01 Oct
|
XPT Software
|
Melbourne
01 Oct
XPT Software
Melbourne
Job Description
We are seeking a mid to senior Splunk Data Administrator to own and continuously improve Splunk data onboarding, normalization, and quality across a complex hybrid Splunk environment (on‐prem and cloud).
n
The ideal candidate is hands‐on with CIM alignment, data source onboarding, field extractions
(regex/props/transforms/ingest
actions), TA deployment, and end‐to‐end operational management of Splunk data pipelines.
n
You will act as the key point of contact for ensuring log sources are onboarded correctly, parsed and normalized consistently, and made usable for security/IT operations, dashboards, correlation searches, and reporting.
Key Responsibilities Data Onboarding & Lifecycle Management n
n
Lead onboarding of new log sources end‐to‐end: requirements gathering, source validation, parsing strategy, TA
selection/deployment,
CIM alignment, testing, and release.
n
Partner with Security/IT teams to translate use‐cases into data requirements, ensuring sources deliver the right fidelity, timeliness, and coverage.
n
Manage onboarding at scale using best practices for source types, metadata strategy, index & sourcetype governance, and naming conventions.
n
Define and enforce data quality standards (field completeness, timestamps, event consistency, parsing accuracy, duplication control).
n
Normalize data to Splunk Common Information Model (CIM) with robust understanding of data models (e.g., Authentication, Network Traffic, Endpoint, Change, etc.).
n
Ensure fields are aligned to CIM requirements to support Splunk Enterprise Security (ES) and other CIM‐based content.
n
Validate normalization using SPL and develop reusable onboarding checklists.
n
Design and implement robust field extractions using: n
n
regex and structured parsing (KV_MODE, JSON, XML)
n
sourcetype / timestamp / line breaking configuration
n
n
Implement enrichment and routing using event breaking, host/source normalization, lookups, and tagging.
n
Install, configure, and maintain Splunk Add‐ons (TAs) and apps across: n
n
Indexers / Search Heads / SHC
n
Deployment Server / Cluster Manager (where applicable)
n
n
Maintain version compatibility and upgrade strategies for: n
n
Splunk Enterprise / Splunk Cloud
n
Add‐ons, apps, and content packs
n
n
Package and deploy TAs using deployment pipelines and change management controls.
n
Ensure fields are aligned to CIM requirements
n
Hybrid Splunk Architecture Operations n
n
Operate and support Splunk in complex environments: n
n
On‐prem Indexer Cluster, Search Head Cluster, Forwarder tiers
n
Splunk Cloud integrations where applicable (e.g., Heavy Forwarder, VPN, PrivateLink, data forwarding patterns)
n
n
Configure and troubleshoot data ingestion pipelines: n
n
Syslog (UDP/TCP), API‐based collection, HEC, file monitors, Windows Event Logs, cloud sources
n
n
Ensure performance and reliability across the pipeline, including indexing throughput, parsing overhead, and search impact.
n
Monitoring, Troubleshooting & Governance n
n
Monitor ingestion health and pipeline performance:
n
Maintain governance for indexes, sourcetypes, retention, RBAC and data access boundaries (as required).
n
Contribute to operational runbooks, SOPs, and documentation; drive continuous improvement in onboarding and normalization standards.
n
Required Skills & Experience (Mid–Senior) n
n
5–10 years experience with Splunk administration and data onboarding (or equivalent depth).
n
Strong practical knowledge of:
n
Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues
n
props.conf / transforms.conf, sourcetypes, timestamps, line‐breaking
n
TA
installation/configuration
and deployment patterns across Splunk tiers
n
Experience with complex Splunk architectures:
n
Indexer clusters, SH/SHC, forwarder management, deployment server
n
Hybrid patterns (on‐prem + cloud), connectivity, and ingestion strategies
n
Comfortable writing and validating SPL for data quality and CIM compliance.
n
Cloud: AWS/Azure/GCP logging patterns (nice‐to‐have)
n
Preferred / Nice-to-Have n
n
Experience with Splunk Enterprise Security (ES) and ES add‐ons / CIM compliance expectations.
n
Knowledge of Splunk Ingest Actions / Edge Processor (or modern ingestion tools, where applicable).
n
Familiarity with:
n
ITSI / Observability (bonus)
n
Splunk Core Certified Power User / Admin
n
#J-*****-Ljbffr
📌 Splunk Data Administrator (Melbourne)
🏢 XPT Software
📍 Melbourne