Job Summary
Job Description : • Bachelor’s degree in Information Technology, Computer Science, or a related field, or equivalent professional experience.
The Splunk Administrator is responsible for supporting and maintaining Sompo’s Splunk Cloud environment and associated log ingestion components. This role ensures reliable data collection across diverse sources, monitors platform health and capacity, and performs ongoing administration, updates, and configuration to support security operations and analytics.
Key Responsibilities
The Splunk Administrator is responsible for supporting and maintaining Sompo’s Splunk Cloud environment and associated log ingestion components. This role ensures reliable data collection across diverse sources, monitors platform health and capacity, and performs ongoing administration, updates, and configuration to support security operations and analytics.
Skill Requirements
3–5 years of hands‑on experience administering Splunk in an enterprise environment.\r\n• Splunk Cloud and on prem Splunk infrastructure, including Heavy Forwarders, Deployment Server, and Universal Forwarders.\r\n• HTTP Event Collector (HEC).\r\n• Common Splunk Technology Add ons (TAs), including Azure, Okta, and other cloud services.\r\n• Splunk data models and data normalization practices.\r\n• Splunk features such as alert actions, SAML based authentication, KV store, and lookups.\r\n• Splunk role based access controls and permission models.\r\n• Data management features including DDAS and reindexing processes.\r\nFamiliarity with:\r\n• Azure Event Hubs, Kafka, Log Analytics Workspaces, and cloud based logging pipelines.\r\n• Windows Event Collection (WEC) and Windows Event Forwarding (WEF).\r\n
Other Requirements
• 3–5 years of hands‑on experience administering Splunk in an enterprise environment.\r\n• Splunk Cloud and on prem Splunk infrastructure, including Heavy Forwarders, Deployment Server, and Universal Forwarders.\r\n• HTTP Event Collector (HEC).\r\n• Common Splunk Technology Add ons (TAs), including Azure, Okta, and other cloud services.\r\n• Splunk data models and data normalization practices.\r\n• Splunk features such as alert actions, SAML based authentication, KV store, and lookups.\r\n• Splunk role based access controls and permission models.\r\n• Data management features including DDAS and reindexing processes.\r\nFamiliarity with:\r\n• Azure Event Hubs, Kafka, Log Analytics Workspaces, and cloud based logging pipelines.\r\n• Windows Event Collection (WEC) and Windows Event Forwarding (WEF).