Splunk Administrator - Remote / Telecommute

CYNET SYSTEMS INC.
Eden Prairie, MN, United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Data Analysis Cloud Computing Dynamic Host Configuration Protocol Linux Domain Name System (DNS) Hypertext Transfer Protocols (HTTP) Intrusion Detection Systems Virtual Private Networks (VPN) JSON Log Analysis Simple Mail Transfer Protocols NetFlow
+17 more
Network Monitoring Simple Network Management Protocols Syslog TCP/IP Extensible Markup Language (XML) Network Routers Transport Layer Security File Transfer Protocol (FTP) Load Balancing Data Ingestion Firewalls (Computer Science) SolarWinds (Software) Restful APIs Ddos Splunk Dynatrace Cisco

Requirements

  • 10+ years of overall technology experience.
  • 2 3 years of hands-on Splunk experience, preferably with Splunk Enterprise or Splunk Cloud.
  • 2 3 years of log analysis and SRE experience.
  • Strong knowledge of SPL (Search Processing Language), including commands such as stats, timechart, transaction, eval, rex, lookup, and mv.
  • Experience building interactive dashboards, drilldowns, and scheduled/ad-hoc reports.
  • Solid experience with field extractions using regex, search-time extractions, and lookups.
  • Understanding of indexes, sourcetypes, hosts, and search-time vs. index-time concepts.
  • Familiarity with JSON, XML, CSV, and standard log formats.
  • Basic understanding of Linux/Unix commands for log analysis.
  • Ability to analyze data and present insights in a clear visual format.
  • Strong stakeholder collaboration and communication skills.
  • Documentation discipline for dashboards, reports, and searches.
  • Strong understanding of TCP/IP, UDP, DNS, DHCP, HTTP/HTTPS, SSL/TLS, FTP, and SMTP protocols.
  • Experience onboarding and analyzing logs from routers, switches, firewalls, load balancers, IDS/IPS, and VPN devices.
  • Configured Syslog, SNMP, NetFlow, sFlow, and REST API data ingestion into Splunk.
  • Troubleshooting log forwarding issues between Universal Forwarders, Heavy Forwarders, Indexers, and Search Heads.
  • Built SPL searches and correlation rules for detecting network anomalies, DDoS attacks, unauthorized access, port scans, and suspicious traffic patterns.
  • Integrated Splunk with network monitoring tools such as SolarWinds, Cisco Prime, ThousandEyes, and Dynatrace.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

2:01 min

Executing remote data exploration and model training

Mingshen Sun Mingshen Sun · WWC 2024

3:11 min

Surviving sudden scale events and malicious traffic

Justin Kitagawa · Coffee With Developers

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all