Noida, Uttar Pradesh
Job Summary
Splunk L3 Engineer / Architect – Job Description
7+ years of hands-on experience in administering and architecting enterprise-scale Splunk environments.
Strong expertise in Splunk architecture, including Indexer Clusters, Search Head Clusters, Cluster Manager, Deployment Server, License Manager, Heavy Forwarders, and Universal Forwarders.
Lead end-to-end onboarding of log sources from Windows, Linux, Unix, Cloud platforms, Databases, APIs, Syslog, HEC, DB Connect, and custom integrations.
Design and implement scalable, highly available, and resilient Splunk architectures aligned with business and security requirements.
Expertise in troubleshooting log ingestion, parsing, indexing, search performance, and data latency issues across distributed Splunk environments.
Strong knowledge of props.conf, transforms.conf, field extractions, CIM compliance, data normalization, and knowledge object management.
Perform Splunk platform upgrades, migrations, patching, and health assessments following best practices.
Key Responsibilities
Develop and optimize SPL queries, dashboards, alerts, reports, and correlation searches for operational and security use cases.
Analyze and resolve complex production issues, conduct RCA, and collaborate with application, infrastructure, and vendor teams for problem resolution.
Manage index lifecycle, data retention policies, storage planning, bucket management, RF/SF configuration, and license utilization optimization.
Implement and maintain security controls including RBAC, SSO, LDAP/SAML integration, certificates, and platform hardening.
Automate Splunk administration and operational activities using Python, Shell, PowerShell, or REST APIs.
Provide technical leadership, architectural guidance, and mentorship to L1/L2 engineers and project teams.
Skill Requirements
Mandatory Skills
Splunk Architecture | Log Onboarding | SPL | Indexer Clustering | Search Head Clustering | HEC | DB Connect | Syslog | Linux | Python/Shell Scripting | Troubleshooting | Performance Tuning | Splunk Upgrades | Observability
Other Requirements
Collaborate with stakeholders to understand monitoring and observability requirements and translate them into Splunk solutions.
Maintain operational documentation, onboarding standards, runbooks, troubleshooting guides, and architecture diagrams to support governance and knowledge management.
Preferred Certifications
Splunk Enterprise Certified Architect
Splunk Enterprise Certified Admin
Splunk Core Certified Power User
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-