06 Oct
|
XPT Software
|
Melbourne
06 Oct
XPT Software
Melbourne
Job Description
We are seeking a mid to senior Splunk Data Administrator to own and continuously improve Splunk data onboarding, normalization, and quality across a complex hybrid Splunk environment (on‑prem and cloud).
n
The ideal candidate is hands‑on with CIM alignment, data source onboarding, field extractions (regex/props/transforms/ingest actions), TA deployment, and end‑to‑end operational management of Splunk data pipelines.
n
You will act as the key point of contact for ensuring log sources are onboarded correctly, parsed and normalized consistently, and made usable for security/IT operations, dashboards, correlation searches, and reporting.
Key Responsibilities Data Onboarding & Lifecycle Management n
n
- Lead onboarding of new log sources end‑to‑end: requirements gathering, source validation, parsing strategy, TA selection/deployment, CIM alignment, testing, and release.
n
- Partner with Security/IT teams to translate use‑cases into data requirements, ensuring sources deliver the right fidelity, timeliness, and coverage.
n
- Manage onboarding at scale using best practices for source types, metadata strategy, index & sourcetype governance, and naming conventions.
n
- Define and enforce data quality standards (field completeness, timestamps, event consistency, parsing accuracy, duplication control).
n
- Normalize data to Splunk Common Information Model (CIM) with strong understanding of data models (e.g., Authentication, Network Traffic, Endpoint, Change, etc.).
n
- Ensure fields are aligned to CIM requirements to support Splunk Enterprise Security (ES) and other CIM‑based content.
n
- Validate normalization using SPL and develop reusable onboarding checklists.
n
- Design and implement robust field extractions using: n n
- regex and structured parsing (KV_MODE, JSON, XML)
n
- sourcetype / timestamp / line breaking configuration
n
n
- Implement enrichment and routing using event breaking, host/source normalization, lookups, and tagging.
n
- Install, configure, and maintain Splunk Add‑ons (TAs) and apps across: n
n
- Indexers / Search Heads / SHC
n
- Deployment Server / Cluster Manager (where applicable)
n
n
- Maintain version compatibility and upgrade strategies for: n
n
- Splunk Enterprise / Splunk Cloud
n
- Add‑ons, apps, and content packs
n
n
- Package and deploy TAs using deployment pipelines and change management controls.
n
- Ensure fields are aligned to CIM requirements
n
Hybrid Splunk Architecture Operations nn
- Operate and support Splunk in complex environments: n n
- On‑prem Indexer Cluster, Search Head Cluster, Forwarder tiers
n
- Splunk Cloud integrations where applicable (e.g., Heavy Forwarder, VPN, PrivateLink, data forwarding patterns)
n
n
- Configure and troubleshoot data ingestion pipelines: n
n
- Syslog (UDP/TCP), API‑based collection, HEC, file monitors, Windows Event Logs, cloud sources
n
n
- Ensure performance and reliability across the pipeline, including indexing throughput, parsing overhead, and search impact.
n
Monitoring, Troubleshooting & Governance nn
- Monitor ingestion health and pipeline performance:
n
- Maintain governance for indexes, sourcetypes, retention, RBAC and data access boundaries (as required).
n
- Contribute to operational runbooks, SOPs, and documentation; drive continuous improvement in onboarding and normalization standards.
n
Required Skills & Experience (Mid–Senior) nn
- 5–10 years experience with Splunk administration and data onboarding (or equivalent depth).
n
- Solid practical knowledge of:
n
- Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues
n
- props.conf / transforms.conf, sourcetypes, timestamps, line‑breaking
n
- TA installation/configuration and deployment patterns across Splunk tiers
n
- Experience with complex Splunk architectures:
n
- Indexer clusters, SH/SHC, forwarder management, deployment server
n
- Hybrid patterns (on‑prem + cloud), connectivity, and ingestion strategies
n
- Comfortable writing and validating SPL for data quality and CIM compliance.
n
- Cloud: AWS/Azure/GCP logging patterns (nice‑to‑have)
n
Preferred / Nice-to-Have nn
- Experience with Splunk Enterprise Security (ES) and ES add‑ons / CIM compliance expectations.
n
- Knowledge of Splunk Ingest Actions / Edge Processor (or modern ingestion tools, where applicable).
n
- Familiarity with:
n
- ITSI / Observability (bonus)
n
- Splunk Core Certified Power User / Admin
n
#J-18808-Ljbffr
📌 Splunk Data Administrator (Melbourne)
🏢 XPT Software
📍 Melbourne