We are seeking a highly skilled and experienced Splunk Engineer to join our dynamic team. The ideal candidate will be responsible for the design, implementation, maintenance, and optimization of our Splunk environment. This role requires a deep understanding of Splunk architecture, data ingestion, search language (SPL), dashboard creation, and alert configuration. The Splunk Engineer will play a critical role in enhancing our monitoring, security, and operational intelligence capabilities.
- Design, deploy, and maintain Splunk Enterprise infrastructure, including indexers, search heads, forwarders, and deployment servers, ensuring high availability and scalability.
- Onboard new data sources into Splunk, configuring inputs, parsing, and field extractions to ensure data quality and usability.
- Develop, optimize, and troubleshoot complex Splunk Processing Language (SPL) queries, reports, dashboards, and alerts to meet business and security requirements.
- Monitor Splunk system health, performance, and capacity, implementing necessary adjustments and optimizations to ensure efficient operation.
- Collaborate with security, operations, and development teams to understand their data needs and provide tailored Splunk solutions.
- Create and manage Splunk knowledge objects, including lookups, data models, and macros, to enhance search efficiency and user experience.
- Implement and manage Splunk Enterprise Security (ES) app, developing correlation searches, notable events, and incident review workflows.
- Develop and maintain automation scripts (e.g., Python, Shell) for Splunk administration tasks, data onboarding, and integration with other systems.
- Provide expert-level support and troubleshooting for Splunk-related issues, ensuring timely resolution and root cause analysis.
- Document Splunk configurations, processes, and best practices, and provide training to other team members as needed.
- Stay current with the latest Splunk features, updates, and industry best practices to continuously improve our Splunk environment.
- Participate in on-call rotation for critical Splunk incidents, as required.