Splunk Data Administrator (Melbourne)

Splunk Data Administrator (Melbourne)

09 Oct
|
XPT Software Australia Pty
|
Melbourne

09 Oct

XPT Software Australia Pty

Melbourne

Role Summary We are seeking a mid to senior SplunkData Administrator to own and continuously improve Splunk data onboarding,normalization, and quality across a complex hybrid Splunk environment (on‐premand cloud).
The ideal candidate is hands -on with CIMalignment, data source onboarding, field extractions(regex/props/transforms/ingest actions), TA deployment, and end -to -endoperational management of Splunk data pipelines.
You will act as the key point of contactfor ensuring log sources are onboarded correctly, parsed and normalizedconsistently, and made usable for security/IT operations, dashboards,correlation searches, and reporting.
Splunk: - Good understanding of Splunkarchitecture and its components (Search Heads, Indexers, Deployers).
- Experience in managing andtroubleshooting Splunk distributed environments (clusters), Splunk upgrade andmigration .
Operating Systems & Cloud Platforms: - Expertise in Linux systems, specificallyRHEL and Amazon Linux.
- Experience with AWS services, includingEC2, S3, IAM, VPC, Subnets, Security Groups and CloudWatch.
DevOps & Automation Tools: - Experience with Jenkins pipelines and CI/CDprocesses, Ansible for configuration management and automation, Terraform for infrastructureprovisioning.
- Ability to write custom Ansible playbooks andTerraform modules for system management and scripting languages like Bash,Python, or Shell for automation tasks.
Certifications (Optional): - Splunk Certified Admin.
- AWS Certified Solutions Architect – Associateor Skilled Required Skills &Experience; • 5–10 yearsexperience with Splunk administration and data onboarding (or equivalentdepth).
• Strong practicalknowledge of: - CIM normalization,tags/eventtypes, datamodel alignment - Field extraction(regex, JSON/KV extraction), and troubleshooting parsing issues - props.conf /transforms.conf, sourcetypes, timestamps, line -breaking - TAinstallation/configuration and deployment patterns across Splunk tiers • Experience withcomplex Splunk architectures: - Indexer clusters,SH/SHC, forwarder management, deployment server - Hybrid patterns(on -prem + cloud), connectivity,



and ingestion strategies • Comfortable writingand validating SPL for data quality and CIM compliance.
• Strong log sourceknowledge across common domains: - Security: EDR,firewall, proxy, IAM/auth, VPN, email security - Infrastructure:Windows, Linux, network devices, virtualization - Cloud: AWS/Azure/GCPlogging patterns (nice -to -have) Key Responsibilities Data Onboarding & LifecycleManagement • Lead onboarding of new log sourcesend -to -end: requirements gathering, source validation, parsing strategy, TAselection/deployment, CIM alignment, testing, and release.
• Partner with Security/IT teams totranslate use -cases into data requirements, ensuring sources deliver the rightfidelity, timeliness, and coverage.
• Manage onboarding at scale using bestpractices for source types, metadata strategy, index & sourcetypegovernance, and naming conventions.
• Define and enforce data qualitystandards (field completeness, timestamps, event consistency, parsing accuracy,duplication control).
CIM Normalization & Data Modelling • Normalize data to Splunk CommonInformation Model (CIM) with strong understanding of data models (e.g.,Authentication, Network Traffic, Endpoint, Change, etc.).
• Ensure fields are aligned to CIMrequirements to support Splunk Enterprise Security (ES) and other CIM -basedcontent.
• Validate normalization using SPL anddevelop reusable onboarding checklists.
Field Extraction, Parsing &Enrichment; • Design and implement robust fieldextractions using: - props.conf / transforms.conf,REPORT/TRANSFORMS stanzas - regex and structured parsing (KV_MODE,JSON, XML) - ingest -time vs search -time extractionstrategy - sourcetype / timestamp / line breakingconfiguration • Implement enrichment and routing usingevent breaking, host/source normalization, lookups, and tagging.




• Troubleshoot parsing issues (timestampdrift, multi -line events, encoding, truncation, duplicate ingestion, brokenextractions).
TA Installation & Configuration(Complex / Hybrid) • Install, configure, and maintainSplunk Add -ons (TAs) and apps across: - Heavy Forwarders / UniversalForwarders - Indexers / Search Heads / SHC - Deployment Server / Cluster Manager(where applicable) • Maintain version compatibility andupgrade strategies for: - Splunk Enterprise / Splunk Cloud - Add -ons, apps, and content packs • Package and deploy TAs usingdeployment pipelines and change management controls.
• Ensure fields are aligned to CIMrequirements Hybrid Splunk Architecture Operations • Operate and support Splunk in complexenvironments: - On -prem Indexer Cluster, Search HeadCluster, Forwarder tiers - Splunk Cloud integrations whereapplicable (e.g., Heavy Forwarder, VPN, PrivateLink, data forwarding patterns) • Configure and troubleshoot dataingestion pipelines: - Syslog (UDP/TCP), API -basedcollection, HEC, file monitors, Windows Event Logs, cloud sources • Ensure performance and reliabilityacross the pipeline, including indexing throughput, parsing overhead, andsearch impact.
Monitoring, Troubleshooting & Governance • Monitor ingestion health and pipelineperformance: - Forwarder health, queue saturation,parsing/indexing delays, dropped events • Maintain governance for indexes,sourcetypes, retention, RBAC and data access boundaries (as required).
• Contribute to operational runbooks,SOPs, and documentation; drive continuous improvement in onboarding andnormalization standards.
Preferred / Nice -to -Have • Experience with Splunk EnterpriseSecurity (ES) and ES add -ons / CIM compliance expectations.
• Knowledge of Splunk Ingest Actions /Edge Processor (or modern ingestion tools, where applicable).
• Familiarity with: - HEC, API ingestion, message queues - ITSI / Observability (bonus) • Splunk certifications (preferred): - Splunk Core Certified Power User /Admin - Splunk Enterprise Certified Admin - Splunk ES Admin (bonus)

📌 Splunk Data Administrator (Melbourne)
🏢 XPT Software Australia Pty
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator (melbourne) / melbourne

Subscribe to this job alert:

Get the latest job offers by email for: splunk data administrator (melbourne) / melbourne