Our client in Melbourne is looking for Splunk Data Administrator is responsiblethis is a Perm role.5–10 years experience with Splunk administration and data onboarding (or equivalent depth).
Robust practical knowledge of:Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issuesprops.conf / transforms.conf, sourcetypes, timestamps, line-breakingTA installation/configuration and deployment patterns across Splunk tiersExperience with complex Splunk architectures:Indexer clusters, SH/SHC, forwarder management, deployment serverHybrid patterns (on-prem + cloud), connectivity, and ingestion strategiesComfortable writing and validating SPL for data quality and CIM compliance.Cloud: AWS/Azure/GCP logging patterns (nice-to-have)Preferred / Nice-to-HaveExperience with Splunk Enterprise Security (ES) and ES add-ons / CIM compliance expectations.Knowledge of Splunk Ingest Actions / Edge Processor (or modern ingestion tools, where applicable).
Familiarity with:ITSI / Observability (bonus)Splunk Core Certified Power User / AdminAll candidates should have full working rights in Australia.Only shortlisted candidates will be contacted for this role.
#J-*****-Ljbffr
📌 Splunk Data Administrator (Melbourne)
🏢 ITbility
📍 Melbourne
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.