Splunk Administrator
Role details
Job location
Tech stack
Job description
We are seeking a Splunk Administrator to support the day-to-day administration, maintenance, and optimization of an enterprise Splunk environment. This role will focus on platform support, data onboarding, monitoring, troubleshooting, and user support while ensuring the Splunk environment remains stable, secure, and highly available., Splunk Administration
- Administer and maintain Splunk Enterprise and/or Splunk Cloud environments.
- Monitor platform health, system performance, and indexing operations.
- Configure and support forwarders, indexes, search heads, and data inputs.
- Manage user accounts, roles, permissions, and authentication integrations.
- Perform routine maintenance, upgrades, patching, and system updates.
- Assist with backup, recovery, and business continuity processes.
Data Onboarding & Monitoring
- Support onboarding and configuration of new data sources including servers, applications, network devices, and security tools.
- Monitor and troubleshoot data ingestion, parsing, and indexing issues.
- Maintain data retention policies and index management.
- Verify data quality and ensure reliable log collection.
Dashboard & Reporting Support
- Create and maintain dashboards, alerts, reports, and visualizations.
- Develop and modify Splunk searches using SPL (Search Processing Language).
- Support operational and security monitoring requirements.
- Assist users with report creation and search optimization.
Troubleshooting & Support
- Investigate and resolve platform performance issues.
- Troubleshoot search delays, data latency, and connectivity problems.
- Work with infrastructure, networking, and security teams to resolve system issues.
- Document configurations, procedures, and support processes., Splunk
- Splunk Enterprise
- Splunk Cloud
- Search Processing Language (SPL)
- Data Onboarding
- Dashboard Development
- Alert Configuration
- Report Development
- User Administration
Infrastructure
- Linux/Unix Administration
- Windows Server
- TCP/IP Networking
- DNS
- Firewalls
- Active Directory
Security & Monitoring
- SIEM Fundamentals
- Log Management
- Security Monitoring
- Basic understanding of NIST and cybersecurity best practices
Requirements
The ideal candidate will have hands-on experience administering Splunk, supporting data ingestion, building dashboards, and troubleshooting issues across infrastructure, application, and security monitoring use cases., * 2-5 years of Splunk administration experience.
- Experience supporting Splunk Enterprise or Splunk Cloud environments.
- Knowledge of:
- Splunk Forwarders
- Index Management
- Search Heads
- Data Inputs and Parsing
- SPL Queries
- Experience onboarding and troubleshooting log sources.
- Understanding of monitoring, logging, and observability concepts.
- Strong troubleshooting and analytical skills., * Experience integrating Cisco technologies with Splunk.
- Splunk Core Certified User or Splunk Core Certified Power User certification.
- Experience with scripting using PowerShell, Python, or Bash.
- Exposure to cloud environments such as AWS or Azure.
- Experience supporting enterprise monitoring or security operations teams.