Skip to main content
Posted 06 August, 2026

Splunk SME

NR Consulting
Chennai,Tamil Nadu Full Time
Reference: 365_463738_26-22477

Title: Splunk SME
Location: Chennai
Exp: 5+ Years

Job Description:

Key Responsibilities

  • Design, implement, administer, and optimize Splunk Enterprise and Splunk Enterprise Security (ES) environments.
  • Develop and maintain dashboards, reports, alerts, and visualizations using SPL (Search Processing Language).
  • Integrate logs from various sources, including servers, network devices, cloud platforms, applications, and security tools.
  • Build and maintain correlation searches, notable events, and detection use cases for security monitoring.
  • Monitor system performance, troubleshoot issues, and optimize Splunk indexing and search efficiency.
  • Support incident investigation, root cause analysis, and threat detection activities.
  • Configure data onboarding, parsing, indexing, forwarding, and retention policies.
  • Work closely with SOC, infrastructure, and application teams to enhance monitoring and security visibility.
  • Perform platform upgrades, patching, and capacity planning.
  • Prepare technical documentation, operational procedures, and knowledge base articles.

Required Skills

  • 5+ years of hands-on experience with Splunk Enterprise administration and engineering.
  • Strong expertise in Splunk Enterprise Security (ES) and SIEM implementations.
  • Advanced knowledge of SPL (Search Processing Language).
  • Experience integrating Windows, Linux, network, cloud, and application logs.
  • Familiarity with cybersecurity concepts, threat detection, MITRE Telecommunication&CK, and incident response.
  • Experience with Universal Forwarders, Indexers, Search Heads, Deployment Server, and Cluster Management.
  • Knowledge of scripting (Python, Shell, or PowerShell) for automation is an added advantage.
  • Excellent troubleshooting, analytical, and communication skills.

Preferred Qualifications

  • Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security Certified Admin.
  • Experience with cloud platforms (AWS, Azure, or GCP) and security tools is preferred.

Sign up for Job Alerts