20 Sep
|
SHI Solutions India
|
Mumbai
20 Sep
SHI Solutions India
Mumbai
Company: SHI Locuz Company,India
Job Title: Splunk Administrator
Skills :: Splunk Enterprise, Splunk Administration, Splunk Enterprise Security (ES), Distributed Architecture, Search Head, Indexer, Forwarder, Cluster Manager, License Manager, SPL, Linux/Unix, Log Onboarding, Log Ingestion, Syslog, Parsing, Field Extraction, SIEM, SOC, TCP/IP, DNS, SSL/TLS, Python/Bash/PowerShell
Experience: 2+ Years
Level: L2
Joining: Immediate to 15 Days
Mode of Interview :: Virtual
Please find below given JD.
Position : Splunk Administrator
Level: L2
Location : Mumbai
Key Responsibilities
Administer and support Splunk Enterprise infrastructure in production environments.
Manage and monitor Search Heads, Indexers, Forwarders, Cluster Managers, and License Managers.
Troubleshoot data ingestion, indexing, search performance, and forwarder-related issues.
Perform root cause analysis (RCA) and resolve incidents within SLA timelines.
Onboard current log sources and configure data collection using Splunk Forwarders and Syslog.
Manage Splunk configurations including inputs.conf, props.conf, transforms.conf, and outputs.conf.
Monitor platform health, storage utilisation, indexing performance, and licence consumption.
Configure and maintain dashboards, alerts, reports,
and scheduled searches.
Implement and manage RBAC, LDAP/AD integration, and Splunk security best practices.
Support Splunk upgrades, patching, migrations, and disaster recovery activities.
Automate operational tasks using Shell scripting, Python, or PowerShell.
Work closely with SOC, Infrastructure, Application, and Security teams for platform support.
Maintain operational documentation, SOPs, and troubleshooting runbooks.
Ensure high availability, performance optimisation, and compliance with organisational standards.
Required Skills
Hands-on experience with Splunk Enterprise and Enterprise Security Administration.
Strong understanding of Splunk distributed architecture and clustering.
Experience with Linux/Unix administration.
Knowledge of SPL (Search Processing Language).
Experience in log onboarding, parsing, and field extractions.
Understanding of SIEM, SOC operations, and security monitoring.
Basic networking knowledge (TCP/IP, DNS, Syslog, SSL/TLS, APIs).
Scripting experience in Python, Bash, or PowerShell.
Experience
2-4 years of hands-on Splunk Administration experience.
Splunk Enterprise Certified Admin certification preferred.
📌 Splunk Administration (Mumbai)
🏢 SHI Solutions India
📍 Mumbai