25 Sep
|
Xpt Software Australia
|
Victoria
25 Sep
Xpt Software Australia
Victoria
Job Description
n
XPT Software Australia Pty Ltd | Contract
Splunk Data Administrator n
Melbourne, Australia | Posted on 09/23/2026
n
n
XPT SoftwareAustralia PTY Ltd, incorporated in ****, is a Software Services company
n
XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and
Manufacturingdomains.
n
We have 120+technocrats in Australia working at our clientlocations.
n
XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
n
We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
n
Job Description n
RoleSummary
n
We areseeking a mid to senior Splunk Data Administrator to own and
continuouslyimprove
Splunk data onboarding, normalization, and quality across a complexhybrid Splunk environment (on‐prem and cloud).
n
The idealcandidate is hands-on with CIM alignment, data source onboarding, fieldextractions
(regex/props/transforms/ingest
actions), TA deployment, andend-to-end operational management of Splunk data pipelines.
n
You willact as the key point of contact for ensuring log sources are
onboardedcorrectly,
parsed and normalized consistently, and made usable for
security/IToperations,
dashboards, correlation searches, and reporting.
Key Responsibilities DataOnboarding & Lifecycle Management n
n
Leadonboarding of recent log sources end-to-end: requirements gathering, sourcevalidation, parsing strategy, TA
selection/deployment,
CIM alignment, testing,and release.
n
Partnerwith Security/IT teams to translate use-cases into data requirements, ensuringsources deliver the right fidelity, timeliness, and coverage.
n
Manageonboarding at scale using best practices for source types, metadata strategy,index & sourcetype governance, and naming conventions.
n
Defineand enforce data quality standards (field completeness,
timestamps, eventconsistency, parsing accuracy, duplication control).
n
Normalizedata to Splunk Common Information Model (CIM) with strong understanding of datamodels (e.g., Authentication, Network Traffic, Endpoint, Change, etc.).
n
Ensurefields are aligned to CIM requirements to support Splunk Enterprise Security(ES) and other CIM-based content.
n
Validatenormalization
using SPL and develop reusable onboarding checklists.
n
Designand implement robust field extractions using: n
n
regex andstructured parsing (KV_MODE, JSON, XML)
n
ingest-time vs search-time extraction strategy
n
sourcetype / timestamp / line breaking configuration
n
n
Implementenrichment
and routing using event breaking, host/source
normalization,lookups,
and tagging.
n
Install,configure, and maintain Splunk Add-ons (TAs) and apps across: n
n
Indexers/ Search Heads / SHC
n
Deployment Server / Cluster Manager (where applicable)
n
n
Maintainversion compatibility and upgrade strategies for: n
n
SplunkEnterprise / Splunk Cloud
n
Add-ons,apps, and content packs
n
n
Packageand deploy TAs using deployment pipelines and change management controls.
n
Ensurefields are aligned to CIM requirements
n
HybridSplunk Architecture Operations n
n
Operateand support Splunk in complex environments: n
n
On-premIndexer Cluster, Search Head Cluster, Forwarder tiers
n
SplunkCloud integrations where applicable (e.g., Heavy Forwarder, VPN,
PrivateLink,data forwarding patterns)
n
n
Configureand troubleshoot data ingestion pipelines: n
n
Syslog(UDP/TCP), API-based collection, HEC, file monitors, Windows Event Logs, cloudsources
n
n
Ensureperformance and reliability across the pipeline, including indexing throughput,parsing overhead, and search impact.
n
Monitoring,Troubleshooting
& Governance n
n
Monitoringestion health and pipeline performance:
n
Maintaingovernance for indexes, sourcetypes, retention, RBAC and data access boundaries(as required).
n
Contribute to operational runbooks, SOPs, and documentation; drive
continuousimprovement
in onboarding and normalization standards.
n
RequiredSkills & Experience (Mid–Senior) n
n
5–10years experience with Splunk administration and data onboarding (or equivalentdepth).
n
Strongpractical knowledge of: n
n
Fieldextraction (regex, JSON/KV extraction), and troubleshooting parsing issues
n
props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
n
TAinstallation/configuration
and deployment patterns across Splunk tiers
n
n
Experience with complex Splunk architectures: n
n
Indexerclusters, SH/SHC, forwarder management, deployment server
n
Hybridpatterns (on-prem + cloud), connectivity, and ingestion strategies
n
n
Comfortable writing and validating SPL for data quality and CIM compliance.
n
Cloud:AWS/Azure/GCP
logging patterns (nice-to-have)
n
Preferred /Nice-to-Have n
n
Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM
complianceexpectations.
n
Knowledgeof Splunk Ingest Actions / Edge Processor (or modern ingestion tools, whereapplicable).
n
Familiaritywith: n
n
ITSI /Observability (bonus)
n
SplunkCore Certified Power User / Admin
n
n
n
#J-*****-Ljbffr
📌 Splunk Data Administrator (Victoria)
🏢 Xpt Software Australia
📍 Victoria