SPLK-3002 · ITSI Certified Admin

SPLK-3002 Study Guide & Practice Exam

Master IT Service Intelligence — services, KPIs, Glass Tables, and anomaly detection.

Start Free Course📝 Practice Exam (77+ questions)
🏰
9
Floors
📖
27
Lessons
📝
77+
Practice Qs
🎉
FREE
Price

About the SPLK-3002 Certification

The SPLK-3002 validates your ability to configure and manage Splunk IT Service Intelligence (ITSI). It covers the full ITSI stack: services, KPIs, entities, Glass Tables, aggregation policies, anomaly detection, and operational troubleshooting.

📋 Exam Details

question Count60 questions
duration60 minutes
passing Score70%
formatMultiple choice
cost$130 USD
prerequisitesSPLK-1003 Enterprise Certified Admin
🎓 View Official Exam Page on Splunk.com →

📚 What's on the SPLK-3002 Exam

1. Services & KPIs

Creating services, defining KPIs, base searches, threshold configuration, and health scoring.

2. Entities & Discovery

Entity rules, bulk import, entity discovery searches, and entity-to-service linking.

3. Glass Tables

Building NOC-style dashboards, real-time KPI visualization, and widget configuration.

4. Aggregation & Events

Aggregation policies, Notable Events, event grouping, and alert suppression.

5. Anomaly Detection

Machine learning-based anomaly detection, training periods, and adaptive thresholds.

🎯 Sample SPLK-3002 Practice Questions

Preview 1 questions from our 77+ question bank:

Q1. Where does ITSI store its configuration data?
A.conf files
BThe KV Store✓ Correct
CIndex metadata
DLookup tables
Explanation: ITSI stores services, KPIs, entities, and thresholds in the KV Store, not traditional .conf files.
Take the Full Practice Exam →

💡 Study Tips for SPLK-3002

  1. Understand that ITSI configuration lives in the KV Store — this affects backup, restore, and SHC operations.
  2. Practice building a service with KPIs and entity rules from scratch.

🏰 Course Curriculum

Our ITSI Certified Admin course covers all exam topics across 9 dungeon floors:

🏗️
Floor 1: ITSI Foundations
Installation & Core Concepts · 3 lessons
Beginner
📊
Floor 2: Services & KPIs
Designing & Implementing Service Monitoring · 3 lessons
Intermediate
🖥️
Floor 3: Entities & Modules
Managing Infrastructure Objects · 3 lessons
Intermediate
🔮
Floor 4: Glass Tables & Deep Dives
Operational Dashboards & Root Cause Analysis · 3 lessons
Advanced
🔗
Floor 5: Aggregation & Correlation
Reducing Noise & Correlating Events · 3 lessons
Advanced
🔍
Floor 6: Anomaly Detection & Ops
ML, Security & Troubleshooting · 3 lessons
Advanced
⚙️
Floor 7: SHC & Operations
Clusters, Backup & Migration · 3 lessons
Advanced
🧠
Floor 8: Event Analytics & Prediction
Correlation, Episodes & MLTK · 3 lessons
Advanced
🤖
Floor 9: Automation & Integration
REST API, ES Integration & Lifecycle · 3 lessons
Advanced

❓ Frequently Asked Questions

Do I need ITSI experience for this exam?

Yes, hands-on ITSI experience is strongly recommended. The exam tests practical configuration and troubleshooting skills.

📗 Other Study Guides

SPLK-1001
Splunk Core Certified User
Everything you need to pass the Splunk Core Certified User exam — 100% free.
SPLK-1002
Splunk Core Certified Power User
Master advanced SPL and pass the Splunk Core Certified Power User exam.
SPLK-1004
Splunk Core Certified Advanced Power User
Conquer the most advanced core Splunk certification with expert-level SPL mastery.