Splunk Admin

Lorven Technologies Inc.

Bengaluru

On-site

INR 1,800,000 - 3,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lorven Technologies Inc. is seeking an experienced Splunk Administrator with hands-on Splunk Enterprise Security (ES) expertise to manage, optimize, and support large-scale Splunk environments in Bengaluru, India.

The role focuses on on-boarding data sources, configuring ES content, developing SPL queries, and performing performance tuning and incident response. Strong scripting and collaboration with SOC teams are essential.

Qualifications

  • 3–14 years of IT experience with hands-on Splunk Administration.
  • Strong experience with Splunk Enterprise Security (ES).
  • Expertise in Splunk architecture and distributed deployments.
  • Experience with Indexer clustering and Search Head Clustering.
  • Strong knowledge of SPL (Search Processing Language).
  • Experience onboarding diverse log sources.
  • Knowledge of CIM (Common Information Model), data models, and field extractions.
  • Experience configuring correlation searches, notable events, risk objects, and dashboards.
  • Experience with authentication integrations such as LDAP, Active Directory, and SAML.
  • Experience with Python, Shell scripting, or PowerShell.
  • Understanding of TCP/IP, DNS, HTTP/HTTPS, Syslog, SNMP, and networking fundamentals.
  • Experience in troubleshooting Splunk performance and ingestion issues.

Responsibilities

  • Install, configure, administer, and maintain Splunk Enterprise and Splunk Enterprise Security (ES).
  • Manage Splunk components including Indexers, Search Heads, Deployment Server, Heavy Forwarders, Universal Forwarders, Cluster Master/Manager, License Manager, and Monitoring Console.
  • Deploy and manage distributed and clustered Splunk environments.
  • Onboard and normalize logs from various data sources including Windows, Linux, Unix, firewalls, proxies, databases, cloud platforms, and applications.
  • Configure and manage Splunk ES content such as correlation searches, notable events, adaptive response actions, risk-based alerting, and dashboards.
  • Develop and optimize SPL queries, reports, dashboards, and alerts.
  • Perform health checks, capacity planning, performance tuning, and troubleshooting.
  • Manage index lifecycle, retention policies, storage optimization, and data archival.
  • Configure RBAC, authentication (LDAP/AD/SAML), and security best practices.
  • Integrate Splunk with third-party security tools including SOAR, threat intelligence platforms, EDR, vulnerability scanners, and ticketing systems.
  • Upgrade Splunk infrastructure and ES versions with minimal downtime.
  • Monitor system availability and resolve production incidents.
  • Automate administrative tasks using Python, Shell scripting, or REST APIs.
  • Collaborate with SOC, Security Operations, Infrastructure, and Application teams.
  • Create technical documentation, SOPs, and operational runbooks.

Skills

Splunk Enterprise Security
Splunk architecture
SPL
Data onboarding
RBAC LDAP/AD/SAML
Python scripting
Shell scripting
PowerShell
Troubleshooting
Distributed deployments
Performance tuning

Tools

Splunk Enterprise

Job description

We are seeking an experienced Splunk Administrator with hands-on expertise in Splunk Enterprise Security (ES) to manage, administer, optimize, and support enterprise Splunk environments. The ideal candidate will have strong experience in Splunk architecture, onboarding data sources, security monitoring, SIEM operations, performance tuning, and troubleshooting in large-scale production environments.

Key Responsibilities

  • Install, configure, administer, and maintain Splunk Enterprise and Splunk Enterprise Security (ES).
  • Manage Splunk components including Indexers, Search Heads, Deployment Server, Heavy Forwarders, Universal Forwarders, Cluster Master/Manager, License Manager, and Monitoring Console.
  • Deploy and manage distributed and clustered Splunk environments.
  • Onboard and normalize logs from various data sources including Windows, Linux, Unix, firewalls, proxies, databases, cloud platforms, and applications.
  • Configure and manage Splunk ES content such as correlation searches, notable events, adaptive response actions, risk-based alerting, and dashboards.
  • Develop and optimize SPL queries, reports, dashboards, and alerts.
  • Perform health checks, capacity planning, performance tuning, and troubleshooting.
  • Manage index lifecycle, retention policies, storage optimization, and data archival.
  • Configure RBAC, authentication (LDAP/AD/SAML), and security best practices.
  • Integrate Splunk with third-party security tools including SOAR, threat intelligence platforms, EDR, vulnerability scanners, and ticketing systems.
  • Upgrade Splunk infrastructure and ES versions with minimal downtime.
  • Monitor system availability and resolve production incidents.
  • Automate administrative tasks using Python, Shell scripting, or REST APIs.
  • Collaborate with SOC, Security Operations, Infrastructure, and Application teams.
  • Create technical documentation, SOPs, and operational runbooks.

Required Skills

  • 3–14 years of IT experience with at least 3 years of hands-on Splunk Administration.
  • Strong experience with Splunk Enterprise Security (ES).
  • Expertise in Splunk architecture and distributed deployments.
  • Experience with Indexer Clustering and Search Head Clustering.
  • Strong knowledge of SPL (Search Processing Language).
  • Experience onboarding diverse log sources.
  • Knowledge of CIM (Common Information Model), data models, and field extractions.
  • Experience configuring correlation searches, notable events, risk objects, and dashboards.
  • Experience with authentication integrations such as LDAP, Active Directory, and SAML.
  • Experience with Python, Shell scripting, or PowerShell.
  • Understanding of TCP/IP, DNS, HTTP/HTTPS, Syslog, SNMP, and networking fundamentals.
  • Experience in troubleshooting Splunk performance and ingestion issues.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Developer/ Splunk Consultant
Splunk Developer/ Splunk Consultant

Cosmonaut Technologies • Pune District

On-site
INR 1,800,000 - 2,800,000
SENIOR ENGINEER - SPLUNK-Admin
SENIOR ENGINEER - SPLUNK-Admin

Happiest Minds Technologies • Bengaluru

On-site
INR 900,000 - 1,300,000
Splunk Administrator
Splunk Administrator

Capgemini • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 2,400,000
SIEM Engineer - Contract
SIEM Engineer - Contract

Gravity Infosolutions, Inc. • India

On-site
INR 1,200,000 - 1,800,000
Lead Observability Engineer
Lead Observability Engineer

Staples India • Chennai District

On-site
INR 1,200,000 - 1,800,000
Splunk Admin
Splunk Admin

Tata Consultancy Services • Hyderabad

On-site
INR 900,000 - 1,300,000
Splunk Admin + Developer
Splunk Admin + Developer

Tata Consultancy Services • Bengaluru

On-site
INR 1,200,000 - 1,400,000
Splunk Architect
Splunk Architect

Tekskills • Hyderabad

On-site
INR 1,200,000 - 1,800,000
SOC Splunk Consultant
SOC Splunk Consultant

KPMG Assurance and Consulting Services LLP • Mumbai

Hybrid
INR 900,000 - 1,500,000
Splunk Architect
Splunk Architect

Tekskills • Bulandshahr

On-site
INR 1,800,000 - 3,000,000