Splunk Administrator

BETA SEARCH COM LLC
New York, NY, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Microsoft Azure Cloud Computing Cyber Security Data Normalization Log Analysis Logstash Security Assertion Markup Language (SAML) Data Streaming Data Logging Okta Data Ingestion
+3 more
Information Technology Apache Kafka Splunk

Job description

The Splunk Administrator is responsible for supporting and maintaining the company Splunk Cloud environment and associated log ingestion components. This role ensures reliable data collection across diverse sources, monitors platform health and capacity, and performs ongoing administration, updates, and configuration to support security operations and analytics. ROLE RESPONSIBILITIES Monitor log ingestion volumes and platform health using custom searches and Splunkbase tools.Ensure reliable log delivery and troubleshoot ingestion interruptions across supported sources.Administer intermediate log collection components, including Logstash, syslog, Heavy Forwarders, and related services.Manage Splunk application configurations on Universal Forwarders using the Splunk Deployment Server.Perform Universal Forwarder upgrades and maintenance to address security, stability, and version requirements.Manage and update Splunk applications within the Splunk Cloud environment.Collaborate with security and infrastructure teams to support onboarding of new log sources.Document configurations, procedures, and troubleshooting steps for operational use.

Requirements

Do you have experience in Windows?, Do you have a Bachelor’s degree?, Hands-on experience administering: 3-5 years of hands-on experience administering Splunk in an enterprise environment.Splunk Cloud and on-prem Splunk infrastructure, including Heavy Forwarders, Deployment Server, and Universal Forwarders.HTTP Event Collector (HEC).Common Splunk Technology Add-ons (TAs), including Azure, Okta, and other cloud services.Splunk data models and data normalization practices.Splunk features such as alert actions, SAML-based authentication, KV store, and lookups.Splunk role-based access controls and permission models.Data management features including DDAS and reindexing processes. Familiarity with: Azure Event Hubs, Kafka, Log Analytics Workspaces, and cloud-based logging pipelines.Windows Event Collection (WEC) and Windows Event Forwarding (WEF)., Ability to create clear, concise technical documentation for both technical and non-technical audiences.Strong analytical and troubleshooting skills with the ability to work independently.Effective time and priority management in a multi-task operational environment.Strong written and verbal communication skills., Bachelor’s degree in Information Technology, Computer Science, or a related field, or equivalent professional experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:31 min

Exploring the core components of the ELK stack

Derek Binkley · LIVE

1:21 min

Reviewing deployment and hosting options for Elasticsearch clusters

Derek Binkley · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:44 min

Career transition into cloud native and data management

Michael Cade · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all