Position: Splunk Administrator (Enterprise Observability Platform Operations)
Location: Anywhere in India
Role Summary:
We are seeking a Splunk Administrator to support day‑to‑day operations of the Enterprise Observability- Splunk suite platform (Splunk Enterprise, ITSI, and Splunk Observability Cloud), including data onboarding, system maintenance, monitoring, troubleshooting, and user support.
This is a hands‑on Splunk support operations role supporting a mission‑critical environment that requires hands‑on collaboration with engineering, operations, and application teams.
Key Responsibilities
Platform Administration & Daily Operations
- Monitor Splunk Enterprise platform health, performance, and capacity.
- Perform routine administrative tasks: restarts, configuration updates, index management, and license monitoring.
- Support search head and indexer cluster operations under guidance from senior engineers.
- Maintain forwarder configurations and ensure reliable data ingestion.
Data Onboarding & Configuration
- Onboard new data sources using forwarders, APIs, add‑ons, and cloud integrations.
- Configure inputs, props/transforms, sourcetypes, and parsing rules.
- Validate data quality, field extractions, and CIM compliance.
- Maintain and update Technology Add‑Ons (TAs) as needed.
ITSI & Observability Support
- Assist with ITSI KPI updates, service model maintenance, and correlation search tuning.
- Support troubleshooting of ITSI lag, KPI failures, and service health issues.
- Help maintain integrations with Splunk Observability Cloud (O11y) and OpenTelemetry collectors.
User Support & Operational Requests
- Provide support to internal users for searches, dashboards, alerts, and knowledge objects.
- Assist teams with troubleshooting search performance and data visibility issues.
- Maintain documentation, runbooks, and onboarding guides.
Incident & Problem Management
- Participate in incident response for Splunk‑related issues.
- Investigate ingestion failures, search errors, and platform alerts.
- Support root cause analysis and implement corrective actions.
Governance & Best Practices
- Follow established standards for data onboarding, index naming, retention, and tagging.
- Ensure compliance with security, audit, and logging requirements.
Maintain accurate documentation of configurations and operational procedures.
-