Splunk Data Administrator

XPT Software Australia Pty Ltd

City of Melbourne

On-site

AUD 120,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

XPT Software Australia Pty Ltd in Melbourne, Australia, seeks a mid–senior Splunk Data Administrator to own and continuously improve Splunk data onboarding, normalization, and quality across a hybrid on‑prem and cloud environment.

You will lead CIM alignment, data source onboarding, and field extractions, while coordinating with Security/IT teams to ensure correct log source onboarding and production readiness. The role emphasizes end-to-end data pipelines and governance.

Qualifications

  • 5–10 years of Splunk administration and data onboarding experience.
  • Proficient in field extraction, props.conf/transforms.conf, and CIM alignment.
  • Experience with complex Splunk architectures (Indexer clusters, SH/SHC, forwarders).

Responsibilities

  • Lead end-to-end onboarding of new log sources and CIM alignment.
  • Configure and maintain CIM-compliant data pipelines and field extractions.
  • Operate Splunk in hybrid on-prem and cloud environments.
  • Monitor ingestion health and governance for indices, retention, and RBAC.

Skills

Splunk administration
Data onboarding
Field extraction
SPL
Cloud logging
Troubleshooting

Tools

TA deployment
Deployment Server
SHC
Sourcetypes

Job description

XPT Software Australia Pty Ltd | Contract

Splunk Data Administrator

Melbourne, Australia | Posted on 09/23/2026

  • XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
  • XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
  • We have 120+technocrats in Australia working at our clientlocations.
  • XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
  • We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
Job Description

RoleSummary

We areseeking a mid to senior Splunk Data Administrator to own and continuouslyimprove Splunk data onboarding, normalization, and quality across a complexhybrid Splunk environment (on‑prem and cloud).

The idealcandidate is hands-on with CIM alignment, data source onboarding, fieldextractions (regex/props/transforms/ingest actions), TA deployment, andend-to-end operational management of Splunk data pipelines.

You willact as the key point of contact for ensuring log sources are onboardedcorrectly, parsed and normalized consistently, and made usable for security/IToperations, dashboards, correlation searches, and reporting.

Key Responsibilities
DataOnboarding & Lifecycle Management
  • Leadonboarding of new log sources end-to-end: requirements gathering, sourcevalidation, parsing strategy, TA selection/deployment, CIM alignment, testing,and release.
  • Partnerwith Security/IT teams to translate use-cases into data requirements, ensuringsources deliver the right fidelity, timeliness, and coverage.
  • Manageonboarding at scale using best practices for source types, metadata strategy,index & sourcetype governance, and naming conventions.
  • Defineand enforce data quality standards (field completeness, timestamps, eventconsistency, parsing accuracy, duplication control).
  • Normalizedata to Splunk Common Information Model (CIM) with strong understanding of datamodels (e.g., Authentication, Network Traffic, Endpoint, Change, etc.).
  • Ensurefields are aligned to CIM requirements to support Splunk Enterprise Security(ES) and other CIM-based content.
  • Validatenormalization using SPL and develop reusable onboarding checklists.
  • Designand implement robust field extractions using:
    • regex andstructured parsing (KV_MODE, JSON, XML)
    • ingest-time vs search-time extraction strategy
    • sourcetype / timestamp / line breaking configuration
  • Implementenrichment and routing using event breaking, host/source normalization,lookups, and tagging.
  • Install,configure, and maintain Splunk Add-ons (TAs) and apps across:
    • Indexers/ Search Heads / SHC
    • Deployment Server / Cluster Manager (where applicable)
  • Maintainversion compatibility and upgrade strategies for:
    • SplunkEnterprise / Splunk Cloud
    • Add-ons,apps, and content packs
  • Packageand deploy TAs using deployment pipelines and change management controls.
  • Ensurefields are aligned to CIM requirements
HybridSplunk Architecture Operations
  • Operateand support Splunk in complex environments:
    • On-premIndexer Cluster, Search Head Cluster, Forwarder tiers
    • SplunkCloud integrations where applicable (e.g., Heavy Forwarder, VPN, PrivateLink,data forwarding patterns)
  • Configureand troubleshoot data ingestion pipelines:
    • Syslog(UDP/TCP), API-based collection, HEC, file monitors, Windows Event Logs, cloudsources
  • Ensureperformance and reliability across the pipeline, including indexing throughput,parsing overhead, and search impact.
Monitoring,Troubleshooting & Governance
  • Monitoringestion health and pipeline performance:
  • Maintaingovernance for indexes, sourcetypes, retention, RBAC and data access boundaries(as required).
  • Contribute to operational runbooks, SOPs, and documentation; drive continuousimprovement in onboarding and normalization standards.
RequiredSkills & Experience (Mid–Senior)
  • 5–10years experience with Splunk administration and data onboarding (or equivalentdepth).
  • Strongpractical knowledge of:
    • Fieldextraction (regex, JSON/KV extraction), and troubleshooting parsing issues
    • props.conf / transforms.conf, sourcetypes, timestamps, line-breaking
    • TAinstallation/configuration and deployment patterns across Splunk tiers
  • Experience with complex Splunk architectures:
    • Indexerclusters, SH/SHC, forwarder management, deployment server
    • Hybridpatterns (on-prem + cloud), connectivity, and ingestion strategies
  • Comfortable writing and validating SPL for data quality and CIM compliance.
  • Cloud:AWS/Azure/GCP logging patterns (nice-to-have)
Preferred /Nice-to-Have
  • Experience with Splunk Enterprise Security (ES) and ES add-ons / CIM complianceexpectations.
  • Knowledgeof Splunk Ingest Actions / Edge Processor (or modern ingestion tools, whereapplicable).
  • Familiaritywith:
    • ITSI /Observability (bonus)
    • SplunkCore Certified Power User / Admin
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Splunk Data Administrator
Splunk Data Administrator

XPT Software • City of Melbourne

Hybrid
AUD 120,000 - 180,000
Splunk Data Administrator
Splunk Data Administrator

XPT Software Australia • City of Melbourne

Hybrid
AUD 120,000 - 150,000
Senior Splunk Data Administrator – CIM & Onboarding Expert
Senior Splunk Data Administrator – CIM & Onboarding Expert

XPT Software Australia Pty Ltd • City of Melbourne

On-site
AUD 120,000 - 180,000
Splunk Platform Engineer
Splunk Platform Engineer

XPT Software Australia Pty Ltd • City of Melbourne

On-site
AUD 110,000 - 165,000
Senior Splunk Data Onboarding & CIM Lead
Senior Splunk Data Onboarding & CIM Lead

XPT Software • City of Melbourne

Hybrid
AUD 120,000 - 180,000
Splunk Platform Engineer
Splunk Platform Engineer

XPT Software • Sydney

On-site
AUD 140,000 - 190,000
Splunk Platform Engineer AWS Cloud & Operations
Splunk Platform Engineer AWS Cloud & Operations

XPT Software Australia • City of Melbourne

On-site
AUD 140,000 - 180,000
Senior Splunk Platform Engineer on AWS
Senior Splunk Platform Engineer on AWS

XPT Software • Sydney

On-site
AUD 140,000 - 190,000
Splunk Technical Consultant - Engineering (ASAP Start)
Splunk Technical Consultant - Engineering (ASAP Start)

Jenkin Beattie • City of Melbourne

On-site
AUD 100,000 - 130,000
Splunk Platform Engineer – AWS & Infra
Splunk Platform Engineer – AWS & Infra

XPT Software Australia Pty Ltd • City of Melbourne

On-site
AUD 110,000 - 165,000