07 Oct
|
XPT Software Australia Pty
|
Melbourne
07 Oct
XPT Software Australia Pty
Melbourne
Job Description
Role Summary
n
n
We are seeking a mid to senior Splunk
n Data Administrator to own and continuously improve Splunk data onboarding,
n normalization, and quality across a complex hybrid Splunk workplace (on‐prem
n and cloud).
n
n
The ideal candidate is hands -on with CIM
n alignment, data source onboarding, field extractions
n
(regex/props/transforms/ingest
actions), TA deployment, and end -to -end
n operational management of Splunk data pipelines.
n
n
n
n
You will act as the key point of contact
n for ensuring log sources are onboarded correctly, parsed and normalized
n consistently, and made usable for security/IT operations, dashboards,
n correlation searches, and reporting.
n
n
n
n
n
n
Splunk:
n
n
- Good understanding of Splunk
n architecture and its components (Search Heads, Indexers, Deployers).
n
n
- Experience in managing and
n troubleshooting Splunk distributed environments (clusters), Splunk upgrade and
n migration .
n
n
n
n
Operating Systems & Cloud Platforms:
n
n
- Expertise in Linux systems, specifically
n RHEL and Amazon Linux.
n
n
- Experience with AWS services, including
n EC2, S3, IAM, VPC, Subnets, Security Groups and CloudWatch.
n
n
n
n
DevOps & Automation Tools:
n
n
- Experience with Jenkins pipelines and CI/CD
n processes, Ansible for configuration management and automation, Terraform for infrastructure
n provisioning.
n
n
- Ability to write custom Ansible playbooks and
n Terraform modules for system management and scripting languages like Bash,
n Python, or Shell for automation tasks.
n
n
n
n
Certifications (Optional):
n
n
- Splunk Certified Admin.
n
n
- AWS Certified Solutions Architect – Associate
n or Professional
n
n
n
n
Required Skills &
n Experience
n
n
• 5–10 years
n experience with Splunk administration and data onboarding (or equivalent
n depth).
n
n
• Strong practical
n knowledge of:
n
n
- CIM normalization,
n tags/eventtypes, datamodel alignment
n
n
- Field extraction
n (regex, JSON/KV extraction), and troubleshooting parsing issues
n
n
- props.conf /
n transforms.conf, sourcetypes, timestamps, line -breaking
n
n
- TA
n
installation/configuration
and deployment patterns across Splunk tiers
n
n
• Experience with
n complex Splunk architectures:
n
n
- Indexer clusters,
n SH/SHC, forwarder management, deployment server
n
n
- Hybrid patterns
n (on -prem + cloud), connectivity, and ingestion strategies
n
n
• Comfortable writing
n and validating SPL for data quality and CIM compliance.
n
n
• Strong log source
n knowledge across common domains:
n
n
- Security: EDR,
n firewall, proxy, IAM/auth, VPN, email security
n
n
- Infrastructure:
n Windows, Linux, network devices, virtualization
n
n
- Cloud: AWS/Azure/GCP
n logging patterns (nice -to -have)
n
n
n
n
n
n
Key Responsibilities
n
n
n
n
Data Onboarding & Lifecycle
n Management
n
n
n
n
• Lead onboarding of new log sources
n end -to -end: requirements gathering, source validation, parsing strategy, TA
n
selection/deployment,
CIM alignment, testing, and release.
n
n
• Partner with Security/IT teams to
n translate use -cases into data requirements, ensuring sources deliver the right
n fidelity, timeliness, and coverage.
n
n
• Manage onboarding at scale using best
n practices for source types, metadata strategy, index & sourcetype
n governance, and naming conventions.
n
n
• Define and enforce data quality
n standards (field completeness, timestamps, event consistency, parsing accuracy,
n duplication control).
n
n
n
n
CIM Normalization & Data Modelling
n
n
n
n
• Normalize data to Splunk Common
n Information Model (CIM) with strong understanding of data models (e.g.,
n Authentication, Network Traffic, Endpoint, Change, etc.).
n
n
• Ensure fields are aligned to CIM
n requirements to support Splunk Enterprise Security (ES) and other CIM -based
n content.
n
n
• Validate normalization using SPL and
n develop reusable onboarding checklists.
n
n
n
n
Field Extraction, Parsing &
n Enrichment
n
n
n
n
• Design and implement robust field
n extractions using:
n
n
- props.conf / transforms.conf,
n REPORT/TRANSFORMS stanzas
n
n
- regex and structured parsing (KV_MODE,
n JSON, XML)
n
n
- ingest -time vs search -time extraction
n strategy
n
n
- sourcetype / timestamp / line breaking
n configuration
n
n
• Implement enrichment and routing using
n event breaking, host/source normalization, lookups, and tagging.
n
n
• Troubleshoot parsing issues (timestamp
n drift, multi -line events, encoding, truncation, duplicate ingestion, broken
n extractions).
n
n
n
n
TA Installation & Configuration
n (Complex / Hybrid)
n
n
n
n
• Install, configure, and maintain
n Splunk Add -ons (TAs) and apps across:
n
n
- Heavy Forwarders / Universal
n Forwarders
n
n
- Indexers / Search Heads / SHC
n
n
- Deployment Server / Cluster Manager
n (where applicable)
n
n
• Maintain version compatibility and
n upgrade strategies for:
n
n
- Splunk Enterprise / Splunk Cloud
n
n
- Add -ons, apps, and content packs
n
n
• Package and deploy TAs using
n deployment pipelines and change management controls.
n
n
• Ensure fields are aligned to CIM
n requirements
n
n
n
n
Hybrid Splunk Architecture Operations
n
n
n
n
• Operate and support Splunk in complex
n environments:
n
n
- On -prem Indexer Cluster, Search Head
n Cluster, Forwarder tiers
n
n
- Splunk Cloud integrations where
n applicable (e.g., Heavy Forwarder, VPN, PrivateLink, data forwarding patterns)
n
n
• Configure and troubleshoot data
n ingestion pipelines:
n
n
- Syslog (UDP/TCP), API -based
n collection, HEC, file monitors, Windows Event Logs, cloud sources
n
n
• Ensure performance and reliability
n across the pipeline, including indexing throughput, parsing overhead, and
n search impact.
n
n
n
n
Monitoring, Troubleshooting & Governance
n
n
n
n
• Monitor ingestion health and pipeline
n performance:
n
n
- Forwarder health, queue saturation,
n parsing/indexing delays, dropped events
n
n
• Maintain governance for indexes,
n sourcetypes, retention, RBAC and data access boundaries (as required).
n
n
• Contribute to operational runbooks,
n SOPs, and documentation; drive continuous improvement in onboarding and
n normalization standards.
n
n
n
n
Preferred / Nice -to -Have
n
n
n
n
• Experience with Splunk Enterprise
n Security (ES) and ES add -ons / CIM compliance expectations.
n
n
• Knowledge of Splunk Ingest Actions /
n Edge Processor (or modern ingestion tools, where applicable).
n
n
• Familiarity with:
n
n
- HEC, API ingestion, message queues
n
n
- ITSI / Observability (bonus)
n
n
• Splunk certifications (preferred):
n
n
- Splunk Core Certified Power User /
n Admin
n
n
- Splunk Enterprise Certified Admin
n
n
- Splunk ES Admin (bonus)
n
n
📌 Splunk Data Administrator (Melbourne)
🏢 XPT Software Australia Pty
📍 Melbourne