Splunk Data Administrator (Melbourne)

Splunk Data Administrator (Melbourne)

31 Jul
|
ITbility
|
Melbourne

31 Jul

ITbility

Melbourne

Our client in Melbourne is looking for Splunk Data Administrator is responsiblethis is a Perm role.

- 5–10 years experience with Splunk administration and data onboarding (or equivalent depth).
- Solid practical knowledge of:
- Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues
- props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
- TA installation/configuration and deployment patterns across Splunk tiers

- Experience with complex Splunk architectures:

- Indexer clusters, SH/SHC, forwarder management, deployment server
- Hybrid patterns (on-prem + cloud), connectivity, and ingestion strategies

- Comfortable writing and validating SPL for data quality and CIM compliance.
- Cloud: AWS/Azure/GCP logging patterns (nice-to-have)

Preferred / Nice-to-Have

- Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM compliance expectations.
- Knowledge of Splunk Ingest Actions / Edge Processor (or modern ingestion tools, where applicable).
- Familiarity with:
- ITSI / Observability (bonus)
- Splunk Core Certified Power User / Admin

All candidates should have full working rights in Australia.

Only shortlisted candidates will be contacted for this role.

#J-18808-Ljbffr

📌 Splunk Data Administrator (Melbourne)
🏢 ITbility
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator (melbourne) / melbourne

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator (melbourne) / melbourne