Splunk Administrator L2
Location: Mumbai
Experience: 2 - 4 Years
Role Overview
We are looking for a Splunk Administrator L2 with hands-on experience in managing and supporting Splunk Enterprise environments. The role involves platform administration, troubleshooting, log onboarding, performance monitoring, security configuration, and production support.
Key Responsibilities
- Administer and support Splunk Enterprise in production environments.
- Manage Search Heads, Indexers, Forwarders, Cluster Managers, and License Managers.
- Troubleshoot data ingestion, indexing, search performance, and forwarder-related issues.
- Perform RCA and resolve incidents within defined SLA timelines.
- Onboard new log sources using Splunk Forwarders and Syslog.
- Configure and troubleshoot inputs.conf, outputs.conf, props.conf, transforms.conf, and indexes.conf.
- Manage dashboards, alerts, reports, and scheduled searches.
- Monitor Splunk health, storage utilization, indexing performance, and license consumption.
- Implement RBAC and LDAP/AD integration and follow Splunk security best practices.
- Support upgrades, patching, migrations, and disaster recovery activities.
- Automate operational tasks using Python, Bash/Shell,
or PowerShell.
- Work with SOC, Infrastructure, Application, Network, and Security teams.
- Maintain SOPs, troubleshooting guides, and operational documentation.
Required Skills
- 24 years of hands-on Splunk Administration experience.
- Strong knowledge of Splunk Enterprise and Splunk Enterprise Security (ES).
- Valuable understanding of Splunk distributed architecture and clustering.
- Strong knowledge of SPL and experience with log onboarding, parsing, and field extraction.
- Experience with Linux/Unix administration.
- Understanding of SIEM, SOC operations, and security monitoring.
- Basic knowledge of TCP/IP, DNS, Syslog, SSL/TLS, and REST APIs.
- Scripting experience in Python, Bash/Shell, or PowerShell.
- Strong troubleshooting, RCA, and production support skills.
Preferred
- Splunk Enterprise Certified Admin certification.
- Experience with Indexer Clustering, Search Head Clustering, Deployment Server, and Cluster Manager.
- Experience supporting Splunk upgrades, migrations, and DR activities.
Please share your cv to
[email protected]
📌 Splunk Administrator (Mumbai)
🏢 Shi
📍 Mumbai