We are seeking an experienced Splunk Engineer with 5–7 years of hands-on expertise in managing and optimizing Splunk Enterprise or Cloud environments. This role involves developing and maintaining Splunk apps / add-ons, enhancing system performance, and supporting advanced log management and security monitoring initiatives within distributed environments.
Requirements and Qualifications :
- 5–7 years of hands-on experience with Splunk Enterprise / Cloud.
- Deep understanding of Splunk CIM Data Models, field extractions, lookups, and data model acceleration.
- Strong knowledge of SPL (Search Processing Language) and data normalization best practices.
- Expertise in Python scripting for automation, data processing, and Splunk REST API usage.
- Experience with Splunk apps / add-ons (TA development) and technology integrations.
- Familiarity with log management, SIEM practices, and security monitoring.
- Strong troubleshooting and performance tuning skills in distributed environments.
Nice to Have
Splunk certifications (Certified Developer, Power User, Architect).Experience with Security Use Cases (SIEM, UEBA, Threat Detection).Knowledge of Docker, Kubernetes, or containerized Splunk deployments.