I
- Experience
- 5–10 yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 گھنٹے قبل
- Work mode
- In office
- Eligibility
- Applicants must have full working rights in Australia.
- Resume
- Required to apply
Where you'll work
Job description
About the Role
Our Melbourne-based client is seeking a skilled Splunk Data Administrator for a permanent position. This role demands extensive experience in Splunk administration, focusing on data onboarding and management across complex environments.
Key Responsibilities
- Manage and administer Splunk platforms with 5 to 10 years of practical experience.
- Apply knowledge in CIM normalization, event tagging, event types, and data model alignment.
- Perform field extraction using regex and JSON/KV techniques, troubleshoot parsing and indexing issues.
- Handle configuration of props.conf and transforms.conf, define sourcetypes, timestamps, and line-breaking patterns.
- Install and configure Technology Add-ons (TAs) and manage deployment configurations across various Splunk tiers.
- Oversee complex Splunk architectures including indexer clusters, search heads and clusters, forwarder management, and deployment servers.
- Implement hybrid ingestion strategies combining on-premises and cloud setups, ensuring reliable connectivity and data ingestion.
- Create and validate SPL queries to ensure data quality and compliance with CIM standards.
- Utilize deep log source expertise across multiple domains: security (EDR, firewalls, proxies, IAM/authentication, VPN, email security), infrastructure (Windows, Linux, networking, virtualization), and cloud platforms (AWS, Azure, GCP).
Preferred Skills and Certifications
- Experience with Splunk Enterprise Security (ES), including add-ons and CIM compliance.
- Familiarity with modern ingestion tools such as Splunk Ingest Actions and Edge Processor.
- Knowledge of HEC, API ingestion methods, message queues.
- Additional advantage: ITSI and Observability tools experience.
- Certifications like Splunk Core Certified Power User/Admin, Splunk Enterprise Certified Admin, and Splunk ES Admin preferred.
Additional Information
Candidates must have full working rights in Australia. Only shortlisted applicants will be contacted for further consideration.
Application Process
Qualified candidates are encouraged to submit their resumes promptly for immediate review.
Skills
Splunk Enterprise Security
Splunk Administration
Data onboarding
Regular expressions
SPL (Search Processing Language)
CIM normalization
props.conf and transforms.conf configuration
Indexer cluster management
Forwarder and deployment server management
Log source analysis (security, infrastructure, cloud)
API and HEC ingestion