Splunk Database Administrator
Whizdom ·whizdom.shazamme.com
Apply direct
Splunk Data Administrator
π Melbourne VIC
β³ 6+ Month Contract
π° Competitive Daily Rate
About the Role
We are working with a global consulting organisation delivering large-scale programs across government and enterprise environments. They are seeking a mid to senior Splunk Data Administrator to take ownership of data onboarding, normalization, and overall data quality across a complex hybrid Splunk environment (on-premise and cloud).
This is a hands-on role suited to someone who thrives in complex environments and enjoys working across the full data lifecycle, from ingestion through to optimisation and governance.
Key Responsibilities
π 0480 002 456
βοΈ dylans@whizdom.com.au
π Melbourne VIC
β³ 6+ Month Contract
π° Competitive Daily Rate
About the Role
We are working with a global consulting organisation delivering large-scale programs across government and enterprise environments. They are seeking a mid to senior Splunk Data Administrator to take ownership of data onboarding, normalization, and overall data quality across a complex hybrid Splunk environment (on-premise and cloud).
This is a hands-on role suited to someone who thrives in complex environments and enjoys working across the full data lifecycle, from ingestion through to optimisation and governance.
Key Responsibilities
- Lead end-to-end onboarding of log sources, including requirements gathering, parsing, testing, and deployment
- Drive CIM normalization and ensure alignment with Splunk data models to support security and operational use cases
- Design and implement field extractions using regex, props.conf, transforms.conf, and structured parsing techniques
- Manage and optimise Splunk data pipelines across hybrid environments, ensuring performance, reliability, and data quality
- Configure and maintain Splunk components including Search Heads, Indexers, forwarders, and deployment infrastructure
- Monitor ingestion performance, troubleshoot issues, and implement best practices for data governance and lifecycle management
- 5β10 yearsβ experience in Splunk administration and data onboarding
- Strong expertise in:
- CIM normalization, data modelling, and SPL validation
- Field extraction, parsing, and sourcetype configuration
- Splunk architecture including Search Heads, Indexers, clusters, and forwarders
- Experience working in complex or hybrid Splunk environments (on-premise and cloud)
- Knowledge of Linux environments (RHEL, Amazon Linux)
- Exposure to AWS services such as EC2, S3, IAM, and CloudWatch is highly regarded
- Experience with automation tools such as Ansible, Terraform, or CI/CD pipelines is advantageous
- Splunk certifications (Admin, Power User, ES Admin)
- Experience with Splunk Enterprise Security (ES)
- Familiarity with modern ingestion methods such as HEC, APIs, or cloud-native logging tools
- Based in Melbourne or willing to relocate
- Australian working rights required
- Open to Working Holiday Visa holders
- No local experience required
- Opportunity to work on large-scale, enterprise Splunk environments
- Exposure to modern cloud and hybrid architectures
- Supportive team environment with strong onboarding and knowledge sharing
- Ideal entry point into the Australian market with a global employer
π 0480 002 456
βοΈ dylans@whizdom.com.au
Frequently asked questions
Who is hiring for the Splunk Database Administrator role?
Whizdom is hiring for the Splunk Database Administrator position, a Shazamme client. Apply directly on the employer's career site.
Where is the Splunk Database Administrator job located?
The Splunk Database Administrator role with Whizdom is based in Melbourne, VIC, AU. The role is hybrid-friendly.
Is the Splunk Database Administrator role remote?
Yes β the Splunk Database Administrator position at Whizdom is hybrid. Candidates based in AU are preferred.
What does the Splunk Database Administrator role pay?
Whizdom lists the Splunk Database Administrator role at AUD 68β90 per hour.
Is the Splunk Database Administrator role full-time or contract?
This is a full time position at Whizdom.
What experience level is the Splunk Database Administrator role?
The Splunk Database Administrator position is aimed at mid-level candidates.
How do I apply for the Splunk Database Administrator role at Whizdom?
Apply directly on Whizdom's career page via the Apply button on this listing. ZammeJobs links straight through to the employer's ATS β no third-party form, no resume database.