20 Sep
|
SHI Solutions India
|
Mumbai
20 Sep
SHI Solutions India
Mumbai
Company: SHI Locuz Company,India
nJob Title: Splunk Administrator
nSkills :: Splunk Enterprise, Splunk Administration, Splunk Enterprise Security (ES), Distributed Architecture, Search Head, Indexer, Forwarder, Cluster Manager, License Manager, SPL, Linux/Unix, Log Onboarding, Log Ingestion, Syslog, Parsing, Field Extraction, SIEM, SOC, TCP/IP, DNS, SSL/TLS, Python/Bash/PowerShell
n
nExperience: 2+ Years
nLevel: L2
nJoining: Immediate to 15 Days
nMode of Interview :: Virtual
n
nPlease find below given JD.
n
nPosition : Splunk Administrator
nLevel: L2
nLocation : Mumbai
n
nKey Responsibilities
n
n
- Administer and support Splunk Enterprise infrastructure in production environments.
n
- Manage and monitor Search Heads, Indexers, Forwarders, Cluster Managers, and License Managers.
n
- Troubleshoot data ingestion, indexing, search performance, and forwarder-related issues.
n
- Perform root cause analysis (RCA) and resolve incidents within SLA timelines.
n
- Onboard current log sources and configure data collection using Splunk Forwarders and Syslog.
n
- Manage Splunk configurations including inputs.conf, props.conf, transforms.conf, and outputs.conf.
n
- Monitor platform health, storage utilisation, indexing performance, and licence consumption.
n
- Configure and maintain dashboards, alerts, reports, and scheduled searches.
n
- Implement and manage RBAC, LDAP/AD integration, and Splunk security best practices.
n
- Support Splunk upgrades, patching, migrations, and disaster recovery activities.
n
- Automate operational tasks using Shell scripting, Python, or PowerShell.
n
- Work closely with SOC, Infrastructure, Application, and Security teams for platform support.
n
- Maintain operational documentation, SOPs, and troubleshooting runbooks.
n
- Ensure high availability, performance optimisation, and compliance with organisational standards.
n
nRequired Skills
n
n
- Hands-on experience with Splunk Enterprise and Enterprise Security Administration.
n
- Strong understanding of Splunk distributed architecture and clustering.
n
- Experience with Linux/Unix administration.
n
- Knowledge of SPL (Search Processing Language).
n
- Experience in log onboarding, parsing, and field extractions.
n
- Understanding of SIEM, SOC operations, and security monitoring.
n
- Basic networking knowledge (TCP/IP, DNS, Syslog, SSL/TLS, APIs).
n
- Scripting experience in Python, Bash, or PowerShell.
n
nExperience
n
n
- 2-4 years of hands-on Splunk Administration experience.
n
- Splunk Enterprise Certified Admin certification preferred.
n
n
📌 Splunk Administration (Mumbai)
🏢 SHI Solutions India
📍 Mumbai