Our client in Melbourne is looking for Splunk Data Administrator is responsiblethis is a Perm role.
- 5–10 years experience with Splunk administration and data onboarding (or equivalent depth).
- Strong practical knowledge of:
- Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues
- props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
- TA installation/configuration and deployment patterns across Splunk tiers
- Experience with complex Splunk architectures:
- Indexer clusters, SH/SHC, forwarder management, deployment server
- Hybrid patterns (on-prem + cloud), connectivity, and ingestion strategies
- Comfortable writing and validating SPL for data quality and CIM compliance.
- Cloud:
AWS/Azure/GCP logging patterns (nice-to-have)
Preferred / Nice-to-Have
- Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM compliance expectations.
- Knowledge of Splunk Ingest Actions / Edge Processor (or contemporary ingestion tools, where applicable).
- Familiarity with:
- ITSI / Observability (bonus)
- Splunk Core Certified Power User / Admin
All candidates should have full working rights in Australia.
Only shortlisted candidates will be contacted for this role.
#J-18808-Ljbffr
📌 Splunk Data Administrator (Melbourne)
🏢 ITbility
📍 Melbourne
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.