DL
Splunk Admin
Diverse Lynx India
🇮🇳 India
On-site
4 weeks ago
- Splunk
- Linux
- Python
- Ansible
- Disaster Recovery
- Windows
4 weeks ago
Experience: 3–8 Years
Location: Delhi (GG5 - Gurugram only)
Job Requirements:
• Splunk Architecture & Administration
• Splunk components: Forwarder, Indexer, Search Head, Deployment Server.
• Splunk clustered architecture.
• Data flow from source to dashboard.
• Index management and retention policies.
• Licensing and license violation handling. Splunk Operations
• New data source onboarding process.
• Universal Forwarder deployment methods.
• Monitoring Splunk health and performance.
• Splunk upgrade and patching strategy. SPL (Search Processing Language)
• Writing basic and advanced SPL queries.
• Use of stats, chart, time chart, eval, lookup commands.
• Query optimization techniques.
• Creating reports, dashboards, and alerts.
• Troubleshooting slow searches. Troubleshooting & Support
• Logs not reaching Splunk.
• High CPU or memory utilization on indexers.
• Missing events in searches.
• Search Head synchronization issues.
• Troubleshooting indexing delays. Linux Administration
• File permissions and ownership.
• Log analysis using Linux commands.
• Process and service management.
• Shell scripting basics. Performance Tuning Index optimization.
• Search performance tuning.
• Capacity planning. Good to have Python/Shell scripting for automation.
• Hands-on experience on Ansible.
Key Responsibilities:
• Manage Splunk components including Search Heads, Indexers, Forwarders, Deployment Server and Cluster Manager.
• Monitor system health, performance, and license utilization.
• Create and maintain indexes, source types, and data inputs.
• Develop dashboards, reports, alerts, and searches to support operational and security requirements.
• Perform Splunk upgrades, patching, backup, and disaster recovery activities. Troubleshoot data ingestion, search performance, and infrastructure issues.
• Work with Windows, Linux, network, and security teams to onboard data sources and ensure log availability.
• Maintain technical documentation, standards, and operational procedures.
Job Qualifications & Skills
Section Details / Example Content
• Domain IT Infrastructure Operations / Observability / Log Management
• Soft Skills - Excellent communication - Team collaboration - Documentation and knowledge sharing - Ability to work independently in remote support setups
• Education Requirements BTech/BE/MCA
• Certifications Optional (Splunk Enterprise Certified Admin preferred).
Topic of Evaluation:
• Splunk Administration Mandatory 30%
• SPL Query Skills Mandatory 20%
• Troubleshooting Mandatory 30%
• Linux Skills Mandatory 15%
• Automation Mandatory 5%
Sample Questions for Training Model
Technical Questions
1. Difference between Heavy Forwarder and Universal Forwarder?
2. How do you reduce Splunk license consumption?
3. What are buckets in Splunk?
4. Explain Indexer Clustering.
5. How do you troubleshoot data ingestion issues?
6. What are props.conf and transforms.conf?
7. How do you optimize a slow SPL query?
8. What is a data model in Splunk?
9. Explain Search Head Clustering.
10. How do you secure a Splunk deployment?
Scenario-Based Questions 1. What would you do if license usage suddenly doubled?
2. How would you design a highly available Splunk environment?
3. How would you investigate a security incident using Splunk?
4. How would you onboard 500 servers into Splunk? 5. A dashboard that previously loaded in 5 seconds now takes over 2 minutes. What would you investigate? 6. One indexer consistently runs at 95% CPU while others are at 30%.
Splunk Admin · Diverse Lynx India