09 Oct
|
XPT Software Australia Pty
|
Melbourne
09 Oct
XPT Software Australia Pty
Melbourne
Role Summary We are seeking a mid to senior SplunkData Administrator to own and continuously improve Splunk data onboarding,normalization, and quality across a complex hybrid Splunk environment (on‐premand cloud).
The ideal candidate is hands -on with CIMalignment, data source onboarding, field extractions(regex/props/transforms/ingest actions), TA deployment, and end -to -endoperational management of Splunk data pipelines.
You will act as the key point of contactfor ensuring log sources are onboarded correctly, parsed and normalizedconsistently, and made usable for security/IT operations, dashboards,correlation searches, and reporting.
Splunk: - Good understanding of Splunkarchitecture and its components (Search Heads, Indexers, Deployers).
- Experience in managing andtroubleshooting Splunk distributed environments (clusters), Splunk upgrade andmigration .
Operating Systems & Cloud Platforms: - Expertise in Linux systems, specificallyRHEL and Amazon Linux.
- Experience with AWS services, includingEC2, S3, IAM, VPC, Subnets, Security Groups and CloudWatch.
DevOps & Automation Tools: - Experience with Jenkins pipelines and CI/CDprocesses, Ansible for configuration management and automation, Terraform for infrastructureprovisioning.
- Ability to write custom Ansible playbooks andTerraform modules for system management and scripting languages like Bash,Python, or Shell for automation tasks.
Certifications (Optional): - Splunk Certified Admin.
- AWS Certified Solutions Architect – Associateor Skilled Required Skills &Experience; • 5–10 yearsexperience with Splunk administration and data onboarding (or equivalentdepth).
• Strong practicalknowledge of: - CIM normalization,tags/eventtypes, datamodel alignment - Field extraction(regex, JSON/KV extraction), and troubleshooting parsing issues - props.conf /transforms.conf, sourcetypes, timestamps, line -breaking - TAinstallation/configuration and deployment patterns across Splunk tiers • Experience withcomplex Splunk architectures: - Indexer clusters,SH/SHC, forwarder management, deployment server - Hybrid patterns(on -prem + cloud), connectivity,
and ingestion strategies • Comfortable writingand validating SPL for data quality and CIM compliance.
• Strong log sourceknowledge across common domains: - Security: EDR,firewall, proxy, IAM/auth, VPN, email security - Infrastructure:Windows, Linux, network devices, virtualization - Cloud: AWS/Azure/GCPlogging patterns (nice -to -have) Key Responsibilities Data Onboarding & LifecycleManagement • Lead onboarding of new log sourcesend -to -end: requirements gathering, source validation, parsing strategy, TAselection/deployment, CIM alignment, testing, and release.
• Partner with Security/IT teams totranslate use -cases into data requirements, ensuring sources deliver the rightfidelity, timeliness, and coverage.
• Manage onboarding at scale using bestpractices for source types, metadata strategy, index & sourcetypegovernance, and naming conventions.
• Define and enforce data qualitystandards (field completeness, timestamps, event consistency, parsing accuracy,duplication control).
CIM Normalization & Data Modelling • Normalize data to Splunk CommonInformation Model (CIM) with strong understanding of data models (e.g.,Authentication, Network Traffic, Endpoint, Change, etc.).
• Ensure fields are aligned to CIMrequirements to support Splunk Enterprise Security (ES) and other CIM -basedcontent.
• Validate normalization using SPL anddevelop reusable onboarding checklists.
Field Extraction, Parsing &Enrichment; • Design and implement robust fieldextractions using: - props.conf / transforms.conf,REPORT/TRANSFORMS stanzas - regex and structured parsing (KV_MODE,JSON, XML) - ingest -time vs search -time extractionstrategy - sourcetype / timestamp / line breakingconfiguration • Implement enrichment and routing usingevent breaking, host/source normalization, lookups, and tagging.
• Troubleshoot parsing issues (timestampdrift, multi -line events, encoding, truncation, duplicate ingestion, brokenextractions).
TA Installation & Configuration(Complex / Hybrid) • Install, configure, and maintainSplunk Add -ons (TAs) and apps across: - Heavy Forwarders / UniversalForwarders - Indexers / Search Heads / SHC - Deployment Server / Cluster Manager(where applicable) • Maintain version compatibility andupgrade strategies for: - Splunk Enterprise / Splunk Cloud - Add -ons, apps, and content packs • Package and deploy TAs usingdeployment pipelines and change management controls.
• Ensure fields are aligned to CIMrequirements Hybrid Splunk Architecture Operations • Operate and support Splunk in complexenvironments: - On -prem Indexer Cluster, Search HeadCluster, Forwarder tiers - Splunk Cloud integrations whereapplicable (e.g., Heavy Forwarder, VPN, PrivateLink, data forwarding patterns) • Configure and troubleshoot dataingestion pipelines: - Syslog (UDP/TCP), API -basedcollection, HEC, file monitors, Windows Event Logs, cloud sources • Ensure performance and reliabilityacross the pipeline, including indexing throughput, parsing overhead, andsearch impact.
Monitoring, Troubleshooting & Governance • Monitor ingestion health and pipelineperformance: - Forwarder health, queue saturation,parsing/indexing delays, dropped events • Maintain governance for indexes,sourcetypes, retention, RBAC and data access boundaries (as required).
• Contribute to operational runbooks,SOPs, and documentation; drive continuous improvement in onboarding andnormalization standards.
Preferred / Nice -to -Have • Experience with Splunk EnterpriseSecurity (ES) and ES add -ons / CIM compliance expectations.
• Knowledge of Splunk Ingest Actions /Edge Processor (or modern ingestion tools, where applicable).
• Familiarity with: - HEC, API ingestion, message queues - ITSI / Observability (bonus) • Splunk certifications (preferred): - Splunk Core Certified Power User /Admin - Splunk Enterprise Certified Admin - Splunk ES Admin (bonus)
📌 Splunk Data Administrator (Melbourne)
🏢 XPT Software Australia Pty
📍 Melbourne