31 Jul
|
ITbility
|
Melbourne
31 Jul
ITbility
Melbourne
Our client in
Melbourne
is looking for
Splunk Data Administrator
is responsiblethis is a
Perm
role.
5–10 years experience with Splunk administration and data onboarding (or equivalent depth).
Solid practical knowledge of:
Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues
props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
TA installation/configuration and deployment patterns across Splunk tiers
Experience with complex Splunk architectures:
Indexer clusters, SH/SHC, forwarder management, deployment server
Hybrid patterns (on-prem + cloud), connectivity, and ingestion strategies
Comfortable writing and validating SPL for data quality and CIM compliance.
Cloud:
AWS/Azure/GCP logging patterns (nice-to-have)
Preferred / Nice-to-Have
Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM compliance expectations.
Knowledge of Splunk Ingest Actions / Edge Processor (or contemporary ingestion tools, where applicable).
Familiarity with:
ITSI / Observability (bonus)
Splunk Core Certified Power User / Admin
All candidates should have full working rights in Australia.
Only shortlisted candidates will be contacted for this role.
J-*-Ljbffr
📌 Splunk Data Administrator Melbourne
🏢 ITbility
📍 Melbourne