01 Oct
|
Wipro APAC
|
Melbourne
01 Oct
Wipro APAC
Melbourne
Job Description
Job Title
n
Splunk Data Administrator (Mid–Senior) – CIM / Data Onboarding / Hybrid
n
Architecture
n
Role Summary
n
We are seeking a mid to senior Splunk Data Administrator to own and continuously
n
improve Splunk data onboarding, normalization, and quality across a complex hybrid
n
Splunk environment (onprem and cloud).
n
The ideal candidate is hands-on with CIM alignment, data source onboarding, field
n
extractions
(regex/props/transforms/ingest
actions), TA deployment, and end-to-end
n
operational management of Splunk data pipelines.
n
You will act as the key point of contact for ensuring log sources are onboarded
n
correctly, parsed and normalized consistently, and made usable for security/IT
n
operations, dashboards, correlation searches, and reporting.
n
Key Responsibilities
n
Data Onboarding & Lifecycle Management
n
• Lead onboarding of new log sources end-to-end: requirements gathering, source
n
validation, parsing strategy, TA
selection/deployment,
CIM alignment, testing, and
n
release.
n
• Partner with Security/IT teams to translate use-cases into data requirements,
n
ensuring sources deliver the right fidelity, timeliness, and coverage.
n
• Manage onboarding at scale using best practices for source types, metadata
n
strategy, index & sourcetype governance, and naming conventions.
n
• Define and enforce data quality standards (field completeness, timestamps, event
n
consistency, parsing accuracy, duplication control).
n
CIM Normalization & Data Modelling
n
Publi
n
c
n
• Normalize data to Splunk Common Information Model (CIM) with robust
n
understanding of data models (e.g., Authentication, Network Traffic, Endpoint,
n
Change, etc.).
n
• Ensure fields are aligned to CIM requirements to support Splunk Enterprise
n
Security (ES) and other CIM-based content.
n
• Validate normalization using SPL and develop reusable onboarding checklists.
n
Field Extraction, Parsing & Enrichment
n
• Design and implement robust field extractions using:
n
- props.conf / transforms.conf, REPORT/TRANSFORMS stanzas
n
- regex and structured parsing (KV_MODE, JSON, XML)
n
- ingest-time vs search-time extraction strategy
n
- sourcetype / timestamp / line breaking configuration
n
• Implement enrichment and routing using event breaking, host/source normalization,
n
lookups, and tagging.
n
• Troubleshoot parsing issues (timestamp drift, multi-line events, encoding,
n
truncation, duplicate ingestion, broken extractions).
n
TA Installation & Configuration (Complex / Hybrid)
n
• Install, configure, and maintain Splunk Add-ons (TAs) and apps across:
n
- Heavy Forwarders / Universal Forwarders
n
- Indexers / Search Heads / SHC
n
- Deployment Server / Cluster Manager (where applicable)
n
• Maintain version compatibility and upgrade strategies for:
n
- Splunk Enterprise / Splunk Cloud
n
- Add-ons, apps, and content packs
n
• Package and deploy TAs using deployment pipelines and change management
n
controls.
n
• Ensure fields are aligned to CIM requirements
n
Publi
n
c
n
Hybrid Splunk Architecture Operations
n
• Operate and support Splunk in complex environments:
n
- On-prem Indexer Cluster, Search Head Cluster, Forwarder tiers
n
- Splunk Cloud integrations where applicable (e.g., Heavy Forwarder, VPN,
n
PrivateLink, data forwarding patterns)
n
• Configure and troubleshoot data ingestion pipelines:
n
- Syslog (UDP/TCP), API-based collection, HEC, file monitors, Windows Event Logs,
n
cloud sources
n
• Ensure performance and reliability across the pipeline, including indexing
n
throughput, parsing overhead, and search impact.
n
Monitoring,
Troubleshooting & Governance
n
• Monitor ingestion health and pipeline performance:
n
- Forwarder health, queue saturation, parsing/indexing delays, dropped events
n
• Maintain governance for indexes, sourcetypes, retention, RBAC and data access
n
boundaries (as required).
n
• Contribute to operational runbooks, SOPs, and documentation; drive continuous
n
improvement in onboarding and normalization standards.
n
Required Skills & Experience (Mid–Senior)
n
• 5–10 years experience with Splunk administration and data onboarding (or
n
equivalent depth).
n
• Strong practical knowledge of:
n
- CIM normalization, tags/eventtypes, datamodel alignment
n
- Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues
n
- props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
n
- TA
installation/configuration
and deployment patterns across Splunk tiers
n
Public
n
• Experience with complex Splunk architectures:
n
- Indexer clusters, SH/SHC, forwarder management, deployment server
n
- Hybrid patterns (on-prem + cloud), connectivity, and ingestion strategies
n
• Comfortable writing and validating SPL for data quality and CIM compliance.
n
• Strong log source knowledge across common domains:
n
- Security: EDR, firewall, proxy, IAM/auth, VPN, email security
n
- Infrastructure: Windows, Linux, network devices, virtualization
n
- Cloud: AWS/Azure/GCP logging patterns (nice-to-have)
n
Preferred / Nice-to-Have
n
• Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM compliance
n
expectations.
n
• Knowledge of Splunk Ingest Actions / Edge Processor (or modern ingestion tools,
n
where applicable).
n
• Familiarity with:
n
- HEC, API ingestion, message queues
n
- ITSI / Observability (bonus)
n
• Splunk certifications (preferred):
n
- Splunk Core Certified Power User / Admin
n
- Splunk Enterprise Certified Admin
n
- Splunk ES Admin (bonus)
📌 Splunk Data Administrator (Melbourne)
🏢 Wipro APAC
📍 Melbourne