Splunk Data Administrator

XPT Software

City of Melbourne

Hybrid

AUD 120,000 - 180,000

Full time

48 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

XPT Software is seeking a mid to senior Splunk Data Administrator to own and continuously improve Splunk data onboarding, normalization, and quality across a complex hybrid Splunk environment (on‑prem and cloud). The ideal candidate will be hands‑on with CIM alignment, data source onboarding, field extractions, TA deployment, and end‑to‑end operational management of Splunk data pipelines.

You will ensure log sources are onboarded correctly and usable for security, IT operations, dashboards and

Qualifications

  • 5–10 years experience with Splunk administration and data onboarding.
  • Strong knowledge of field extraction (regex/JSON/KV) and parsing issues.
  • Proficient with props.conf, transforms.conf, sourcetype handling and timestamps.
  • Experience deploying TAs and patterns across Splunk tiers.
  • Familiarity with CIM alignment to support ES and CIM-based content.
  • Comfortable working in hybrid on‑prem and cloud environments.

Responsibilities

  • Own onboarding of new log sources end‑to‑end: requirements, validation, parsing strategy, CIM alignment and release.
  • Collaborate with Security/IT to ensure data fidelity, timeliness and coverage.
  • Govern data onboarding with governance for indices, sourcetypes, metadata and naming conventions.
  • Design robust field extractions using regex and structured parsing (KV, JSON, XML).
  • Implement enrichment and routing with lookups, tagging and host/source normalization.
  • Maintain and upgrade Splunk Add‑ons (TAs) and apps across indexers, SHC, deployment server.

Skills

Splunk administration
Data onboarding
Field extraction
SPL queries
CIM alignment
TA deployment
Hybrid environment

Tools

Deployment Server
Splunk Cloud
Splunk Add-ons (TAs)

Job description

We are seeking a mid to senior Splunk Data Administrator to own and continuously improve Splunk data onboarding, normalization, and quality across a complex hybrid Splunk environment (on‑prem and cloud).

The ideal candidate is hands‑on with CIM alignment, data source onboarding, field extractions (regex/props/transforms/ingest actions), TA deployment, and end‑to‑end operational management of Splunk data pipelines.

You will act as the key point of contact for ensuring log sources are onboarded correctly, parsed and normalized consistently, and made usable for security/IT operations, dashboards, correlation searches, and reporting.

Key Responsibilities
Data Onboarding & Lifecycle Management
  • Lead onboarding of new log sources end‑to‑end: requirements gathering, source validation, parsing strategy, TA selection/deployment, CIM alignment, testing, and release.
  • Partner with Security/IT teams to translate use‑cases into data requirements, ensuring sources deliver the right fidelity, timeliness, and coverage.
  • Manage onboarding at scale using best practices for source types, metadata strategy, index & sourcetype governance, and naming conventions.
  • Define and enforce data quality standards (field completeness, timestamps, event consistency, parsing accuracy, duplication control).
  • Normalize data to Splunk Common Information Model (CIM) with strong understanding of data models (e.g., Authentication, Network Traffic, Endpoint, Change, etc.).
  • Ensure fields are aligned to CIM requirements to support Splunk Enterprise Security (ES) and other CIM‑based content.
  • Validate normalization using SPL and develop reusable onboarding checklists.
  • Design and implement robust field extractions using:
    • regex and structured parsing (KV_MODE, JSON, XML)
    • sourcetype / timestamp / line breaking configuration
  • Implement enrichment and routing using event breaking, host/source normalization, lookups, and tagging.
  • Install, configure, and maintain Splunk Add‑ons (TAs) and apps across:
    • Indexers / Search Heads / SHC
    • Deployment Server / Cluster Manager (where applicable)
  • Maintain version compatibility and upgrade strategies for:
    • Splunk Enterprise / Splunk Cloud
    • Add‑ons, apps, and content packs
  • Package and deploy TAs using deployment pipelines and change management controls.
  • Ensure fields are aligned to CIM requirements
Hybrid Splunk Architecture Operations
  • Operate and support Splunk in complex environments:
    • On‑prem Indexer Cluster, Search Head Cluster, Forwarder tiers
    • Splunk Cloud integrations where applicable (e.g., Heavy Forwarder, VPN, PrivateLink, data forwarding patterns)
  • Configure and troubleshoot data ingestion pipelines:
    • Syslog (UDP/TCP), API‑based collection, HEC, file monitors, Windows Event Logs, cloud sources
  • Ensure performance and reliability across the pipeline, including indexing throughput, parsing overhead, and search impact.
Monitoring, Troubleshooting & Governance
  • Monitor ingestion health and pipeline performance:
  • Maintain governance for indexes, sourcetypes, retention, RBAC and data access boundaries (as required).
  • Contribute to operational runbooks, SOPs, and documentation; drive continuous improvement in onboarding and normalization standards.
Required Skills & Experience (Mid–Senior)
  • 5–10 years experience with Splunk administration and data onboarding (or equivalent depth).
  • Strong practical knowledge of:
  • Field extraction (regex, JSON/KV extraction), and troubleshooting parsing issues
  • props.conf / transforms.conf, sourcetypes, timestamps, line‑breaking
  • TA installation/configuration and deployment patterns across Splunk tiers
  • Experience with complex Splunk architectures:
  • Indexer clusters, SH/SHC, forwarder management, deployment server
  • Hybrid patterns (on‑prem + cloud), connectivity, and ingestion strategies
  • Comfortable writing and validating SPL for data quality and CIM compliance.
  • Cloud: AWS/Azure/GCP logging patterns (nice‑to‑have)
Preferred / Nice-to-Have
  • Experience with Splunk Enterprise Security (ES) and ES add‑ons / CIM compliance expectations.
  • Knowledge of Splunk Ingest Actions / Edge Processor (or modern ingestion tools, where applicable).
  • Familiarity with:
  • ITSI / Observability (bonus)
  • Splunk Core Certified Power User / Admin
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Splunk Data Administrator
Splunk Data Administrator

XPT Software Australia • City of Melbourne

Hybrid
AUD 120,000 - 150,000
Splunk Data Administrator
Splunk Data Administrator

XPT Software Australia Pty Ltd • City of Melbourne

On-site
AUD 120,000 - 180,000
Senior Splunk Data Onboarding & CIM Lead
Senior Splunk Data Onboarding & CIM Lead

XPT Software • City of Melbourne

Hybrid
AUD 120,000 - 180,000
Senior Splunk Data Administrator – CIM & Onboarding Expert
Senior Splunk Data Administrator – CIM & Onboarding Expert

XPT Software Australia Pty Ltd • City of Melbourne

On-site
AUD 120,000 - 180,000
Splunk Platform Engineer
Splunk Platform Engineer

XPT Software Australia • City of Melbourne

On-site
AUD 140,000 - 180,000
Splunk Platform Engineer
Splunk Platform Engineer

XPT Software • City of Melbourne

On-site
AUD 120,000 - 170,000
Data Administrator
Data Administrator

ITbility • City of Melbourne

On-site
AUD 120,000 - 170,000
Splunk Platform Engineer
Splunk Platform Engineer

XPT Software Australia Pty Ltd • City of Melbourne

On-site
AUD 110,000 - 165,000
Splunk Platform Engineer
Splunk Platform Engineer

XPT Software • Sydney

On-site
AUD 140,000 - 190,000
Senior Splunk Data Admin — Melbourne
Senior Splunk Data Admin — Melbourne

ITbility • City of Melbourne

On-site
AUD 120,000 - 170,000