03 Oct
|
Whizdom
|
Melbourne
Contract: Initial 6-month contract with potential extension
Start: ASAP
We are seeking an experienced Splunk Data Administrator to support and continuously improve data onboarding, normalisation and quality across a complex hybrid Splunk workplace.
This hands-on contract role will be responsible for ensuring log sources are correctly onboarded, parsed, normalised and made available for security operations, IT operations, dashboards, correlation searches and reporting.
Key Responsibilities:
Lead the end-to-end onboarding of recent log sources, including requirements gathering, parsing, testing and release
Align data sources with the Splunk Common Information Model
Develop and maintain field extractions using regex, props.conf and transforms.conf
Configure sourcetypes, timestamps, line breaking and structured data parsing
Install, configure and deploy Splunk Technology Add-ons across forwarders, indexers and search heads
Support hybrid Splunk environments incorporating on-premises and cloud infrastructure
Configure and troubleshoot ingestion through Syslog, HEC, APIs, file monitoring and Windows Event Logs
Monitor pipeline performance, indexing delays, forwarder health and data quality
Maintain governance across indexes, sourcetypes,
retention and access controls
Develop operational documentation, runbooks and onboarding standards
Skills and Experience
Approximately 5 to 10 years of Splunk administration, data onboarding or equivalent experience
Solid knowledge of CIM normalisation, data models, tags and event types
Demonstrated experience with regex, JSON and key-value field extraction
Advanced knowledge of props.conf, transforms.conf, sourcetypes and timestamp configuration
Experience deploying and managing Splunk Add-ons across multiple Splunk tiers
Experience supporting indexer clusters, search head clusters, forwarders and deployment servers
Understanding of hybrid Splunk architecture and cloud-based ingestion patterns
Ability to write and validate SPL for data quality and CIM compliance
Knowledge of security, infrastructure and cloud log sources
Highly Regarded
Splunk Enterprise Security experience
Experience with Splunk Ingest Actions or Edge Processor
Knowledge of HEC, API ingestion and message queues
Exposure to ITSI or observability platforms
Splunk Power User, Administrator or Enterprise Security certifications
J-18808-Ljbffr
📌 Splunk Data Administrator Melbourne
🏢 Whizdom
📍 Melbourne