02 Aug
|
Lorven Technologies
|
Bengaluru
02 Aug
Lorven Technologies
Bengaluru
Job Title : Splunk Admin
Experience : 3 to 14 Years
Work Location : Pan India
Job Summary
We are seeking an experienced Splunk Administrator with hands-on expertise in Splunk Enterprise Security (ES) to manage, administer, optimize, and support enterprise Splunk environments. The ideal candidate will have strong experience in Splunk architecture, onboarding data sources, security monitoring, SIEM operations, performance tuning, and troubleshooting in large-scale production environments.
Key Responsibilities
- Install, configure, administer, and maintain Splunk Enterprise and Splunk Enterprise Security (ES).
- Manage Splunk components including Indexers, Search Heads, Deployment Server, Heavy Forwarders, Universal Forwarders, Cluster Master/Manager, License Manager, and Monitoring Console.
- Deploy and manage distributed and clustered Splunk environments.
- Onboard and normalize logs from various data sources including Windows, Linux, Unix, firewalls, proxies, databases, cloud platforms, and applications.
- Configure and manage Splunk ES content such as correlation searches, notable events, adaptive response actions, risk-based alerting, and dashboards.
- Develop and optimize SPL queries, reports, dashboards, and alerts.
- Perform health checks, capacity planning, performance tuning, and troubleshooting.
- Manage index lifecycle, retention policies, storage optimization, and data archival.
- Configure RBAC, authentication (LDAP/AD/SAML), and security best practices.
- Integrate Splunk with third-party security tools including SOAR, threat intelligence platforms, EDR, vulnerability scanners, and ticketing systems.
- Upgrade Splunk infrastructure and ES versions with minimal downtime.
- Monitor system availability and resolve production incidents.
- Automate administrative tasks using Python, Shell scripting, or REST APIs.
- Collaborate with SOC, Security Operations, Infrastructure, and Application teams.
- Create technical documentation, SOPs, and operational runbooks.
Required Skills
- 3–14 years of IT experience with at least 3 years of hands-on Splunk Administration.
- Strong experience with Splunk Enterprise Security (ES).
- Expertise in Splunk architecture and distributed deployments.
- Experience with Indexer Clustering and Search Head Clustering.
- Strong knowledge of SPL (Search Processing Language).
- Experience onboarding diverse log sources.
- Knowledge of CIM (Common Information Model), data models, and field extractions.
- Experience configuring correlation searches, notable events, risk objects, and dashboards.
- Experience with authentication integrations such as LDAP, Active Directory, and SAML.
- Solid Linux/Unix administration skills.
- Experience with Python, Shell scripting, or PowerShell.
- Understanding of TCP/IP, DNS, HTTP/HTTPS, Syslog, SNMP, and networking fundamentals.
- Experience in troubleshooting Splunk performance and ingestion issues.
📌 Splunk Admin (Bengaluru)
🏢 Lorven Technologies
📍 Bengaluru