Job Summary:
We are looking for a skilled Splunk Administrator with hands-on experience in deploying and managing Splunk Enterprise and Splunk Cloud. The ideal candidate should have experience in Splunk Enterprise Security (ES), Splunk UBA, and IT Service Intelligence (ITSI). This role requires strong technical skills, along with the ability to communicate effectively with customers.
Key Responsibilities:
✅ Splunk Deployment & Administration:
Install, configure, and manage Splunk Enterprise and Splunk Cloud.
Handle indexers, search heads, forwarders, and clustering.
Optimize Splunk performance, storage, and scalability.
✅ Security & Splunk Monitoring Solutions:
Implement and manage Splunk Enterprise Security (ES), Splunk UBA, and ITSI.
Configure correlation searches, threat intelligence feeds, risk-based alerting (RBA), and dashboards.
Troubleshoot security-related issues within Splunk.
✅ Customer Interaction & Troubleshooting:
Engage with customers to understand their requirements and provide technical guidance.
Troubleshoot and resolve Splunk-related issues, logs ingestion, parsing, and data onboarding.
Must-Have Skills:
✔️ 2-3 years of hands-on experience with Splunk Enterprise & Splunk Cloud.
✔️ Experience with Splunk ES, Splunk UBA, ITSI (anyone mandatory).
✔️ Strong understanding of Splunk architecture, data onboarding, parsing, CIM mapping, knowledge objects, Lookups, Correlation Searches etc.
✔️ Strong experience in Troubleshooting Splunk issues.
✔️ Strong experience in Splunk Searches, correlation searches, dashboarding, reporting, development.
✔️ Ability to clearly communicate and explain Splunk configurations and troubleshooting steps.
Preferred Skills:
➕ Splunk Certifications (e.g., Splunk Enterprise Certified Admin, Splunk ES Certified Admin, Splunk Certified Architect).
➕ Good scripting skills in Python, Bash, or PowerShell for automation.
➕ Experience with SOAR, Splunk Observability, IT operations monitoring, or cloud security use cases.
➕ Familiarity with AWS, Azure, or GCP integrations with Splunk.
➕ Familiarity with On-premise infrastructure components, log sources etc