CareerPlanSign in

Splunk Data Administrator

Melbourne, Victoria💼 Full-time🗓 2026-09-23 → 2026-09-26

Core

Own and continuously improve Splunk data onboarding, normalization, and quality across a complex hybrid Splunk environment (on-prem and cloud) to ensure logs are usable for security/IT operations, dashboards, and reporting.

Role type

Mid–Senior Splunk Data Administrator

Builds

Normalized, CIM-aligned log data pipelines for security and IT operations

Domain

Security Information and Event Management (SIEM) / Log Management

Deliverable

production ML models | product features | dashboards & analysis | infrastructure

Required skills

Splunk data onboarding, CIM normalization, field extraction (regex/props/transforms), TA deployment, hybrid architecture operations, pipeline troubleshooting, governance

Preferred skills

Splunk Enterprise Security (ES), Ingest Actions/Edge Processor, HEC/API ingestion, ITSI/Observability

Technologies

Splunk Enterprise, Splunk Cloud, Heavy Forwarders, Universal Forwarders, Indexers, Search Heads, Deployment Server, props.conf, transforms.conf, SPL, Syslog, HEC, AWS, Azure, GCP

Responsibilities

Lead end-to-end onboarding of new log sources including requirements gathering, parsing strategy, and release; Normalize data to Splunk Common Information Model (CIM); Design and implement field extractions and enrichment; Install, configure, and maintain Splunk Add-ons across hybrid environments; Monitor ingestion health and pipeline performance; Maintain governance for indexes, sourcetypes, and data access.

Seniority

Mid–Senior, hands-on IC

Sourced via viewjobs · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.