1.1 Elastic Certified SIEM Analyst Exam Facts, Objectives & Study Plan

Key Takeaways

  • The Elastic Certified SIEM Analyst exam is a timed cognitive exam (multiple choice, select all that apply, fill in the blanks, true/false) based on Elastic Stack 8.15.

  • Elastic lists the exam at $400 USD per attempt with a 2-hour duration, and each purchased attempt must be used within one year.

  • Elastic does not publish the number of questions, the passing score or the domain weights for the SIEM Analyst exam.

  • After a failed attempt you must wait 14 days and buy a new full-price attempt; results typically arrive within 7–10 business days.

  • The credential is valid for 2 years from the exam date and is renewed by passing an Elastic certification exam before it expires.

Last updated: September 2026

Quick Answer: The Elastic Certified SIEM Analyst exam is a timed, cognitive (knowledge-based) exam about the Elastic Security solution, based on Elastic Stack 8.15. It costs $400 USD per attempt, is taken online with remote proctoring, and Elastic's exam page lists a 2-hour duration. The credential is valid for 2 years. Elastic does not publish the number of questions, the passing score or domain weights.

Before studying any feature, know exactly what Elastic measures and how the exam runs. Every fact below comes from Elastic's exam page and Certification FAQ (checked September 2026). Recheck them before you buy an attempt, because Elastic can change prices and policies.

What Kind of Exam Is It?

Elastic runs two styles of certification exam. The Elastic Certified Engineer, Observability Engineer and Analyst exams are performance-based: you complete live tasks on a cluster while a proctor watches. The SIEM Analyst exam is different. It is a timed cognitive-based exam in which you answer:

  • Multiple choice questions
  • Select all that apply questions
  • Fill in the blanks questions
  • True or false questions

All of them center on the Elastic Security solution. You will not build a detection rule on a live cluster during the exam. You will be asked which feature, setting, query or workflow achieves a result, and why. That is why this guide stresses exact feature names, defaults, limits and the differences between similar tools.

Exam Facts at a Glance

DetailWhat Elastic Publishes
Exam typeTimed cognitive exam: multiple choice, select all that apply, fill in the blanks, true/false
Elastic Stack version8.15 (Certification FAQ)
Duration2 hours (listed on the exam page)
Fee$400 USD per attempt; Elastic currently offers no exam discounts; purchases are non-refundable
Attempt validityUse the attempt within one year of purchase (attempts bought through a training subscription expire with the subscription)
PrerequisitesNone; Elastic strongly encourages the Elastic Security for SIEM course
DeliveryOnline at any time, remotely proctored with the Honorlock browser extension; scheduled through Trueability
ComputerWindows or macOS (Linux is not supported), webcam, microphone, speakers, stable broadband; a 13-inch screen minimum, with a larger screen recommended
IdentificationValid, non-expired government-issued photo ID matching your enrollment details
BreakOne break of up to 10 minutes; it counts toward exam time, and phones are not allowed
DocumentationElastic documentation is available inside the exam environment's browser; all other websites are prohibited
ResultsTypically within 7–10 business days
RetakesWait 14 days, then buy a new attempt; reattempts are not discounted
CredentialDigital badge issued through Accredible, valid 2 years from the exam date
Not publishedNumber of questions, passing score, domain weights

Scheduling Rules That Can Cost You an Attempt

  • You can reschedule up to 24 hours before your self-scheduled time.
  • You must start within 30 minutes of your scheduled time. Otherwise you are marked a no-show and forfeit the attempt.
  • If ID verification fails, contact the proctor through Honorlock chat rather than leaving the exam. No refunds or reschedules are given for an invalid or missing ID.
  • A US keyboard (or the on-screen keyboard) is recommended for special characters such as { }. DeepL translation is available inside the exam environment, and extra time for translation can be requested from certification@elastic.co 3–5 business days in advance.

Keeping the Credential

The certification is valid for 2 years from the exam date. To renew, pass an Elastic certification exam before it expires, which extends an active certification by two years. Extensions are not available for expired certifications.

The Official Exam Objectives

Elastic states that candidates should be able to complete all of the following objectives with only the assistance of the Elastic documentation. The table maps each objective to this guide.

Objective GroupElastic's Exam ObjectivesWhere This Guide Teaches It
Stack ArchitectureDescribe basic Stack Architecture; demonstrate use of Fleet and Elastic AgentsChapter 2; Fleet and Elastic Agent in 3.3
Elastic Common Schema (ECS)Examine the application and guidelines of ECSChapter 3
DiscoverCustomize the Discover interface to search for dataChapter 4
VisualizationsCreate aggregation-based visualizations for security use cases; construct Lens visualizations for security use casesChapters 5 and 6
DashboardsConstruct dashboards for security use cases; demonstrate the use of dashboardsChapter 7
Security ApplicationRecognize the capabilities of the Security App; use Explore within the Security App; monitor security-related events with dashboards in the Security AppChapter 8
Describe how the Detection Engine searches activity and generates alertsChapters 9 and 10
Analyze alerts that are generated from detection rules; correlate relevant data using TimelineChapter 11
Track security issues using Cases; describe how AI is used in the Security AppChapter 12

Two chapters give supporting context. Chapter 13 covers spaces, privileges and Elastic Defend administration, and Chapter 14 follows the threat-hunting capstone that ends Elastic's training course.

Recommended Preparation

Elastic's exam page recommends the Elastic Security for SIEM course, a 24-hour course whose lessons follow the objectives above: Stack overview, ECS, Discover, Visualizations, Dashboards, Security App, and a Hunt capstone. The virtual instructor-led version is listed at $2,700 USD. Elastic also offers an Elastic Security for SIEM Self-Paced Learning Plan. Elastic Training Subscription holders get one exam and one practice exam per solution during the subscription term.

The course assumes a basic understanding of:

  • Networking: TCP/IP, common ports and protocols, routers, switches and firewalls
  • Network monitoring tools: IDS (Suricata), Zeek and packet capture
  • Operating systems: Windows and Linux, file systems and permissions, command-line navigation
  • Attack methodology: reconnaissance, command and control (C2) and data exfiltration

A Practical Study Plan

WeekFocusGuide Chapters
1Stack components, Fleet and Elastic Agent, ECS fields and categorization2–3
2Discover, KQL and Lucene, ES|QL basics4
3Aggregation-based visualizations, Lens and dashboards5–7
4Security app tour, Explore pages, Security dashboards, detection engine8–9
5Rule types, exceptions, suppression, alert triage and Timeline10–11
6Cases, connectors, AI Assistant, privileges, capstone review and practice questions12–14

Exam-Day Strategy

  1. Read for the version. The exam targets 8.15, and several features changed later. For example, in 8.15 Attack Discovery is a technical preview and prebuilt rules can't be edited beyond actions and exceptions.
  2. Watch for "select all that apply." Evaluate every option on its own merits rather than stopping at the first correct one.
  3. Separate look-alike features. Common traps include exceptions vs. alert suppression, trusted applications vs. event filters, KQL vs. EQL vs. ES|QL syntax, and Cases vs. Timeline.
  4. Use the documentation deliberately. Know where the Elastic Security docs cover rules, alerts and Timeline, so a lookup takes seconds rather than minutes.
  5. Budget your time. With 2 hours and an unpublished question count, move on from hard items and come back.
Test Your Knowledge

Which Elastic Stack version does Elastic's Certification FAQ list for the Elastic Certified SIEM Analyst exam?

A

8.8

B

8.15

C

9.3

D

7.17

Test Your Knowledge

A candidate fails the Elastic Certified SIEM Analyst exam. According to Elastic's Certification FAQ, what must the candidate do before trying again?

A

Retake it immediately at a 50% discount within the same week

B

Wait 14 days and purchase a new exam attempt at the regular price

C

Wait 90 days and complete the Elastic Security for SIEM course first

D

Request a free retake from certification@elastic.co within 24 hours

Test Your Knowledge
Multi-Select

Which of the following details does Elastic NOT publish for the Elastic Certified SIEM Analyst exam? (Select all that apply.)

Select all that apply

The number of questions

The passing score

The price per attempt

The question formats used

Test Your Knowledge

During the remotely proctored exam, a candidate takes the permitted break. Which statement matches Elastic's rules?

A

The break can last up to 30 minutes and pauses the exam clock

B

The break can last up to 10 minutes, counts toward exam time, and phone use is not permitted

C

Breaks are not allowed on cognitive exams

D

The break is unlimited as long as the webcam stays on

Sections you finish are checked off in the contents.