12 Sep
|
Atloen Global
|
Delhi
12 Sep
Atloen Global
Delhi
Role & responsibilities
- Administer and support large-scale Splunk Enterprise environments.
- Manage Splunk components including Search Heads, Indexers, Heavy Forwarders, Universal Forwarders, Deployment Server, License Manager, and Cluster Manager.
- Perform advanced troubleshooting of Splunk infrastructure, searches, indexing, ingestion, and performance issues.
- Manage and troubleshoot indexer clusters and search head clusters.
- Configure and maintain indexes, indexers, data inputs, forwarders, sourcetypes, parsing, and data retention policies.
- Monitor Splunk health, license utilization, indexing performance, search performance, and storage capacity.
- Perform Splunk upgrades, patching, configuration changes, and migrations.
- Troubleshoot data ingestion issues, missing logs, delayed data, parsing problems, and broken forwarder connections.
- Optimize SPL searches, dashboards, reports, alerts, and scheduled searches for performance.
- Manage RBAC, authentication, roles,
permissions, and access controls.
- Support integrations with security and infrastructure technologies such as Windows, Linux, Active Directory, firewalls, network devices, cloud platforms, EDR, and SIEM tools.
- Configure and troubleshoot HEC, syslog, REST API, TCP/UDP inputs, and other data ingestion mechanisms.
- Perform root-cause analysis for complex L3 incidents and provide permanent fixes.
- Participate in incident, problem, and change management processes.
- Create and maintain technical documentation, SOPs, troubleshooting guides, and architecture diagrams.
- Work with application, infrastructure, network, security, and vendor teams to resolve complex issues.
- Participate in on-call / 247 production support as required.
Preferred candidate profile
Immediate Joiner
📌 Splunk Administrator (Delhi)
🏢 Atloen Global
📍 Delhi