Splunk Data Administrator (Melbourne)

Splunk Data Administrator (Melbourne)

26 Sep
|
Whizdom
|
Melbourne

26 Sep

Whizdom

Melbourne

Splunk Data Administrator

- Location:

Melbourne

- Contract:

Initial 6-month contract with potential extension

- Start:

ASAP

We are seeking an experienced

Splunk Data Administrator to support and continuously improve data onboarding, normalisation and quality across a complex hybrid Splunk environment.

This hands-on contract role will be responsible for ensuring log sources are correctly onboarded, parsed, normalised and made available for security operations, IT operations, dashboards, correlation searches and reporting.

Key Responsibilities:

- Lead the end-to-end onboarding of new log sources, including requirements gathering, parsing, testing and release

- Align data sources with the Splunk Common Information Model

- Develop and maintain field extractions using regex, props.conf and transforms.conf

- Configure sourcetypes, timestamps, line breaking and structured data parsing

- Install, configure and deploy Splunk Technology Add-ons across forwarders, indexers and search heads

- Support hybrid Splunk environments incorporating on-premises and cloud infrastructure

- Configure and troubleshoot ingestion through Syslog, HEC, APIs, file monitoring and Windows Event Logs

- Monitor pipeline performance, indexing delays, forwarder health and data quality

- Maintain governance across indexes, sourcetypes, retention and access controls

- Develop operational documentation, runbooks and onboarding standards

Skills and Experience





- Approximately 5 to 10 years of Splunk administration, data onboarding or equivalent experience

- Strong knowledge of CIM normalisation, data models, tags and event types

- Demonstrated experience with regex, JSON and key-value field extraction

- Advanced knowledge of props.conf, transforms.conf, sourcetypes and timestamp configuration

- Experience deploying and managing Splunk Add-ons across multiple Splunk tiers

- Experience supporting indexer clusters, search head clusters, forwarders and deployment servers

- Understanding of hybrid Splunk architecture and cloud-based ingestion patterns

- Ability to write and validate SPL for data quality and CIM compliance

- Knowledge of security, infrastructure and cloud log sources

Highly Regarded

- Splunk Enterprise Security experience

- Experience with Splunk Ingest Actions or Edge Processor

- Knowledge of HEC, API ingestion and message queues

- Exposure to ITSI or observability platforms

- Splunk Power User, Administrator or Enterprise Security certifications

Why Apply?

- Initial 6-month contract with potential extension

- Melbourne-based opportunity

- Immediate start

- Work within a complex hybrid Splunk environment

- Take ownership of data onboarding, quality and normalisation

If you are an experienced Splunk skilled who enjoys solving complex ingestion and data-quality challenges, apply now with your updated resume.

📌 Splunk Data Administrator (Melbourne)
🏢 Whizdom
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator (melbourne) / melbourne

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator (melbourne) / melbourne