Splunk Data Administrator (Melbourne)

Splunk Data Administrator (Melbourne)

07 Oct
|
XPT Software Australia Pty
|
Melbourne

07 Oct

XPT Software Australia Pty

Melbourne

Job Description
Role Summary
n
n
We are seeking a mid to senior Splunk
n Data Administrator to own and continuously improve Splunk data onboarding,
n normalization, and quality across a complex hybrid Splunk workplace (on‐prem
n and cloud).
n
n
The ideal candidate is hands -on with CIM
n alignment, data source onboarding, field extractions
n
(regex/props/transforms/ingest
actions), TA deployment, and end -to -end
n operational management of Splunk data pipelines.
n
n

n
n
You will act as the key point of contact
n for ensuring log sources are onboarded correctly, parsed and normalized
n consistently, and made usable for security/IT operations, dashboards,
n correlation searches, and reporting.
n
n

n
n

n
n
Splunk:
n
n
- Good understanding of Splunk
n architecture and its components (Search Heads, Indexers, Deployers).
n
n
- Experience in managing and
n troubleshooting Splunk distributed environments (clusters), Splunk upgrade and
n migration .
n
n

n
n
Operating Systems & Cloud Platforms:
n
n
- Expertise in Linux systems, specifically
n RHEL and Amazon Linux.
n
n
- Experience with AWS services, including
n EC2, S3, IAM, VPC, Subnets, Security Groups and CloudWatch.
n
n

n
n
DevOps & Automation Tools:
n
n
- Experience with Jenkins pipelines and CI/CD
n processes, Ansible for configuration management and automation, Terraform for infrastructure
n provisioning.
n
n
- Ability to write custom Ansible playbooks and
n Terraform modules for system management and scripting languages like Bash,
n Python, or Shell for automation tasks.
n
n

n
n
Certifications (Optional):
n
n
- Splunk Certified Admin.
n
n
- AWS Certified Solutions Architect – Associate
n or Professional
n
n

n
n
Required Skills &
n Experience
n
n
• 5–10 years
n experience with Splunk administration and data onboarding (or equivalent
n depth).
n
n
• Strong practical
n knowledge of:
n
n
- CIM normalization,
n tags/eventtypes, datamodel alignment
n
n
- Field extraction
n (regex, JSON/KV extraction), and troubleshooting parsing issues
n
n
- props.conf /
n transforms.conf, sourcetypes, timestamps, line -breaking
n
n
- TA
n
installation/configuration
and deployment patterns across Splunk tiers
n
n
• Experience with
n complex Splunk architectures:
n
n
- Indexer clusters,
n SH/SHC, forwarder management, deployment server
n
n
- Hybrid patterns
n (on -prem + cloud), connectivity, and ingestion strategies
n
n




• Comfortable writing
n and validating SPL for data quality and CIM compliance.
n
n
• Strong log source
n knowledge across common domains:
n
n
- Security: EDR,
n firewall, proxy, IAM/auth, VPN, email security
n
n
- Infrastructure:
n Windows, Linux, network devices, virtualization
n
n
- Cloud: AWS/Azure/GCP
n logging patterns (nice -to -have)
n
n

n
n

n
n
Key Responsibilities
n
n

n
n
Data Onboarding & Lifecycle
n Management
n
n

n
n
• Lead onboarding of new log sources
n end -to -end: requirements gathering, source validation, parsing strategy, TA
n
selection/deployment,
CIM alignment, testing, and release.
n
n
• Partner with Security/IT teams to
n translate use -cases into data requirements, ensuring sources deliver the right
n fidelity, timeliness, and coverage.
n
n
• Manage onboarding at scale using best
n practices for source types, metadata strategy, index & sourcetype
n governance, and naming conventions.
n
n
• Define and enforce data quality
n standards (field completeness, timestamps, event consistency, parsing accuracy,
n duplication control).
n
n

n
n
CIM Normalization & Data Modelling
n
n

n
n
• Normalize data to Splunk Common
n Information Model (CIM) with strong understanding of data models (e.g.,
n Authentication, Network Traffic, Endpoint, Change, etc.).
n
n
• Ensure fields are aligned to CIM
n requirements to support Splunk Enterprise Security (ES) and other CIM -based
n content.
n
n
• Validate normalization using SPL and
n develop reusable onboarding checklists.
n
n

n
n
Field Extraction, Parsing &
n Enrichment
n
n

n
n
• Design and implement robust field
n extractions using:
n
n
- props.conf / transforms.conf,
n REPORT/TRANSFORMS stanzas
n
n
- regex and structured parsing (KV_MODE,
n JSON, XML)
n
n
- ingest -time vs search -time extraction
n strategy
n
n
- sourcetype / timestamp / line breaking
n configuration
n
n
• Implement enrichment and routing using
n event breaking, host/source normalization, lookups, and tagging.
n
n




• Troubleshoot parsing issues (timestamp
n drift, multi -line events, encoding, truncation, duplicate ingestion, broken
n extractions).
n
n

n
n
TA Installation & Configuration
n (Complex / Hybrid)
n
n

n
n
• Install, configure, and maintain
n Splunk Add -ons (TAs) and apps across:
n
n
- Heavy Forwarders / Universal
n Forwarders
n
n
- Indexers / Search Heads / SHC
n
n
- Deployment Server / Cluster Manager
n (where applicable)
n
n
• Maintain version compatibility and
n upgrade strategies for:
n
n
- Splunk Enterprise / Splunk Cloud
n
n
- Add -ons, apps, and content packs
n
n
• Package and deploy TAs using
n deployment pipelines and change management controls.
n
n
• Ensure fields are aligned to CIM
n requirements
n
n

n
n
Hybrid Splunk Architecture Operations
n
n

n
n
• Operate and support Splunk in complex
n environments:
n
n
- On -prem Indexer Cluster, Search Head
n Cluster, Forwarder tiers
n
n
- Splunk Cloud integrations where
n applicable (e.g., Heavy Forwarder, VPN, PrivateLink, data forwarding patterns)
n
n
• Configure and troubleshoot data
n ingestion pipelines:
n
n
- Syslog (UDP/TCP), API -based
n collection, HEC, file monitors, Windows Event Logs, cloud sources
n
n
• Ensure performance and reliability
n across the pipeline, including indexing throughput, parsing overhead, and
n search impact.
n
n

n
n
Monitoring, Troubleshooting & Governance
n
n

n
n
• Monitor ingestion health and pipeline
n performance:
n
n
- Forwarder health, queue saturation,
n parsing/indexing delays, dropped events
n
n
• Maintain governance for indexes,
n sourcetypes, retention, RBAC and data access boundaries (as required).
n
n
• Contribute to operational runbooks,
n SOPs, and documentation; drive continuous improvement in onboarding and
n normalization standards.
n
n

n
n
Preferred / Nice -to -Have
n
n

n
n
• Experience with Splunk Enterprise
n Security (ES) and ES add -ons / CIM compliance expectations.
n
n
• Knowledge of Splunk Ingest Actions /
n Edge Processor (or modern ingestion tools, where applicable).
n
n
• Familiarity with:
n
n
- HEC, API ingestion, message queues
n
n
- ITSI / Observability (bonus)
n
n
• Splunk certifications (preferred):
n
n
- Splunk Core Certified Power User /
n Admin
n
n
- Splunk Enterprise Certified Admin
n
n
- Splunk ES Admin (bonus)
n
n

📌 Splunk Data Administrator (Melbourne)
🏢 XPT Software Australia Pty
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator (melbourne) / melbourne

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator (melbourne) / melbourne