Splunk Data Administrator (Melbourne)

Splunk Data Administrator (Melbourne)

24 Sep
|
Xpt Software Australia
|
Melbourne

24 Sep

Xpt Software Australia

Melbourne

XPT Software Australia Pty Ltd | Contract

Splunk Data Administrator

Melbourne, Australia | Posted on 09/23/2026

- XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company

- XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.

- We have 120+technocrats in Australia working at our clientlocations.

- XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.

- We have served100+ clients globally, fulfilling their onsite-offshoreneeds.

Job Description

RoleSummary

We areseeking a mid to senior Splunk Data Administrator to own and continuouslyimprove Splunk data onboarding, normalization, and quality across a complexhybrid Splunk setting (on‑prem and cloud).

The idealcandidate is hands-on with CIM alignment, data source onboarding, fieldextractions (regex/props/transforms/ingest actions), TA deployment, andend-to-end operational management of Splunk data pipelines.

You willact as the key point of contact for ensuring log sources are onboardedcorrectly, parsed and normalized consistently, and made usable for security/IToperations, dashboards, correlation searches, and reporting.

Key Responsibilities

DataOnboarding & Lifecycle Management

- Leadonboarding of new log sources end-to-end: requirements gathering, sourcevalidation, parsing strategy, TA selection/deployment, CIM alignment, testing,and release.
- Partnerwith Security/IT teams to translate use-cases into data requirements, ensuringsources deliver the right fidelity, timeliness, and coverage.
- Manageonboarding at scale using best practices for source types, metadata strategy,index & sourcetype governance, and naming conventions.




- Defineand enforce data quality standards (field completeness, timestamps, eventconsistency, parsing accuracy, duplication control).
- Normalizedata to Splunk Common Information Model (CIM) with strong understanding of datamodels (e.g., Authentication, Network Traffic, Endpoint, Change, etc.).
- Ensurefields are aligned to CIM requirements to support Splunk Enterprise Security(ES) and other CIM-based content.
- Validatenormalization using SPL and develop reusable onboarding checklists.
- Designand implement robust field extractions using:
- regex andstructured parsing (KV_MODE, JSON, XML)
- ingest-time vs search-time extraction strategy
- sourcetype / timestamp / line breaking configuration

- Implementenrichment and routing using event breaking, host/source normalization,lookups, and tagging.
- Install,configure, and maintain Splunk Add-ons (TAs) and apps across:

- Indexers/ Search Heads / SHC
- Deployment Server / Cluster Manager (where applicable)

- Maintainversion compatibility and upgrade strategies for:

- SplunkEnterprise / Splunk Cloud
- Add-ons,apps, and content packs

- Packageand deploy TAs using deployment pipelines and change management controls.
- Ensurefields are aligned to CIM requirements

HybridSplunk Architecture Operations

- Operateand support Splunk in complex environments:
- On-premIndexer Cluster, Search Head Cluster, Forwarder tiers
- SplunkCloud integrations where applicable (e.g., Heavy Forwarder, VPN,



PrivateLink,data forwarding patterns)

- Configureand troubleshoot data ingestion pipelines:

- Syslog(UDP/TCP), API-based collection, HEC, file monitors, Windows Event Logs, cloudsources

- Ensureperformance and reliability across the pipeline, including indexing throughput,parsing overhead, and search impact.

Monitoring,Troubleshooting & Governance

- Monitoringestion health and pipeline performance:
- Maintaingovernance for indexes, sourcetypes, retention, RBAC and data access boundaries(as required).
- Contribute to operational runbooks, SOPs, and documentation; drive continuousimprovement in onboarding and normalization standards.

RequiredSkills & Experience (Mid–Senior)

- 5–10years experience with Splunk administration and data onboarding (or equivalentdepth).
- Strongpractical knowledge of:
- Fieldextraction (regex, JSON/KV extraction), and troubleshooting parsing issues
- props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
- TAinstallation/configuration and deployment patterns across Splunk tiers

- Experience with complex Splunk architectures:

- Indexerclusters, SH/SHC, forwarder management, deployment server
- Hybridpatterns (on-prem + cloud), connectivity, and ingestion strategies

- Comfortable writing and validating SPL for data quality and CIM compliance.
- Cloud:AWS/Azure/GCP logging patterns (nice-to-have)

Preferred /Nice-to-Have

- Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM complianceexpectations.
- Knowledgeof Splunk Ingest Actions / Edge Processor (or modern ingestion tools, whereapplicable).
- Familiaritywith:
- ITSI /Observability (bonus)
- SplunkCore Certified Power User / Admin

#J-18808-Ljbffr

📌 Splunk Data Administrator (Melbourne)
🏢 Xpt Software Australia
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator (melbourne) / melbourne

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator (melbourne) / melbourne