SPLK-3002 — Splunk IT Service Intelligence Certified Admin
Splunk

Splunk IT Service Intelligence Certified Admin (SPLK-3002) Practice Questions

★★★★★★ 4.8 136 verified reviews
88 questions
2026-06-18 updated
✓ Online quiz simulator

Domain coverage

  • Introducing ITSI (5%)
  • Glass Tables (5%)
  • Managing Notable Events (10%)
  • Investigating Issues with Deep Dives (10%)
  • Installing and Configuring ITSI (10%)
  • Designing Services (5%)
  • Data Audit and Base Searches (5%)
  • Implementing Services (5%)
  • Thresholds and Time Policies (5%)
  • Entities and Modules (5%)
  • Templates and Dependencies (5%)
  • Anomaly Detection (5%)
  • Correlation & Multi-KPI Searches (5%)
  • Aggregation Policies (5%)
  • Access Control (5%)
  • Troubleshooting ITSI (10%)

Sample Questions (9 of 88 shown)

Q1 Introducing ITSI (5%)
What is the primary function of Splunk IT Service Intelligence (ITSI)?
  1. To provide real-time visibility into the health of IT and business services using machine learning
  2. To perform security event correlation
  3. To manage network configurations
  4. To replace the Splunk search head
✓ Correct Answer: A
Splunk IT Service Intelligence (ITSI) is an AIOps solution that provides real-time visibility into the health and performance of critical IT and business services. It uses machine learning for anomaly detection, predictive analytics, and service-level monitoring to help IT operations teams identify and resolve issues faster.
Q2 Introducing ITSI (5%)
What is a key benefit of using Splunk ITSI for IT operations?
  1. Reducing alert noise through service-based correlation and aggregation
  2. Replacing all existing monitoring tools
  3. Eliminating the need for Splunk administrators
  4. Automatically fixing all infrastructure issues
✓ Correct Answer: A
One of the primary benefits of ITSI is reducing alert noise by correlating and aggregating alerts into service-based notable events. ITSI groups related alerts by service, uses anomaly detection to identify true issues, and provides a single pane of glass for IT operations teams to focus on critical service health.
Q3 Introducing ITSI (5%)
Which component of the ITSI architecture provides the user interface for service health monitoring?
  1. ITSI module
  2. ITSI app on the Splunk search head
  3. ITSI indexer cluster
  4. ITSI forwarder
✓ Correct Answer: B
ITSI runs as an application on the Splunk search head. The ITSI app provides the user interface, including Glass Tables, Episode Review (notable events), deep dives, and service analyzers. It extends the Splunk platform with AIOps-specific capabilities.
Q4 Introducing ITSI (5%)
What types of users typically benefit most from Splunk ITSI?
  1. IT operations teams and service owners
  2. Only security analysts
  3. Only application developers
  4. Only network engineers
✓ Correct Answer: A
ITSI is designed primarily for IT operations (ITOps) teams and service owners who need to monitor the health and performance of IT services. It provides service-level dashboards, anomaly detection, and event correlation to help operations teams maintain service availability and performance.
Q5 Glass Tables (5%)
What is a Glass Table in Splunk ITSI?
  1. A customizable real-time visualization dashboard for displaying service health KPIs
  2. A physical glass monitor for SOC displays
  3. A type of search head hardware
  4. A configuration file for ITSI settings
✓ Correct Answer: A
A Glass Table in ITSI is a highly customizable, real-time visualization dashboard designed for displaying service health, KPIs, and key metrics. It can include tiles showing service health scores, KPI values, and other visualizations, and is commonly used for NOC (Network Operations Center) wall displays.
Q6 Glass Tables (5%)
A KPI tile on a Glass Table can be configured to drill down to which of the following?
  1. Another Glass Table
  2. A Splunk dashboard
  3. A custom deep dive
  4. Any of the above
✓ Correct Answer: D
KPI tiles on Glass Tables support drill-down actions that can navigate to multiple target types: another Glass Table (for more detailed service views), a standard Splunk dashboard (for broader analytics), or a custom deep dive (for in-depth KPI investigation). This provides flexible navigation for operators.
Q7 Glass Tables (5%)
An administrator needs to design a Glass Table for NOC display. Which types of tiles can be added?
  1. KPI tiles, service health tiles, and custom visualization tiles
  2. Only KPI tiles
  3. Only service health tiles
  4. Only text tiles
✓ Correct Answer: A
Glass Tables support multiple tile types including KPI tiles (showing specific KPI values), service health tiles (showing overall service health scores), and custom visualization tiles (based on Splunk searches or ITSI data). This flexibility allows administrators to create comprehensive NOC displays.
Q8 Glass Tables (5%)
How can a Glass Table be shared with different ITSI users?
  1. By setting appropriate permissions through the ITSI access control settings
  2. By copying the Glass Table XML to each user's system
  3. By emailing the Glass Table URL to users
  4. By exporting and importing the Glass Table
✓ Correct Answer: A
Glass Tables can be shared through ITSI's access control settings, where administrators set permissions for viewing and editing. This ensures that only users with the appropriate role (itoa_admin, itoa_team_admin, or itoa_analyst) can access specific Glass Tables based on their assigned services and teams.
Q9 Managing Notable Events (10%)
Which of the following describes a notable event group in ITSI?
  1. A notable event group logically combines individual notable events for easier management
  2. A notable event group is created in the itsi_tracked_alerts index
  3. A notable event group allows users to adjust threshold settings
  4. All of the above
✓ Correct Answer: A
A notable event group in ITSI logically combines individual notable events that are related, making them easier to manage and investigate. Groups aggregate related alerts so operators can address the root cause rather than individual symptoms. Groups are created through aggregation policies.

You've viewed 3 of 88 questions. Start the free practice exam to answer all questions with instant feedback.

Exam overview

Built for IT operations teams managing service health and observability, the Splunk IT Service Intelligence Certified Admin (SPLK-3002) certification validates your ability to install, configure, and maintain ITSI environments with KPIs, entities, Glass Tables, and notable event rules. Administered through Pearson VUE, this 60-minute exam requires a scaled passing score of 700/1000 and has no formal prerequisite certifications, though operational experience equivalent to a Splunk Cloud or Enterprise Certified Admin is strongly recommended.

Splunk suggests completing the Introduction to Splunk IT Service Intelligence and Installing and Administering ITSI courses, paired with at least 6 months of hands-on experience managing complex data modeling, service analyzer components, or specialized observability pipelines. The exam is currently designated as a legacy track — its content is stabilized and remains a valid, widely recognized credential for enterprise ITSI management.

The SPLK-3002 blueprint spans 16 domains, with the highest weights on Managing Notable Events (10%), Investigating Issues with Deep Dives (10%), Installing and Configuring ITSI (10%), and Troubleshooting ITSI (10%). Core skills include configuring multi-KPI alerting with correlation searches, designing KPI thresholds using static vs. adaptive policies that adjust to seasonal behavior cycles, creating deep dives with swim lanes for root-cause analysis, and building aggregation policies with Smart Mode grouping to reduce alert fatigue.

For candidates preparing for the SPLK-3002 exam, our practice materials cover all 16 domains in the same proportions as the real test — from ITSI fundamentals and Glass Table executive dashboard design through Notable Event management with multi-KPI alerting workflows, Deep Dive investigation with swim lane root-cause analysis, Installing and Configuring ITSI with hardware requirements and deployment topologies, Designing and Implementing Services with KPI mapping and base search optimization, Thresholds and Time Policies comparing static vs. adaptive threshold calculations, Entities and Modules with dynamic KPI entity integration, Templates and Dependencies for upstream/downstream service relationships, Anomaly Detection with ad-hoc, trending, and cohesive engine types, Correlation Searches and Multi-KPI alerting configurations, Aggregation Policies with Smart Mode grouping rules, Access Control with team-level permissions, and Troubleshooting ITSI with internal log file auditing and lagging base search diagnosis. Each online practice question includes a detailed answer explanation that walks through the ITSI-specific reasoning, while the downloadable PDF packages the same question bank for offline review during commutes or in environments without stable internet.

Start your free SPLK-3002 practice test today and master Splunk ITSI configuration, KPI thresholding, and service health monitoring.

Official Exam Domains & Weighting

To successfully pass the SPLK-3002 exam, candidates must master the following core domains:
  • Domain 1: Introducing ITSI (5%) — Identifying what ITSI does, describing business value, and navigating the core ITSI user interface.
  • Domain 2: Glass Tables (5%) — Describing, using, designing, and configuring interactive executive dashboards (Glass Tables).
  • Domain 3: Managing Notable Events (10%) — Defining key notable event terms, evaluating multi-KPI alert examples, and executing notable event workflows with custom views.
  • Domain 4: Investigating Issues with Deep Dives (10%) — Explaining deep dive concepts, utilizing default and custom deep dives, adding swim lanes, and performing root-cause troubleshooting.
  • Domain 5: Installing and Configuring ITSI (10%) — Listing hardware requirements, mapping deployment topologies, identifying app components, and configuring data inputs.
  • Domain 6: Designing Services (5%) — Planning ITSI implementation based on client prerequisites and mapping site entities.
  • Domain 7: Data Audit and Base Searches (5%) — Using data audits to map KPIs and designing optimized base searches.
  • Domain 8: Implementing Services (5%) — Translating design workflows into configured live services within the ITSI framework.
  • Domain 9: Thresholds and Time Policies (5%) — Building KPIs with static vs. adaptive thresholds and implementing time policies for flexible alarming.
  • Domain 10: Entities and Modules (5%) — Importing site entities, leveraging entities dynamically inside KPI searches, and implementing pre-built ITSI modules.
  • Domain 11: Templates and Dependencies (5%) — Managing services efficiently via service templates and establishing upstream/downstream dependencies.
  • Domain 12: Anomaly Detection (5%) — Enabling native anomaly detection engines and triaging auto-generated anomaly events.
  • Domain 13: Correlation & Multi-KPI Searches (5%) — Authoring correlation searches, declaring multi-KPI alerting configurations, and coordinating notable event storage.
  • Domain 14: Aggregation Policies (5%) — Designing notable event aggregation policies and configuring Smart Mode grouping to limit alert fatigue.
  • Domain 15: Access Control (5%) — Defining explicit team permissions and configuring service/team-level access for multi-tenant environments.
  • Domain 16: Troubleshooting ITSI (10%) — Auditing internal ITSI log files, pinpointing misconfigured KPIs, checking health indicators, and remedying lagging base searches.

What Our Customers Say 136 verified reviews

4.8 ★★★★★★ Based on 136 reviews
★★★★★
I bought the SPLK-3002 question bank a week before my exam and passed with 90%+. The questions are that good.
— Maria V.
★★★★★★
The most realistic SPLK-3002 practice test I have ever used. The question style and difficulty match the real exam perfectly.
— Brian J.
★★★★★★
Bought lifetime access for the SPLK-3002 bank and it’s been great. Still use it to brush up even after passing the cert.
— Sophie L.
★★★★★★
Detailed, organized, and accurate. Exactly what you want in SPLK-3002 prep material. The explanations deserve special mention.
— Gabriel L.
★★★★★★
Straight to the point. No filler, just good SPLK-3002 practice questions with clear explanations. Exactly what I needed.
— Paisley K.
★★★★★★
I was struggling with SPLK-3002 until I found this. The domain-based organization and instant feedback helped me identify weak areas quickly.
— David L.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

Splunk labels SPLK-3002 as legacy because the exam objectives are frozen and stable. It remains a valid, credentialed path widely recognized for managing enterprise ITSI infrastructure, but the test pool is not constantly modified for micro-version software upgrades.

The most difficult combination involves Troubleshooting ITSI (10%) paired with Thresholds and Time Policies (5%). You must thoroughly understand how lagging base searches impact KPI calculations and how adaptive thresholds adjust to seasonal behavior cycles without generating false alarms. Our practice materials include these troubleshooting scenarios.

A mandatory 7-day cooldown before retaking, with the full $130 fee required each attempt.

Three years from the date your passing grade is logged by Pearson VUE.

Our mock exam covers all 16 domains with the same weight distribution as the real test — from ITSI fundamentals and Glass Table configuration through multi-KPI notable event workflows, deep dive creation with swim lane analysis, KPI threshold design comparing static and adaptive policies, anomaly detection with ad-hoc/trending/cohesive engine types, correlation search and multi-KPI alerting, aggregation policies with Smart Mode grouping, and troubleshooting lagging base searches. Each question includes detailed ITSI reasoning.

Yes. The downloadable PDF contains the same question bank as the online version, including answer explanations covering Glass Table interactive dashboard design, KPI adaptive threshold calculation mechanics, deep dive swim lane root-cause analysis, anomaly detection engine types, service template dependency mapping, aggregation policy Smart Mode rules, and ITSI internal log troubleshooting. It is designed for offline study.

Candidates report Troubleshooting ITSI (10%) — especially lagging base search diagnosis — and Thresholds and Time Policies (5%) with adaptive threshold seasonality as the most demanding. Correlation & Multi-KPI Searches (5%) also requires careful attention to notable event storage and alerting logic. Our practice questions include focused drills on these areas.