Noida, Uttar Pradesh
Job Summary
We are seeking an experienced Splunk Administrator to manage, maintain, and optimize the Splunk platform. The candidate will be responsible for ensuring high availability, performance, security, and scalability of the Splunk environment while supporting monitoring, log analytics, security operations, and operational intelligence initiatives.
Key Responsibilities
Key Responsibilities Platform Administration Install, configure, upgrade, and maintain Splunk Enterprise environments. Administer Splunk components including Search Heads, Indexers, Deployment Servers, Cluster Managers, and Forwarders. Configure and manage Splunk distributed and clustered environments. Monitor platform health, performance, and capacity utilization. Data Management Onboard logs from servers, applications, databases, cloud platforms, and network devices. Develop and maintain data inputs, parsing, indexing, retention, and archival policies. Manage index lifecycle, data retention, and storage optimization. Monitoring & Analytics Create dashboards, reports, alerts, and visualizations. Develop SPL (Search Processing Language) queries for operational and security use cases. Support incident troubleshooting and root cause analysis using log analytics. Security & Compliance Implement RBAC, authentication, and authorization controls. Integrate Splunk with LDAP/AD, SSO, and security tools. Ensure compliance with organizational security standards and audit requirements. Automation & Integration Integrate Splunk with ITSM, CMDB, SIEM, cloud, and monitoring tools. Develop automation scripts using Python, Shell, or PowerShell. Support REST API integrations and data ingestion workflows. Support & Operations Provide L2/L3 support for Splunk infrastructure. Troubleshoot ingestion, search, performance, and clustering issues. Prepare operational documentation, SOPs, and knowledge articles. Participate in on-call and major incident support when required.
Skill Requirements
Required Skills Strong hands-on experience with Splunk Enterprise Administration. Expertise in SPL query development. Knowledge of Search Head Clustering and Indexer Clustering. Experience with Universal Forwarders and Heavy Forwarders. Good understanding of Linux administration. Experience with monitoring and observability tools. Knowledge of networking concepts, security logs, and protocols. Scripting experience in Python, Shell, or PowerShell. Familiarity with REST APIs and integrations.
Other Requirements
Preferred Skills Splunk Enterprise Security (ES) Splunk ITSI AWS/Azure cloud environments Dynatrace, Datadog, Grafana, Zabbix, or similar monitoring platforms ServiceNow Integration Cybersecurity and SIEM concepts Certifications (Preferred) Splunk Core Certified User Splunk Enterprise Certified Admin Splunk Enterprise Security Certified Admin
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-