Splunk Administrator

Atloen Global

Gurugram District, Delhi

On-site

INR 1,200,000 - 1,800,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Atloen Global is seeking a seasoned Splunk Architect to Administer and support large-scale Splunk Enterprise environments in Gurgaon. You will manage Search Heads, Indexers, Heavy Forwarders, and related components while troubleshooting performance and ingestion issues.

The role requires expertise in RBAC, data inputs, and data retention policies, with hands-on experience in upgrades, migrations, and cross-team collaboration to resolve complex incidents. Immediate joiner preferred.

Qualifications

  • Extensive experience administering Splunk Enterprise environments.
  • Strong troubleshooting across Splunk infrastructure, searches, indexing, ingestion and performance.
  • Experience with RBAC, authentication, roles and access controls.

Responsibilities

  • Administer and support large-scale Splunk Enterprise environments.
  • Manage Search Heads, Indexers, Heavy Forwarders, Universal Forwarders, Deployment Server, License Manager, and Cluster Manager.
  • Perform advanced troubleshooting of Splunk infrastructure, searches, indexing, ingestion, and performance issues.
  • Manage and troubleshoot indexer and search head clusters.
  • Configure and maintain indexes, indexers, data inputs, forwarders, sourcetypes and data retention policies.
  • Monitor Splunk health, license utilization, indexing and storage capacity.
  • Perform Splunk upgrades, patching, configuration changes and migrations.
  • Troubleshoot data ingestion issues, missing logs, delayed data and parsing problems.
  • Optimize SPL searches, dashboards, reports, alerts and scheduled searches for performance.
  • Manage RBAC, authentication, roles, permissions and access controls.
  • Support integrations with Windows, Linux, Active Directory, firewalls and cloud platforms.
  • Configure and troubleshoot HEC, syslog, REST API, TCP/UDP inputs and other ingestion mechanisms.
  • Perform root-cause analysis for complex incidents and provide permanent fixes.
  • Participate in incident, problem and change management processes.
  • Create and maintain technical documentation, SOPs and architecture diagrams.
  • Work with application, infrastructure, network, security and vendor teams to resolve issues.
  • Participate in on-call / 247 production support as required.

Skills

Splunk Admin
Troubleshooting
Incident Mgmt
Change Mgmt
Documentation
Performance Tuning
Data Ingestion
RBAC & Access
On-call Support

Tools

Splunk
Windows
Linux

Job description

Role & responsibilities
  • Administer and support large-scale Splunk Enterprise environments.
  • Manage Splunk components including Search Heads, Indexers, Heavy Forwarders, Universal Forwarders, Deployment Server, License Manager, and Cluster Manager.
  • Perform advanced troubleshooting of Splunk infrastructure, searches, indexing, ingestion, and performance issues.
  • Manage and troubleshoot indexer clusters and search head clusters.
  • Configure and maintain indexes, indexers, data inputs, forwarders, sourcetypes, parsing, and data retention policies.
  • Monitor Splunk health, license utilization, indexing performance, search performance, and storage capacity.
  • Perform Splunk upgrades, patching, configuration changes, and migrations.
  • Troubleshoot data ingestion issues, missing logs, delayed data, parsing problems, and broken forwarder connections.
  • Optimize SPL searches, dashboards, reports, alerts, and scheduled searches for performance.
  • Manage RBAC, authentication, roles, permissions, and access controls.
  • Support integrations with security and infrastructure technologies such as Windows, Linux, Active Directory, firewalls, network devices, cloud platforms, EDR, and SIEM tools.
  • Configure and troubleshoot HEC, syslog, REST API, TCP/UDP inputs, and other data ingestion mechanisms.
  • Perform root-cause analysis for complex L3 incidents and provide permanent fixes.
  • Participate in incident, problem, and change management processes.
  • Create and maintain technical documentation, SOPs, troubleshooting guides, and architecture diagrams.
  • Work with application, infrastructure, network, security, and vendor teams to resolve complex issues.
  • Participate in on-call / 247 production support as required.
Preferred candidate profile

Immediate Joiner

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Administrator
Splunk Administrator

Tata Consultancy Services • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Splunk Administrator
Splunk Administrator

Alike Thoughts • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Splunk Developer & Administrator
Splunk Developer & Administrator

Tata Consultancy Services • Hyderabad, Chennai District, Bengaluru

On-site
INR 2,500,000 - 3,500,000
Splunk Administrator
Splunk Administrator

Cloudxtreme • Hyderabad

On-site
INR 600,000 - 1,200,000
Splunk Administrator/Engineer
Splunk Administrator/Engineer

Cloudxtreme • Hyderabad

On-site
INR 900,000 - 1,500,000
Splunk Administrator - Hyderabad
Splunk Administrator - Hyderabad

Cloudxtreme • Hyderabad

Hybrid
INR 1,500,000 - 2,500,000
Splunk Engineer Senior Splunk Engineer
Splunk Engineer Senior Splunk Engineer

Giesecke+Devrient • Pune District

On-site
INR 900,000 - 1,800,000
Splunk Engineer
Splunk Engineer

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,800,000
Splunk certification support
Splunk Developer
Splunk Developer

Purview Services • Greater Noida

On-site
INR 1,400,000 - 2,100,000
Splunk Administrator
Splunk Administrator

Tata Consultancy Services • Chennai District

On-site
INR 900,000 - 1,500,000