Key Responsibilities
- Administer and support Splunk Enterprise infrastructure, including Indexer Clusters, Search Head Clusters, and Forwarders.
- Perform Linux/Unix system administration, patching, SSL management, firewall rules, routing, and capacity planning.
- Onboard data using Syslog, Universal Forwarder (UF), HTTP Event Collector (HEC), DB Connect, and custom scripts.
- Monitor, troubleshoot, and optimize Splunk performance, indexing, search, and infrastructure health.
- Integrate Splunk with third-party APIs and enterprise tools.
- Develop automation scripts using Python, Shell, PowerShell, Bash, SQL, Java, or Perl.
- Perform root cause analysis and implement tactical and strategic solutions.
- Lead and mentor technical team members while supporting production incidents, including after-hours P1 issues.
Required Skills
- Strong experience with Splunk Administration and Linux/Unix system administration.
- Experience with Windows Server, Red Hat, CentOS, and Unix environments.
- Knowledge of Splunk Data Models, data normalization, and data onboarding.
- Understanding of infrastructure, networking, storage, databases, automation, and performance tuning.
- Experience with AWS, Azure, or IBM Cloud.
- Excellent troubleshooting, communication, and documentation skills.