Splunk Admin + Developer

Tata Consultancy Services

Bengaluru

On-site

INR 1,200,000 - 1,400,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Tata Consultancy Services is seeking a Splunk Admin to manage and optimize a customer-managed Splunk environment. The role focuses on log onboarding, alerting, and daily indexing governance across Forwarders, Indexers, Search Heads, and Deployment Server.

The candidate will ensure CIM-compliant data normalization, implement retention policies, and perform health checks while coordinating with security teams on SIEM-related tasks. Strong Regex skills are essential.

Qualifications

  • Experience with Splunk components and CIM framework.
  • Proficient in data onboarding, indexing, and alerting.
  • Knowledge of retention policies, archiving, and data normalization.
  • Regex skills for field extraction and data parsing.

Responsibilities

  • Manage log onboarding and alert monitoring in Splunk Cloud.
  • Configure index.conf including index name, home path, cold and frozen paths.
  • Define storage locations and retention policies for data.
  • Maintain current customer-managed Splunk infrastructure.
  • Perform health checks and handle incidents/service requests.

Skills

Splunk
Log Onboarding
Alert Monitoring
Forwarders
Indexers
Search Heads
Deployment Server
Cluster Master
License Manager
CIM Framework
Regex
SIEM
Data Normalization

Tools

Splunk Admin Console
SPL
Splunk CIM

Job description

Role & responsibilities
Desired Competencies (Technical/Behavioral Competency)
Must-Have
  • Good communication skill
  • Responsible for log onboarding and alert monitoring setup in Splunk Cloud
  • Daily indexing volume must be minimum of 100 GB and more.
  • Involved various Splunk components:
  • Forwarders: Collected data from various sources.
  • Indexers: Indexed incoming data and managed data storage.
  • Search Heads: Distributed search requests to indexers.
  • Deployment Server: Managed configurations and app deployments.
  • Cluster Master: Managed replication and data redundancy.
  • License Manager: Tracked daily indexing volume for compliance.
  • Focused on configuration tasks:
  • Managed `index.conf`, including index name, home path, cold path, and frozen path.
  • Defined storage locations and retention policies for data.
  • Worked on settings related to:
  • Data archiving and retention limits.
  • Replication settings for data redundancy.
  • Worked on Splunk enterprise security is a security information and event management (SIEM) tool.
  • Involves setting up collaboration searches and alerts to monitor suspicious activities.
  • Must have worked on CIM (Common Information Model) framework
  • Worked on normalize data in Splunk.
  • Exposure to security and provides common structure and field names.
  • The model helps in the standardization of data across different sources.
  • Must have Regex skills
  • Responsible for maintaining the current customer managed Splunk infrastructure
  • Responsible for log onboarding and alert monitoring setup in Splunk
  • Responsible for Offloading logs involves searching, archiving, exporting, and deleting.
  • Responsible for identifying opportunities to enhance the current baseline processes and configuration.
  • Responsible for monitoring the health of the customer managed asset and vendor managed Splunk infrastructure configuration
  • Assist with any common and complex user issues of both technical and process nature.
  • Verify operational effects of any changes on existing Splunk deployments.
  • Develop SOP documents on processes associated with tasks identified under BAU.
  • Manage the Incident and Service Request under the assignment group for Splunk support.
  • Perform the regular health check of the application and report any discrepancies.
  • Support and manage existing data sources.
  • Provide timely resolution to any data forwarding, Search head, indexing or parsing related request.
  • Application/platform log source types onboarding (S/M/L efforts)
  • Application/platform log source types onboarding maintenance activity
  • Operation alert creation and maintenance
  • Validating existing monitoring metrics and work with support team to fine tune parameters and alerting.
  • Provide support for user management activities (onboarding - offboarding users).
  • Analysis and improvement of configuration of data collection and data
  • Perform detailed evaluation of Information Systems audit and security log requirements.
Preferred candidate profile
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Developer & Administrator
Splunk Developer & Administrator

Tata Consultancy Services • Hyderabad, Chennai District, Bengaluru

On-site
INR 2,500,000 - 3,500,000
Splunk Admin
Splunk Admin

Tata Consultancy Services • Hyderabad

On-site
INR 900,000 - 1,300,000
Splunk Developer/ Splunk Consultant
Splunk Developer/ Splunk Consultant

Cosmonaut Technologies • Pune District

On-site
INR 1,800,000 - 2,800,000
Lead Observability Engineer
Lead Observability Engineer

Staples India • Chennai District

On-site
INR 1,200,000 - 1,800,000
Splunk Administrator
Splunk Administrator

Capgemini • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 2,400,000
Splunk Developer
Splunk Developer

Purview Services • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Infra Developer
Infra Developer

Cognizant • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Splunk Admin
Splunk Admin

Lorven Technologies Inc. • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Splunk Development & Administration Cyber Security Analyst
Splunk Development & Administration Cyber Security Analyst

Sopra Steria Group • Chennai District

On-site
INR 800,000 - 1,200,000
Infra Developer
Infra Developer

Cognizant • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000