01 Sep
|
Lorven Technologies
|
Bengaluru
01 Sep
Lorven Technologies
Bengaluru
Job Description
Job Title : Splunk Admin
nExperience : 3 to 14 Years
nWork Location : Pan India
n
nJob Summary
n
nWe are seeking an experienced Splunk Administrator with hands-on expertise in Splunk Enterprise Security (ES) to manage, administer, optimize, and support enterprise Splunk environments. The ideal candidate will have solid experience in Splunk architecture, onboarding data sources, security monitoring, SIEM operations, performance tuning, and troubleshooting in large-scale production environments.
n
nKey Responsibilities
n
n
- n
- Install, configure, administer, and maintain Splunk Enterprise and Splunk Enterprise Security (ES).n
- Manage Splunk components including Indexers, Search Heads, Deployment Server, Heavy Forwarders, Universal Forwarders, Cluster Master/Manager, License Manager, and Monitoring Console.n
- Deploy and manage distributed and clustered Splunk environments.n
- Onboard and normalize logs from various data sources including Windows, Linux, Unix, firewalls, proxies, databases, cloud platforms, and applications.n
- Configure and manage Splunk ES content such as correlation searches, notable events, adaptive response actions, risk-based alerting, and dashboards.n
- Develop and optimize SPL queries, reports, dashboards, and alerts.n
- Perform health checks, capacity planning, performance tuning, and troubleshooting.n
- Manage index lifecycle, retention policies, storage optimization, and data archival.n
- Configure RBAC, authentication (LDAP/AD/SAML), and security best practices.n
- Integrate Splunk with third-party security tools including SOAR, threat intelligence platforms, EDR, vulnerability scanners, and ticketing systems.n
- Upgrade Splunk infrastructure and ES versions with minimal downtime.n
- Monitor system availability and resolve production incidents.n
- Automate administrative tasks using Python, Shell scripting, or REST APIs.n
- Collaborate with SOC, Security Operations, Infrastructure, and Applica
📌 Splunk Admin (Bengaluru)
🏢 Lorven Technologies
📍 Bengaluru