24 Sep
|
Xpt Software Australia
|
Melbourne
24 Sep
Xpt Software Australia
Melbourne
XPT Software Australia Pty Ltd | Contract
Splunk Data Administrator
Melbourne, Australia | Posted on 09/23/2026
XPT SoftwareAustralia PTY Ltd, incorporated in ****, is a Software Services company
XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
We have 120+technocrats in Australia working at our clientlocations.
XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
Job Description
RoleSummary
We areseeking a mid to senior Splunk Data Administrator to own and continuouslyimprove Splunk data onboarding, normalization, and quality across a complexhybrid Splunk environment (on‐prem and cloud).
The idealcandidate is hands-on with CIM alignment, data source onboarding, fieldextractions (regex/props/transforms/ingest actions), TA deployment, andend-to-end operational management of Splunk data pipelines.
You willact as the key point of contact for ensuring log sources are onboardedcorrectly, parsed and normalized consistently, and made usable for security/IToperations, dashboards, correlation searches, and reporting.
Key Responsibilities
DataOnboarding & Lifecycle Management
Leadonboarding of new log sources end-to-end: requirements gathering, sourcevalidation, parsing strategy, TA selection/deployment, CIM alignment, testing,and release.
Partnerwith Security/IT teams to translate use-cases into data requirements, ensuringsources deliver the right fidelity, timeliness, and coverage.
Manageonboarding at scale using best practices for source types, metadata strategy,index & sourcetype governance, and naming conventions.
Defineand enforce data quality standards (field completeness, timestamps, eventconsistency, parsing accuracy, duplication control).
Normalizedata to Splunk Common Information Model (CIM) with solid understanding of datamodels (e.g., Authentication, Network Traffic, Endpoint, Change, etc.).
Ensurefields are aligned to CIM requirements to support Splunk Enterprise Security(ES) and other CIM-based content.
Validatenormalization using SPL and develop reusable onboarding checklists.
Designand implement robust field extractions using:
regex andstructured parsing (KV_MODE, JSON, XML)
ingest-time vs search-time extraction strategy
sourcetype / timestamp / line breaking configuration
Implementenrichment and routing using event breaking, host/source normalization,lookups, and tagging.
Install,configure, and maintain Splunk Add-ons (TAs) and apps across:
Indexers/ Search Heads / SHC
Deployment Server / Cluster Manager (where applicable)
Maintainversion compatibility and upgrade strategies for:
SplunkEnterprise / Splunk Cloud
Add-ons,apps, and content packs
Packageand deploy TAs using deployment pipelines and change management controls.
Ensurefields are aligned to CIM requirements
HybridSplunk Architecture Operations
Operateand support Splunk in complex environments:
On-premIndexer Cluster, Search Head Cluster, Forwarder tiers
SplunkCloud integrations where applicable (e.g., Heavy Forwarder, VPN,
PrivateLink,data forwarding patterns)
Configureand troubleshoot data ingestion pipelines:
Syslog(UDP/TCP), API-based collection, HEC, file monitors, Windows Event Logs, cloudsources
Ensureperformance and reliability across the pipeline, including indexing throughput,parsing overhead, and search impact.
Monitoring,Troubleshooting & Governance
Monitoringestion health and pipeline performance:
Maintaingovernance for indexes, sourcetypes, retention, RBAC and data access boundaries(as required).
Contribute to operational runbooks, SOPs, and documentation; drive continuousimprovement in onboarding and normalization standards.
RequiredSkills & Experience (Mid–Senior)
5–10years experience with Splunk administration and data onboarding (or equivalentdepth).
Strongpractical knowledge of:
Fieldextraction (regex, JSON/KV extraction), and troubleshooting parsing issues
props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
TAinstallation/configuration and deployment patterns across Splunk tiers
Experience with complex Splunk architectures:
Indexerclusters, SH/SHC, forwarder management, deployment server
Hybridpatterns (on-prem + cloud), connectivity, and ingestion strategies
Comfortable writing and validating SPL for data quality and CIM compliance.
Cloud:AWS/Azure/GCP logging patterns (nice-to-have)
Preferred /Nice-to-Have
Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM complianceexpectations.
Knowledgeof Splunk Ingest Actions / Edge Processor (or modern ingestion tools, whereapplicable).
Familiaritywith:
ITSI /Observability (bonus)
SplunkCore Certified Power User / Admin
#J-*****-Ljbffr
📌 Splunk Data Administrator (Melbourne)
🏢 Xpt Software Australia
📍 Melbourne