26 Sep
|
Xpt Software Australia
|
Victoria
26 Sep
Xpt Software Australia
Victoria
Job Description
n
XPT Software Australia Pty Ltd | Contract
Splunk Data Administrator n
Melbourne, Australia | Posted on 09/23/2026
n
n
- XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
n
- XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
n
- We have 120+technocrats in Australia working at our clientlocations.
n
- XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
n
- We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
n
Job Description n
RoleSummary
n
We areseeking a mid to senior Splunk Data Administrator to own and continuouslyimprove Splunk data onboarding, normalization, and quality across a complexhybrid Splunk environment (on‑prem and cloud).
n
The idealcandidate is hands-on with CIM alignment, data source onboarding, fieldextractions (regex/props/transforms/ingest actions), TA deployment, andend-to-end operational management of Splunk data pipelines.
n
You willact as the key point of contact for ensuring log sources are onboardedcorrectly, parsed and normalized consistently, and made usable for security/IToperations, dashboards, correlation searches, and reporting.
Key Responsibilities DataOnboarding & Lifecycle Management n
n
- Leadonboarding of new log sources end-to-end: requirements gathering, sourcevalidation, parsing strategy, TA selection/deployment, CIM alignment, testing,and release.
n
- Partnerwith Security/IT teams to translate use-cases into data requirements, ensuringsources deliver the right fidelity, timeliness, and coverage.
n
- Manageonboarding at scale using best practices for source types, metadata strategy,index & sourcetype governance, and naming conventions.
n
- Defineand enforce data quality standards (field completeness,
timestamps, eventconsistency, parsing accuracy, duplication control).
n
- Normalizedata to Splunk Common Information Model (CIM) with strong understanding of datamodels (e.g., Authentication, Network Traffic, Endpoint, Change, etc.).
n
- Ensurefields are aligned to CIM requirements to support Splunk Enterprise Security(ES) and other CIM-based content.
n
- Validatenormalization using SPL and develop reusable onboarding checklists.
n
- Designand implement robust field extractions using: n n
- regex andstructured parsing (KV_MODE, JSON, XML)
n
- ingest-time vs search-time extraction strategy
n
- sourcetype / timestamp / line breaking configuration
n
n
- Implementenrichment and routing using event breaking, host/source normalization,lookups, and tagging.
n
- Install,configure, and maintain Splunk Add-ons (TAs) and apps across: n
n
- Indexers/ Search Heads / SHC
n
- Deployment Server / Cluster Manager (where applicable)
n
n
- Maintainversion compatibility and upgrade strategies for: n
n
- SplunkEnterprise / Splunk Cloud
n
- Add-ons,apps, and content packs
n
n
- Packageand deploy TAs using deployment pipelines and change management controls.
n
- Ensurefields are aligned to CIM requirements
n
HybridSplunk Architecture Operations nn
- Operateand support Splunk in complex environments: n n
- On-premIndexer Cluster, Search Head Cluster, Forwarder tiers
n
- SplunkCloud integrations where applicable (e.g., Heavy Forwarder, VPN,
PrivateLink,data forwarding patterns)
n
n
- Configureand troubleshoot data ingestion pipelines: n
n
- Syslog(UDP/TCP), API-based collection, HEC, file monitors, Windows Event Logs, cloudsources
n
n
- Ensureperformance and reliability across the pipeline, including indexing throughput,parsing overhead, and search impact.
n
Monitoring,Troubleshooting & Governance n
n
- Monitoringestion health and pipeline performance:
n
- Maintaingovernance for indexes, sourcetypes, retention, RBAC and data access boundaries(as required).
n
- Contribute to operational runbooks, SOPs, and documentation; drive continuousimprovement in onboarding and normalization standards.
n
RequiredSkills & Experience (Mid–Senior) nn
- 5–10years experience with Splunk administration and data onboarding (or equivalentdepth).
n
- Strongpractical knowledge of: n n
- Fieldextraction (regex, JSON/KV extraction), and troubleshooting parsing issues
n
- props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
n
- TAinstallation/configuration and deployment patterns across Splunk tiers
n
n
- Experience with complex Splunk architectures: n
n
- Indexerclusters, SH/SHC, forwarder management, deployment server
n
- Hybridpatterns (on-prem + cloud), connectivity, and ingestion strategies
n
n
- Comfortable writing and validating SPL for data quality and CIM compliance.
n
- Cloud:AWS/Azure/GCP logging patterns (nice-to-have)
n
Preferred /Nice-to-Have nn
- Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM complianceexpectations.
n
- Knowledgeof Splunk Ingest Actions / Edge Processor (or up-to-date ingestion tools, whereapplicable).
n
- Familiaritywith: n n
- ITSI /Observability (bonus)
n
- SplunkCore Certified Power User / Admin
n
n
n
#J-18808-Ljbffr
📌 Splunk Data Administrator (Victoria)
🏢 Xpt Software Australia
📍 Victoria