26 Sep
|
Whizdom
|
Melbourne
Splunk Data Administrator
- Location:
Melbourne
- Contract:
Initial 6-month contract with potential extension
- Start:
ASAP
We are seeking an experienced
Splunk Data Administrator to support and continuously improve data onboarding, normalisation and quality across a complex hybrid Splunk environment.
This hands-on contract role will be responsible for ensuring log sources are correctly onboarded, parsed, normalised and made available for security operations, IT operations, dashboards, correlation searches and reporting.
Key Responsibilities:
- Lead the end-to-end onboarding of new log sources, including requirements gathering, parsing, testing and release
- Align data sources with the Splunk Common Information Model
- Develop and maintain field extractions using regex, props.conf and transforms.conf
- Configure sourcetypes, timestamps, line breaking and structured data parsing
- Install, configure and deploy Splunk Technology Add-ons across forwarders, indexers and search heads
- Support hybrid Splunk environments incorporating on-premises and cloud infrastructure
- Configure and troubleshoot ingestion through Syslog, HEC, APIs, file monitoring and Windows Event Logs
- Monitor pipeline performance, indexing delays, forwarder health and data quality
- Maintain governance across indexes, sourcetypes, retention and access controls
- Develop operational documentation, runbooks and onboarding standards
Skills and Experience
- Approximately 5 to 10 years of Splunk administration, data onboarding or equivalent experience
- Strong knowledge of CIM normalisation, data models, tags and event types
- Demonstrated experience with regex, JSON and key-value field extraction
- Advanced knowledge of props.conf, transforms.conf, sourcetypes and timestamp configuration
- Experience deploying and managing Splunk Add-ons across multiple Splunk tiers
- Experience supporting indexer clusters, search head clusters, forwarders and deployment servers
- Understanding of hybrid Splunk architecture and cloud-based ingestion patterns
- Ability to write and validate SPL for data quality and CIM compliance
- Knowledge of security, infrastructure and cloud log sources
Highly Regarded
- Splunk Enterprise Security experience
- Experience with Splunk Ingest Actions or Edge Processor
- Knowledge of HEC, API ingestion and message queues
- Exposure to ITSI or observability platforms
- Splunk Power User, Administrator or Enterprise Security certifications
Why Apply?
- Initial 6-month contract with potential extension
- Melbourne-based opportunity
- Immediate start
- Work within a complex hybrid Splunk environment
- Take ownership of data onboarding, quality and normalisation
If you are an experienced Splunk skilled who enjoys solving complex ingestion and data-quality challenges, apply now with your updated resume.
📌 Splunk Data Administrator (Melbourne)
🏢 Whizdom
📍 Melbourne