified Admin credential. This professional certification demonstrates your ability to administer enterprise-wide data pipelines effectively.

Objectives

By the end of this Enterprise Admin course, you will be able to:

  • manage key Splunk Enterprise components daily, including licences, indexers and search heads;
  • configure data input and ingestion through methods such as APIs, Syslog and forwarders;
  • master data parsing and normalisation through advanced configuration files and the CIM model;
  • administer indexing strategies and storage lifecycles (buckets);
  • secure the environment through role management, encryption and LDAP/SAML integration;
  • optimise performance and monitor system health through the monitoring console;
  • maintain, back up and troubleshoot Splunk components;
  • prepare for and pass the Splunk Certified Enterprise Admin certification exam.
Last update: 24/09/2026

Splunk is a registered trademark of Cisco Systems, Inc. or its affiliates in the United States and other countries. 
Mention for educational purposes does not constitute an endorsement or partnership.