Splunk Administrator (VP2)
We are seeking an experienced Splunk Administrator responsible for the design, implementation, administration, and optimization of the enterprise Splunk platform. The ideal candidate will have strong hands-on experience managing Splunk infrastructure components including Search Head Clusters, Indexer Clusters, Deployment Servers, Heavy Forwarders, Universal Forwarders, and License Management in large-scale enterprise environments.
Responsibilities
- Design, implement, administer, and maintain the enterprise Splunk platform.
- Manage Splunk infrastructure components including Search Heads, Indexers, Deployment Servers, Heavy Forwarders, Universal Forwarders, Cluster Manager, License Manager, and Deployer.
- Configure and maintain Search Head Clusters and Indexer Clusters.
- Administer data onboarding, source type configuration, parsing, indexing, and data retention.
- Monitor Splunk platform health, performance, availability, and capacity.
- Perform Splunk upgrades, patching, migration, and infrastructure expansion activities.
- Optimize indexes, searches, data models, and platform performance.
- Develop automation scripts using Python or similar scripting languages.
- Integrate Splunk with various enterprise systems and data sources.
- Support troubleshooting and root cause analysis related to Splunk platform and data ingestion issues.
- Configure dashboards, reports, alerts, and knowledge objects as required.
Requirements
- Bachelor's Degree in Computer Science, Information Technology, or related discipline.
- Minimum 6 years of IT experience with at least 3 years of hands-on Splunk Administration experience.
- Strong experience managing:
- Search Head Clusters
- Indexer Clusters
- Deployment Servers
- Heavy Forwarders
- Universal Forwarders
- License Management
- Strong understanding of Splunk architecture, deployment models, and platform sizing.
- Experience with Splunk upgrades, platform scaling, and infrastructure lifecycle management.
- Expertise in Splunk SPL and platform performance tuning.
- Experience onboarding and integrating diverse log sources into Splunk.
- Strong understanding of Linux, networking, virtualization, storage, and enterprise infrastructure.
Preferred Qualifications
- Splunk Certified Admin.
- Experience with Python, REST APIs, or automation scripting.
- Knowledge of Ansible, Puppet, Chef, or Infrastructure as Code tools.
- Experience with Docker, Kubernetes, and DevOps practices.
- Familiarity with Agile methodologies, Jira, and Confluence.
Important Note
This role is focused on Splunk Platform Administration and Engineering. Candidates whose experience is primarily in production support, application support, monitoring operations, or dashboard development without hands-on Splunk infrastructure administration experience may not be suitable.