Job Summary
Splunk L3 Engineer / Architect – Job Description
- 7+ years of hands-on experience in administering and architecting enterprise-scale Splunk environments.
- 24x7 Open shift
Key Responsibilities
Splunk L3 Engineer / Architect – Job Description
- 7+ years of hands-on experience in administering and architecting enterprise-scale Splunk environments.
- Strong expertise in Splunk architecture, including Indexer Clusters, Search Head Clusters, Cluster Manager, Deployment Server, License Manager, Heavy Forwarders, and Universal Forwarders.
- Lead end-to-end onboarding of log sources from Windows, Linux, Unix, Cloud platforms, Databases, APIs, Syslog, HEC, DB Connect, and custom integrations.
- Design and implement scalable, highly available, and resilient Splunk architectures aligned with business and security requirements.
- Expertise in troubleshooting log ingestion, parsing, indexing, search performance, and data latency issues across distributed Splunk environments.
- Strong knowledge of props.conf, transforms.conf, field extractions, CIM compliance, data normalization, and knowledge object management.
- Perform Splunk platform upgrades, migrations, patching, and health assessments following best practices.
- Develop and optimize SPL queries, dashboards, alerts, reports, and correlation searches for operational and security use cases.
- Analyze and resolve complex production issues, conduct RCA, and collaborate with application, infrastructure, and vendor teams for problem resolution.
- Manage index lifecycle, data retention policies, storage planning, bucket management, RF/SF configuration, and license utilization optimization.
- Implement and maintain security controls including RBAC, SSO, LDAP/SAML integration, certificates, and platform hardening.
- Automate Splunk administration and operational activities using Python, Shell, PowerShell, or REST APIs.
- Provide technical leadership, architectural guidance, and mentorship to L1/L2 engineers and project teams.
- Collaborate with stakeholders to understand monitoring and observability requirements and translate them into Splunk solutions.
- Maintain operational documentation, onboarding standards, runbooks, troubleshooting guides, and architecture diagrams to support governance and knowledge management.
Skill Requirements
Preferred Certifications
- Splunk Enterprise Certified Architect
- Splunk Enterprise Certified Admin
- Splunk Core Certified Power User
Other Requirements
Mandatory Skills
Splunk Architecture | Log Onboarding | SPL | Indexer Clustering | Search Head Clustering | HEC | DB Connect | Syslog | Linux | Python/Shell Scripting | Troubleshooting | Performance Tuning | Splunk Upgrades | Observability