XPT Software Australia Pty Ltd Logo

XPT Software Australia Pty Ltd

Splunk Data Administrator

Posted An Hour Ago
Be an Early Applicant
In-Office
Melbourne, Victoria, AUS
Senior level
In-Office
Melbourne, Victoria, AUS
Senior level
Owns Splunk data onboarding, normalization, parsing, field extraction, TA deployment, and data quality across hybrid on-premises and cloud environments. Configures and troubleshoots ingestion pipelines, CIM alignment, indexes, sourcetypes, timestamps, and data models. Supports Splunk Enterprise Security, dashboards, correlation searches, and reporting while monitoring pipeline health, performance, governance, and reliability. Partners with Security and IT teams to define requirements, validate log sources, maintain deployment processes, and document operational standards.
The summary above was generated by AI

Splunk Data Administrator (Mid–Senior) – CIM / Data Onboarding / Hybrid Architecture

 

Role Summary

We are seeking a mid to senior Splunk Data Administrator to own and continuously improve Splunk data onboarding, normalization, and quality across a complex hybrid Splunk environment (on‑prem and cloud).

The ideal candidate is hands-on with CIM alignment, data source onboarding, field extractions (regex/props/transforms/ingest actions), TA deployment, and end-to-end operational management of Splunk data pipelines.

 You will act as the key point of contact for ensuring log sources are onboarded correctly, parsed and normalized consistently, and made usable for security/IT operations, dashboards, correlation searches, and reporting.

Key Responsibilities

 Data Onboarding & Lifecycle Management

• Lead onboarding of new log sources end-to-end: requirements gathering, source validation, parsing strategy, TA selection/deployment, CIM alignment, testing, and release.

• Partner with Security/IT teams to translate use-cases into data requirements, ensuring sources deliver the right fidelity, timeliness, and coverage.

• Manage onboarding at scale using best practices for source types, metadata strategy, index & sourcetype governance, and naming conventions.

• Define and enforce data quality standards (field completeness, timestamps, event consistency, parsing accuracy, duplication control).

 CIM Normalization & Data Modelling

• Normalize data to Splunk Common Information Model (CIM) with strong understanding of data models (e.g., Authentication, Network Traffic, Endpoint, Change, etc.).

• Ensure fields are aligned to CIM requirements to support Splunk Enterprise Security (ES) and other CIM-based content.

• Validate normalization using SPL and develop reusable onboarding checklists.

 Field Extraction, Parsing & Enrichment

• Design and implement robust field extractions using:

- props.conf / transforms.conf, REPORT/TRANSFORMS stanzas

- regex and structured parsing (KV_MODE, JSON, XML)

- ingest-time vs search-time extraction strategy

- sourcetype / timestamp / line breaking configuration

• Implement enrichment and routing using event breaking, host/source normalization, lookups, and tagging.

• Troubleshoot parsing issues (timestamp drift, multi-line events, encoding, truncation, duplicate ingestion, broken extractions).

 TA Installation & Configuration (Complex / Hybrid)

• Install, configure, and maintain Splunk Add-ons (TAs) and apps across:

- Heavy Forwarders / Universal Forwarders

- Indexers / Search Heads / SHC

- Deployment Server / Cluster Manager (where applicable)

• Maintain version compatibility and upgrade strategies for:

- Splunk Enterprise / Splunk Cloud

- Add-ons, apps, and content packs

• Package and deploy TAs using deployment pipelines and change management controls.

• Ensure fields are aligned to CIM requirements

 Hybrid Splunk Architecture Operations

• Operate and support Splunk in complex environments:

- On-prem Indexer Cluster, Search Head Cluster, Forwarder tiers

- Splunk Cloud integrations where applicable (e.g., Heavy Forwarder, VPN, PrivateLink, data forwarding patterns)

• Configure and troubleshoot data ingestion pipelines:

- Syslog (UDP/TCP), API-based collection, HEC, file monitors, Windows Event Logs, cloud sources

• Ensure performance and reliability across the pipeline, including indexing throughput, parsing overhead, and search impact.

 Monitoring, Troubleshooting & Governance

• Monitor ingestion health and pipeline performance:

- Forwarder health, queue saturation, parsing/indexing delays, dropped events

• Maintain governance for indexes, sourcetypes, retention, RBAC and data access boundaries (as required).

• Contribute to operational runbooks, SOPs, and documentation; drive continuous improvement in onboarding and normalization standards.

 Required Skills & Experience (Mid–Senior)

• 5–10 years experience with Splunk administration and data onboarding (or equivalent depth).

• Strong practical knowledge of:

- CIM normalization, tags/eventtypes, datamodel alignment

- Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues

- props.conf / transforms.conf, sourcetypes, timestamps, line-breaking

- TA installation/configuration and deployment patterns across Splunk tiers

• Experience with complex Splunk architectures:

- Indexer clusters, SH/SHC, forwarder management, deployment server

- Hybrid patterns (on-prem + cloud), connectivity, and ingestion strategies

• Comfortable writing and validating SPL for data quality and CIM compliance.

• Strong log source knowledge across common domains:

- Security: EDR, firewall, proxy, IAM/auth, VPN, email security

- Infrastructure: Windows, Linux, network devices, virtualization

- Cloud: AWS/Azure/GCP logging patterns (nice-to-have)

 Preferred / Nice-to-Have

• Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM compliance expectations.

• Knowledge of Splunk Ingest Actions / Edge Processor (or modern ingestion tools, where applicable).

• Familiarity with:

- HEC, API ingestion, message queues

- ITSI / Observability (bonus)

• Splunk certifications (preferred):

- Splunk Core Certified Power User / Admin

- Splunk Enterprise Certified Admin

- Splunk ES Admin (bonus)



Similar Jobs

Yesterday
Remote or Hybrid
5 Locations
Mid level
Mid level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Provides technical support for CrowdStrike customers globally, with a focus on Korean-speaking enterprise customers in the Asia-Pacific region. Responsibilities include troubleshooting application and operating-system issues, identifying root causes, resolving escalations, collaborating with engineering and product teams, creating knowledge articles, and supporting customers across scheduled shifts and holidays. The role requires strong bilingual communication, technical debugging expertise, customer focus, and familiarity with cybersecurity, cloud, identity, SIEM, or related technologies.
Top Skills: Active DirectoryAi TechnologiesCassandraContainersCrowdstrike FalconDockerElasticsearchHttpsJSONKafkaKerberosKubernetesLdapLinuxmacOSMultifactor AuthenticationNtlmPcapRegular ExpressionsRest ApisSaaSSAMLSplunkTcp/IpWindowsWiresharkZero Trust
Yesterday
In-Office
Junior
Junior
Food • Retail • Agriculture • Manufacturing
Provides hands-on, site-based HR support at McCain’s Ballarat plant across employee relations, labour relations, recruitment, onboarding, employee lifecycle activities, leave administration, engagement, wellbeing, retention, and HR systems adoption. Partners with leaders, employees, Talent Acquisition, HR Business Partners, and service delivery teams while supporting compliance, employee experience, and culture initiatives.
Top Skills: Hr Self-Service ToolsHr Systems
Yesterday
Remote or Hybrid
Melbourne, Victoria, AUS
Entry level
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Support alliance managers, solution providers, and managed service partners across Australia by delivering cybersecurity enablement, technical training, demonstrations, proof-of-concept guidance, accreditation support, and opportunity assistance. Build trusted partner relationships, promote CrowdStrike’s cloud-native security platform, improve partner technical independence, support joint sales initiatives, and identify professional services opportunities. The role requires security architecture knowledge, strong communication, consulting or sales engineering capability, AI technology experience, and travel to partner locations.
Top Skills: Ai TechnologiesAnti-VirusAPIsAWSAzureBashCehCisspCloud Security ArchitectureComputer ForensicsCrowdstrikeData ProtectionEndpoint SecurityGCPIdentity ProtectionIncident ResponseMdr/XdrOscpPowershellPythonSansSIEMZero-Trust

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account