About the job:
As a Splunk Administrator/Engineer, you will play a key role in ensuring the reliability, performance, and continuous evolution of our Splunk setting. You will be responsible for maintaining and troubleshooting the Splunk infrastructure, supporting data onboarding initiatives, developing monitoring and alerting solutions, and collaborating with stakeholders to deliver actionable insights through dashboards and reporting. You will contribute to platform improvements, share technical expertise, and help drive operational excellence across the organization.
Location: Chennai
Work Model: Night Shift USA Alaska Time Zone
What you will do:
Troubleshoot issues in the Splunk cluster (247), supporting upgrades and patches of the Splunk cluster
Participate in various projects to support data ingestion (installing forwarders, indexers, search heads, etc.)
Work with users to create reports, dashboards and troubleshoot issues with data ingestion
Share your experience and the way you overcame technical and delivery challenges with your colleagues
Design,
implement and maintain alerting solutions using Splunk
Onboard diverse data sources, build technology add-ons (TAs), and create optimized regular expressions (regex) for field extractions.
What would help you succeed:
5+ years hands-on experience working with Splunk/Splunk Cloud and modules like Enterprise Security and ITSI
Experience onboarding and integrating current data sources into Splunk
Solid knowledge of SPL (Search Processing Language) and the ability to create and optimize searches, reports, dashboards, and alerts
Scripting experience - Bash, Python or any other similar languages will help you in your day-to-day tasks
Experience with Linux is a must since the platform is hosted on Linux
Hands-on experience with methodologies like SNMP, Syslogs, Winrm, WMI, SNMP Traps, agent/agentless, API, etc.
Exposure to CI/CD pipelines (Ansible/Gitlab),
Capability to develop and improve
📌 Splunk Administrator Night Shift Chennai (India)
🏢 Cegeka
📍 India