We are looking for a Splunk Administrator to manage, maintain, and optimize our enterprise Splunk environment. In this role, you will be responsible for the health of the Splunk infrastructure, including Indexers, Search Heads, Deployment Servers, and Universal/Heavy Forwarders. You will work closely with security, IT operations, and development teams to ensure smooth data onboarding, user access management, platform performance, and cluster stability.
Key Responsibilities:
- Infrastructure & Platform Management:
- Install, configure, upgrade, and maintain Splunk Enterprise components (Search Heads, Indexers, Heavy/Universal Forwarders, and Deployment Servers).
- Monitor cluster health, perform indexer cluster rolling restarts, and manage license usage and storage retention policies (Hot, Warm, Cold, Frozen buckets).
- Manage Splunk apps, add-ons, and configuration files (inputs.conf, outputs.conf, props.conf, transforms.conf, and server.conf).
- Data Onboarding & Parsing:
- Ingest data from various log sources (Linux/Windows OS, network devices, cloud services, databases, and web applications).
- Configure field extractions, event breaking, and timestamp parsing to ensure clean data indexing.
- User Access & Governance:
- Manage Splunk user accounts, roles, permissions, and index-level access controls.
- Integrate Splunk with Enterprise Authentication systems (SAML, LDAP, Active Directory, OKTA).
- System Monitoring & Optimization:
- Troubleshoot data ingestion delays, forwarder disconnects, and search performance bottlenecks.
- Clean dispatch directories and optimize search head bundle replication.
- Assist internal teams with creating basic searches, alerts, and operational dashboards.
Required Technical Skills & Qualifications:
- Core Splunk Administration: 3+ years of dedicated hands-on experience administering Splunk Enterprise or Splunk Cloud environments.
- Operating Systems: Strong proficiency with Linux (RHEL/Ubuntu) administration and CLI navigation (system service management, permissions, cron jobs).
- Scripting Skills: Working knowledge of Bash, Python, or PowerShell for task automation and agent maintenance.
- Networking & Protocols: Solid understanding of networking protocols (TCP/IP, UDP, Syslog, HTTP/HEC, SSL/TLS, DNS, and Firewalls).
- Log Analytics: Strong understanding of log formats (JSON, Syslog, CSV, XML, and Windows Event Logs).
Pay: ₹600,000.00 - ₹800,000.00 per year
Work Location: In person