13 Sep
|
Atloen Global
|
Delhi
13 Sep
Atloen Global
Delhi
Role & responsibilities
Administer and support large-scale Splunk Enterprise settings.
Manage Splunk components including Search Heads, Indexers, Heavy Forwarders, Universal Forwarders, Deployment Server, License Manager, and Cluster Manager.
Perform advanced troubleshooting of Splunk infrastructure, searches, indexing, ingestion, and performance issues.
Manage and troubleshoot indexer clusters and search head clusters.
Configure and maintain indexes, indexers, data inputs, forwarders, sourcetypes, parsing, and data retention policies.
Monitor Splunk health, license utilization, indexing performance, search performance, and storage capacity.
Perform Splunk upgrades, patching, configuration changes, and migrations.
Troubleshoot data ingestion issues, missing logs, delayed data, parsing problems, and broken forwarder connections.
Optimize SPL searches, dashboards, reports, alerts, and scheduled searches for performance.
Manage RBAC, authentication, roles, permissions,
and access controls.
Support integrations with security and infrastructure technologies such as Windows, Linux, Active Directory, firewalls, network devices, cloud platforms, EDR, and SIEM tools.
Configure and troubleshoot HEC, syslog, REST API, TCP/UDP inputs, and other data ingestion mechanisms.
Perform root-cause analysis for complex L3 incidents and provide permanent fixes.
Participate in incident, problem, and change management processes.
Create and maintain technical documentation, SOPs, troubleshooting guides, and architecture diagrams.
Work with application, infrastructure, network, security, and vendor teams to resolve complex issues.
Participate in on-call / 247 production support as required.
Preferred candidate profile
Immediate Joiner
📌 Splunk Administrator Delhi
🏢 Atloen Global
📍 Delhi