I

Splunk Data Administrator

ITbility

Melbourne, Victoria, Australia · Full Time

Be the first to apply

Experience
5–10 yrs
Salary
Openings
1
Posted
12 ore fa
Work mode
In office
Eligibility
Applicants must have full working rights in Australia.
Resume
Required to apply

Where you'll work

Job description

About the Role

Our Melbourne-based client is seeking a skilled Splunk Data Administrator for a permanent position. This role demands extensive experience in Splunk administration, focusing on data onboarding and management across complex environments.

Key Responsibilities

  • Manage and administer Splunk platforms with 5 to 10 years of practical experience.
  • Apply knowledge in CIM normalization, event tagging, event types, and data model alignment.
  • Perform field extraction using regex and JSON/KV techniques, troubleshoot parsing and indexing issues.
  • Handle configuration of props.conf and transforms.conf, define sourcetypes, timestamps, and line-breaking patterns.
  • Install and configure Technology Add-ons (TAs) and manage deployment configurations across various Splunk tiers.
  • Oversee complex Splunk architectures including indexer clusters, search heads and clusters, forwarder management, and deployment servers.
  • Implement hybrid ingestion strategies combining on-premises and cloud setups, ensuring reliable connectivity and data ingestion.
  • Create and validate SPL queries to ensure data quality and compliance with CIM standards.
  • Utilize deep log source expertise across multiple domains: security (EDR, firewalls, proxies, IAM/authentication, VPN, email security), infrastructure (Windows, Linux, networking, virtualization), and cloud platforms (AWS, Azure, GCP).

Preferred Skills and Certifications

  • Experience with Splunk Enterprise Security (ES), including add-ons and CIM compliance.
  • Familiarity with modern ingestion tools such as Splunk Ingest Actions and Edge Processor.
  • Knowledge of HEC, API ingestion methods, message queues.
  • Additional advantage: ITSI and Observability tools experience.
  • Certifications like Splunk Core Certified Power User/Admin, Splunk Enterprise Certified Admin, and Splunk ES Admin preferred.

Additional Information

Candidates must have full working rights in Australia. Only shortlisted applicants will be contacted for further consideration.

Application Process

Qualified candidates are encouraged to submit their resumes promptly for immediate review.

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help