05 Oct
|
Whizdom
|
Melbourne
Job Description
n
Contract:
Initial 6-month contract with potential extension
n
Start:
ASAP
n
n
We are seeking an experienced
Splunk Data Administrator
to support and continuously improve data onboarding, normalisation and quality across a complex hybrid Splunk environment.
n
This hands-on contract role will be responsible for ensuring log sources are correctly onboarded, parsed, normalised and made available for security operations, IT operations, dashboards, correlation searches and reporting.
n
Key Responsibilities:
n
n
Lead the end-to-end onboarding of current log sources, including requirements gathering, parsing, testing and release
n
Align data sources with the Splunk Common Information Model
n
Develop and maintain field extractions using regex, props.conf and transforms.conf
n
Configure sourcetypes, timestamps, line breaking and structured data parsing
n
Install, configure and deploy Splunk Technology Add-ons across forwarders, indexers and search heads
n
Support hybrid Splunk environments incorporating on-premises and cloud infrastructure
n
Configure and troubleshoot ingestion through Syslog, HEC, APIs, file monitoring and Windows Event Logs
n
Monitor pipeline performance, indexing delays, forwarder health and data quality
n
Maintain governance across indexes, sourcetypes,
retention and access controls
n
Develop operational documentation, runbooks and onboarding standards
n
n
Skills and Experience
n
n
Approximately 5 to 10 years of Splunk administration, data onboarding or equivalent experience
n
Strong knowledge of CIM normalisation, data models, tags and event types
n
Demonstrated experience with regex, JSON and key-value field extraction
n
Advanced knowledge of props.conf, transforms.conf, sourcetypes and timestamp configuration
n
Experience deploying and managing Splunk Add-ons across multiple Splunk tiers
n
Experience supporting indexer clusters, search head clusters, forwarders and deployment servers
n
Understanding of hybrid Splunk architecture and cloud-based ingestion patterns
n
Ability to write and validate SPL for data quality and CIM compliance
n
Knowledge of security, infrastructure and cloud log sources
n
n
Highly Regarded
n
n
Splunk Enterprise Security experience
n
Experience with Splunk Ingest Actions or Edge Processor
n
Knowledge of HEC, API ingestion and message queues
n
Exposure to ITSI or observability platforms
n
Splunk Power User, Administrator or Enterprise Security certifications
n
#J-*****-Ljbffr
📌 Splunk Data Administrator (Melbourne)
🏢 Whizdom
📍 Melbourne