Splunk Admin (Bengaluru)

Splunk Admin (Bengaluru)

02 Aug
|
Lorven Technologies
|
Bengaluru

02 Aug

Lorven Technologies

Bengaluru

Job Title : Splunk Admin

Experience : 3 to 14 Years

Work Location : Pan India

Job Summary

We are seeking an experienced Splunk Administrator with hands-on expertise in Splunk Enterprise Security (ES) to manage, administer, optimize, and support enterprise Splunk environments. The ideal candidate will have strong experience in Splunk architecture, onboarding data sources, security monitoring, SIEM operations, performance tuning, and troubleshooting in large-scale production environments.

Key Responsibilities

- Install, configure, administer, and maintain Splunk Enterprise and Splunk Enterprise Security (ES).
- Manage Splunk components including Indexers, Search Heads, Deployment Server, Heavy Forwarders, Universal Forwarders, Cluster Master/Manager, License Manager, and Monitoring Console.
- Deploy and manage distributed and clustered Splunk environments.
- Onboard and normalize logs from various data sources including Windows, Linux, Unix, firewalls, proxies, databases, cloud platforms, and applications.
- Configure and manage Splunk ES content such as correlation searches, notable events, adaptive response actions, risk-based alerting, and dashboards.
- Develop and optimize SPL queries, reports, dashboards, and alerts.
- Perform health checks, capacity planning, performance tuning, and troubleshooting.
- Manage index lifecycle, retention policies, storage optimization, and data archival.
- Configure RBAC, authentication (LDAP/AD/SAML), and security best practices.




- Integrate Splunk with third-party security tools including SOAR, threat intelligence platforms, EDR, vulnerability scanners, and ticketing systems.
- Upgrade Splunk infrastructure and ES versions with minimal downtime.
- Monitor system availability and resolve production incidents.
- Automate administrative tasks using Python, Shell scripting, or REST APIs.
- Collaborate with SOC, Security Operations, Infrastructure, and Application teams.
- Create technical documentation, SOPs, and operational runbooks.

Required Skills

- 3–14 years of IT experience with at least 3 years of hands-on Splunk Administration.
- Strong experience with Splunk Enterprise Security (ES).
- Expertise in Splunk architecture and distributed deployments.
- Experience with Indexer Clustering and Search Head Clustering.
- Strong knowledge of SPL (Search Processing Language).
- Experience onboarding diverse log sources.
- Knowledge of CIM (Common Information Model), data models, and field extractions.
- Experience configuring correlation searches, notable events, risk objects, and dashboards.
- Experience with authentication integrations such as LDAP, Active Directory, and SAML.
- Solid Linux/Unix administration skills.
- Experience with Python, Shell scripting, or PowerShell.
- Understanding of TCP/IP, DNS, HTTP/HTTPS, Syslog, SNMP, and networking fundamentals.
- Experience in troubleshooting Splunk performance and ingestion issues.

📌 Splunk Admin (Bengaluru)
🏢 Lorven Technologies
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk admin (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: splunk admin (bengaluru) / bengaluru