Splunk Data Administrator Melbourne

Splunk Data Administrator Melbourne

01 Aug
|
ITbility
|
Melbourne

01 Aug

ITbility

Melbourne

Our client in Melbourne is looking for Splunk Data Administrator is responsiblethis is a Perm role.
5–10 years experience with Splunk administration and data onboarding (or equivalent depth).
Robust practical knowledge of:
Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues
props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
TA installation/configuration and deployment patterns across Splunk tiers
Experience with complex Splunk architectures:
Indexer clusters, SH/SHC, forwarder management, deployment server
Hybrid patterns (on-prem + cloud), connectivity, and ingestion strategies
Comfortable writing and validating SPL for data quality and CIM compliance.
Cloud:



AWS/Azure/GCP logging patterns (nice-to-have)

Preferred / Nice-to-Have
Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM compliance expectations.
Knowledge of Splunk Ingest Actions / Edge Processor (or up-to-date ingestion tools, where applicable).
Familiarity with:
ITSI / Observability (bonus)
Splunk Core Certified Power User / Admin

All candidates should have full working rights in Australia.

Only shortlisted candidates will be contacted for this role.
J-18808-Ljbffr

📌 Splunk Data Administrator Melbourne
🏢 ITbility
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator melbourne / melbourne

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator melbourne / melbourne