Splunk Data Administrator Melbourne

Splunk Data Administrator Melbourne

27 Sep
|
FR Consultancy
|
Melbourne

27 Sep

FR Consultancy

Melbourne

Role: Splunk Data Administrator

Type: Full Time / Contract

Location: Melbourne, AU

Status: AU valid visa with full work rights

Requisites:
5–10 years experience with Splunk administration and data onboarding (or equivalent depth).
Robust practical knowledge of:
CIM normalization, tags/eventtypes, datamodel alignment
Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues
props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
TA installation/configuration and deployment patterns across Splunk tiers

• Experience with complex Splunk architectures:
Indexer clusters, SH/SHC, forwarder management, deployment server
Hybrid patterns (on-prem + cloud), connectivity, and ingestion strategies

• Comfortable writing and validating SPL for data quality and CIM compliance.
Solid log source knowledge across common domains:
Security: EDR, firewall, proxy, IAM/auth, VPN, email security
Infrastructure: Windows, Linux, network devices, virtualization
Cloud: AWS/Azure/GCP logging patterns (nice-to-have)

Interested? Please apply, thanks for your interest and time.

📌 Splunk Data Administrator Melbourne
🏢 FR Consultancy
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator melbourne / melbourne

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator melbourne / melbourne