n
- 5–10 years experience with Splunk administration and data onboarding (or equivalent depth).
n
- Robust practical knowledge of:n n
- Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues
n
- props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
n
- TA installation/configuration and deployment patterns across Splunk tiers
n
n
- Experience with complex Splunk architectures:n
n
- Indexer clusters, SH/SHC, forwarder management, deployment server
n
- Hybrid patterns (on-prem + cloud), connectivity, and ingestion strategies
n
n
- Comfortable writing and validating SPL for data quality and CIM compliance.n
n
- Cloud: AWS/Azure/GCP logging patterns (nice-to-have)
n
n
n
#J-18808-Ljbffr
📌 Splunk Data Administrator (Victoria)
🏢 FR Consultancy
📍 Victoria
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.