We are seeking a skilled Splunk Engineer to join our team. The primary focus will be on deploying, managing, and optimizing Splunk Enterprise for comprehensive log management, monitoring, and observability. You will play a critical role in ensuring the reliability, scalability, and efficiency of our on-premises Splunk infrastructure, supporting IT operations, and driving actionable insights from machine data.
Key Responsibilities
- Deploy, configure, and maintain Splunk Enterprise in an on-premises environment
- Manage Search Heads, Indexers, and Indexer Storage, ensuring high availability and data integrity
- Oversee data collection using Universal and Heavy Forwarders; troubleshoot and optimize data onboarding
- Administer and monitor Splunk license usage, License Managers, and Cluster Managers
- Develop, optimize, and maintain Splunk search queries, dashboards, and alerts for operational and observability use cases
- Collaborate with IT, network, and security teams to integrate diverse log sources and improve monitoring capabilities
- Implement best practices for Splunk architecture, data retention, and search performance
- Perform regular system health checks, upgrades, and patch management
- Document configurations, processes, and changes for operational transparency and knowledge sharing
- Provide onsite technical support and training for end-users and stakeholders
Required Skills & Experience
- Proven hands-on experience with Splunk Enterprise in on-premises environments
- Deep understanding of Splunk Search Management, Search Heads, Indexers, and Indexer Storage
- Experience configuring and managing Universal and Heavy Forwarders
- Familiarity with Splunk License Manager and Cluster Manager roles and operations
- Strong expertise in developing and optimizing Splunk searches, reports, and dashboards
- Solid understanding of IT operations, monitoring, and log management best practices
- Proficiency in troubleshooting Splunk components and system integrations
- Excellent communication and documentation skills
- Ability to work independently and as part of a cross-functional team
Preferred Qualifications
- Splunk Certified Admin or Architect certification(s)
- Experience with IT operations monitoring and observability solutions
- Scripting skills (e.g., Python, Bash) for automation and integration
- Familiarity with regulatory and compliance frameworks related to log management
- Bachelor's degree in an IT-related field