Splunk Data Administrator
Core
Own and continuously improve Splunk data onboarding, normalization, and quality across a complex hybrid Splunk environment (on-prem and cloud) to ensure logs are usable for security/IT operations, dashboards, and reporting.
Role type
Mid–Senior Splunk Data Administrator
Builds
Normalized, CIM-aligned log data pipelines for security and IT operations
Domain
Security Information and Event Management (SIEM) / Log Management
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Splunk data onboarding, CIM normalization, field extraction (regex/props/transforms), TA deployment, hybrid architecture operations, pipeline troubleshooting, governance
Preferred skills
Splunk Enterprise Security (ES), Ingest Actions/Edge Processor, HEC/API ingestion, ITSI/Observability
Technologies
Splunk Enterprise, Splunk Cloud, Heavy Forwarders, Universal Forwarders, Indexers, Search Heads, Deployment Server, props.conf, transforms.conf, SPL, Syslog, HEC, AWS, Azure, GCP
Responsibilities
Lead end-to-end onboarding of new log sources including requirements gathering, parsing strategy, and release; Normalize data to Splunk Common Information Model (CIM); Design and implement field extractions and enrichment; Install, configure, and maintain Splunk Add-ons across hybrid environments; Monitor ingestion health and pipeline performance; Maintain governance for indexes, sourcetypes, and data access.
Seniority
Mid–Senior, hands-on IC