18 Sep
|
SHI Solutions India
|
Mumbai
18 Sep
SHI Solutions India
Mumbai
Company: SHI Locuz Company,India
Job Title: Splunk Administrator
Skills :: Splunk Enterprise, Splunk Administration, Splunk Enterprise Security (ES), Distributed Architecture, Search Head, Indexer, Forwarder, Cluster Manager, License Manager, SPL, Linux/Unix, Log Onboarding, Log Ingestion, Syslog, Parsing, Field Extraction, SIEM, SOC, TCP/IP, DNS, SSL/TLS, Python/Bash/PowerShell
Experience: 2+ Years
Level: L2
Joining: Immediate to 15 Days
Mode of Interview :: Virtual
Please find below given JD.
Position : Splunk Administrator
Level: L2
Location : Mumbai
Key Responsibilities
- Administer and support Splunk Enterprise infrastructure in production environments.
- Manage and monitor Search Heads, Indexers, Forwarders, Cluster Managers, and License Managers.
- Troubleshoot data ingestion, indexing, search performance, and forwarder-related issues.
- Perform root cause analysis (RCA) and resolve incidents within SLA timelines.
- Onboard current log sources and configure data collection using Splunk Forwarders and Syslog.
- Manage Splunk configurations including inputs.conf, props.conf, transforms.conf, and outputs.conf.
- Monitor platform health, storage utilisation, indexing performance, and licence consumption.
- Configure and maintain dashboards, alerts, reports, and scheduled searches.
- Implement and manage RBAC, LDAP/AD integration, and Splunk security best practices.
- Support Splunk upgrades, patching, migrations, and disaster recovery activities.
- Automate operational tasks using Shell scripting, Python, or PowerShell.
- Work closely with SOC, Infrastructure, Application, and Security teams for platform support.
- Maintain operational documentation, SOPs, and troubleshooting runbooks.
- Ensure high availability, performance optimisation, and compliance with organisational standards.
Required Skills
- Hands-on experience with Splunk Enterprise and Enterprise Security Administration.
- Strong understanding of Splunk distributed architecture and clustering.
- Experience with Linux/Unix administration.
- Knowledge of SPL (Search Processing Language).
- Experience in log onboarding, parsing, and field extractions.
- Understanding of SIEM, SOC operations, and security monitoring.
- Basic networking knowledge (TCP/IP, DNS, Syslog, SSL/TLS, APIs).
- Scripting experience in Python, Bash, or PowerShell.
Experience
- 2-4 years of hands-on Splunk Administration experience.
- Splunk Enterprise Certified Admin certification preferred.
📌 Splunk Administration (Mumbai)
🏢 SHI Solutions India
📍 Mumbai