27 Aug
|
SkillRecruit
|
India
27 Aug
SkillRecruit
India
Role: MSP Splunk Engineer
Experience Level: 4+ years
Location: Remote
About the Role
We're looking for an MSP Splunk Engineer to join our existing MSP team. You'll own the end-to-end health of customer Splunk environments, from onboarding and data ingestion through daily operations, monitoring, troubleshooting, and optimization. This is a multi-tenant role: you'll juggle multiple customer environments, SLAs, and priorities every day, so proven MSP experience is a hard requirement.
Key Responsibilities
- Operate, maintain, and optimize Splunk Enterprise / Splunk Cloud environments for multiple MSP customers concurrently
- Own end-to-end delivery: customer onboarding, data onboarding (forwarders, HEC, syslog, DB Connect, cloud sources), parsing/props/transforms, index and retention design
- Perform daily health checks, monitor environment performance, and proactively remediate issues (indexer/search head clusters, license usage, skipped searches, queue blockages)
- Respond to and resolve customer tickets within defined SLAs; manage incident, problem, and change processes
- Build and tune dashboards, alerts, reports, and knowledge objects aligned to customer use cases
- Perform Splunk upgrades, app/add-on management, and configuration management across distributed deployments
- Troubleshoot data ingestion, search performance, and infrastructure issues end to end
- Document runbooks, environment configurations, and standard operating procedures
- Communicate clearly with customer stakeholders: status updates, RCA reports,
and recommendations
- Collaborate with the broader delivery team on escalations, Professional Services handoffs, and continuous service improvement
Required Qualifications
- 4+ years of solid MSP Splunk experience managing Splunk environments for multiple customers in a managed services model (not a single in-house deployment)
- End-to-end Splunk expertise: architecture, deployment, data onboarding, administration, and troubleshooting
- Strong hands-on experience with distributed Splunk deployments (indexer clustering, search head clustering, deployment server, deployer)
- Proficiency in SPL, props/transforms, CIM normalization, and knowledge object management
- Experience with Splunk Cloud and hybrid environments
- Solid Linux administration skills; comfort with scripting (Bash, Python) for automation
- Experience working within ticketing/ITSM workflows (ServiceNow, Jira, or similar) and meeting SLAs
- Robust written and verbal communication, able to interface directly with customer teams
- Splunk Core Certified Power User or Admin certification
Preferred Qualifications
- Splunk Enterprise Certified Admin / Architect certification
- Experience with Splunk ES, ITSI, or SOAR
- Exposure to observability and cloud data sources (AWS, Azure, GCP)
- Experience in 24×7 NOC/SOC support models and on-call rotations
- Familiarity with automation and Infrastructure-as-Code (Ansible, Terraform)
- Exposure to AI-assisted operations tooling
📌 MSP Splunk Engineer (India)
🏢 SkillRecruit
📍 India