01 Oct
|
Xpt Software Australia
|
Melbourne
01 Oct
Xpt Software Australia
Melbourne
Job Description
XPT Software Australia Pty Ltd | Contract
Splunk Data Administrator
Melbourne, Australia | Posted on 09/23/2026
XPT SoftwareAustralia PTY Ltd, incorporated in ****, is a Software Services company
XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining andManufacturingdomains.
We have 120+technocrats in Australia working at our clientlocations.
XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
Job Description
RoleSummary
We areseeking a mid to senior Splunk Data Administrator to own andcontinuouslyimproveSplunk data onboarding, normalization, and quality across a complexhybrid Splunk environment (on‐prem and cloud).
The idealcandidate is hands-on with CIM alignment, data source onboarding, fieldextractions(regex/props/transforms/ingestactions), TA deployment, andend-to-end operational management of Splunk data pipelines.
You willact as the key point of contact for ensuring log sources areonboardedcorrectly,parsed and normalized consistently, and made usable forsecurity/IToperations,dashboards, correlation searches, and reporting.
Key Responsibilities DataOnboarding & Lifecycle Management
Leadonboarding of new log sources end-to-end: requirements gathering, sourcevalidation, parsing strategy, TAselection/deployment,CIM alignment, testing,and release.
Partnerwith Security/IT teams to translate use-cases into data requirements, ensuringsources deliver the right fidelity, timeliness, and coverage.
Manageonboarding at scale using best practices for source types, metadata strategy,index & sourcetype governance, and naming conventions.
Defineand enforce data quality standards (field completeness, timestamps, eventconsistency, parsing accuracy, duplication control).
Normalizedata to Splunk Common Information Model (CIM) with robust understanding of datamodels (e.g., Authentication, Network Traffic, Endpoint, Change, etc.).
Ensurefields are aligned to CIM requirements to support Splunk Enterprise Security(ES) and other CIM-based content.
Validatenormalizationusing SPL and develop reusable onboarding checklists.
Designand implement robust field extractions using:
regex andstructured parsing (KV_MODE, JSON, XML)
ingest-time vs search-time extraction strategy
sourcetype / timestamp / line breaking configuration
Implementenrichmentand routing using event breaking, host/sourcenormalization,lookups,and tagging.
Install,configure, and maintain Splunk Add-ons (TAs) and apps across:
Indexers/ Search Heads / SHC
Deployment Server / Cluster Manager (where applicable)
Maintainversion compatibility and upgrade strategies for:
SplunkEnterprise / Splunk Cloud
Add-ons,apps, and content packs
Packageand deploy TAs using deployment pipelines and change management controls.
Ensurefields are aligned to CIM requirements
HybridSplunk Architecture Operations
Operateand support Splunk in complex environments:
On-premIndexer Cluster, Search Head Cluster, Forwarder tiers
SplunkCloud integrations where applicable (e.g., Heavy Forwarder, VPN,
PrivateLink,data forwarding patterns)
Configureand troubleshoot data ingestion pipelines:
Syslog(UDP/TCP), API-based collection, HEC, file monitors, Windows Event Logs, cloudsources
Ensureperformance and reliability across the pipeline, including indexing throughput,parsing overhead, and search impact.
Monitoring,Troubleshooting& Governance
Monitoringestion health and pipeline performance:
Maintaingovernance for indexes, sourcetypes, retention, RBAC and data access boundaries(as required).
Contribute to operational runbooks, SOPs, and documentation; drivecontinuousimprovementin onboarding and normalization standards.
RequiredSkills & Experience (Mid–Senior)
5–10years experience with Splunk administration and data onboarding (or equivalentdepth).
Strongpractical knowledge of:
Fieldextraction (regex, JSON/KV extraction), and troubleshooting parsing issues
props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
TAinstallation/configurationand deployment patterns across Splunk tiers
Experience with complex Splunk architectures:
Indexerclusters, SH/SHC, forwarder management, deployment server
Hybridpatterns (on-prem + cloud), connectivity, and ingestion strategies
Comfortable writing and validating SPL for data quality and CIM compliance.
Cloud:AWS/Azure/GCPlogging patterns (nice-to-have)
Preferred /Nice-to-Have
Experience with Splunk Enterprise Security (ES) and ES add-ons / CIMcomplianceexpectations.
Knowledgeof Splunk Ingest Actions / Edge Processor (or modern ingestion tools, whereapplicable).
Familiaritywith:
ITSI /Observability (bonus)
SplunkCore Certified Power User / Admin
#J-*****-Ljbffr
📌 Splunk Data Administrator (Melbourne)
🏢 Xpt Software Australia
📍 Melbourne