Must-Have
- Positive communication skill
- Responsible for log onboarding and alert monitoring setup in Splunk Cloud
- Daily indexing volume must be minimum of 100 GB and more.
- Involved various Splunk components:
- **Forwarders**: Collected data from various sources.
- **Indexers**: Indexed incoming data and managed data storage.
- **Search Heads**: Distributed search requests to indexers.
- **Deployment Server**: Managed configurations and app deployments.
- **Cluster Master**: Managed replication and data redundancy.
- **License Manager**: Tracked daily indexing volume for compliance.
- Focused on configuration tasks:
- Managed index.conf, including index name, home path, cold path, and frozen path.
- Defined storage locations and retention policies for data.
- Worked on settings related to:
- Data archiving and retention limits.
- Replication settings for data redundancy.
- Worked on Splunk enterprise security is a security information and event management (SIEM) tool.
- Involves setting up collaboration searches and alerts to monitor suspicious activities.
- Must have worked on CIM (Common Information Model) framework
- Worked on normalize data in Splunk.
- Exposure to security and provides common structure and field names.
- The model helps in the standardization of data across different sources.
- Must have Regex skills
- Responsible for maintaining the current customer managed Splunk infrastructure
- Responsible for log onboarding and alert monitoring setup in Splunk
- Responsible for Offloading logs involves searching, archiving, exporting, and deleting.
- Responsible for identifying opportunities to enhance the current baseline processes and configuration.
- Responsible for monitoring the health of the customer managed asset and vendor managed Splunk infrastructure configuration
- Assist with any common and complex user issues of both technical and process