- Positive communication skill
- Responsible for log onboarding and alert monitoring setup in Splunk Cloud
- Daily indexing volume must be minimum of 100 GB and more.
- Involved various Splunk components:
- Forwarders: Collected data from various sources.
- Indexers: Indexed incoming data and managed data storage.
- Search Heads: Distributed search requests to indexers.
- Deployment Server: Managed configurations and app deployments.
- Cluster Master: Managed replication and data redundancy.
- License Manager: Tracked daily indexing volume for compliance.
- Focused on configuration tasks:
- Managed `index.conf`, including index name, home path, cold path, and frozen path.
- Defined storage locations and retention policies for data.
- Worked on settings related to:
- Data archiving and retention limits.
- Replication settings for data redundancy.
- Worked on Splunk enterprise security is a security information and event management (SIEM) tool.
- Involves setting up collaboration searches and alerts to monitor suspicious activities.
- Must have worked on CIM (Common Information Model) framework
- Worked on normalize data in Splunk.
- Exposure to security and provides common structure and field names.
- The model helps in the standardization of data across different sources.
- Must have Regex skills
- Responsible for maintaining the current customer managed Splunk infrastructure
- Responsible for log onboarding and alert monitoring setup in Splunk
- Responsible for Offloading logs involves searching, archiving, exporting, and deleting.
- Responsible for identifying opportunities to enhance the current baseline processes and configuration.
- Responsible for monitoring the health of the customer managed asset and vendor managed Splunk infrastructure configuration
- Assist with any common and complex user issues of both technical and process nature.
- Verify operational effects of any changes on existing Splunk deployments.
- Develop SOP documents on processes associated with tasks identified under BAU.
- Manage the Incident and Service Request under the assignment group for Splunk support.
- Perform the regular health check of the application and report any discrepancies.
- Support and manage existing data sources.
- Provide timely resolution to any data forwarding, Search head, indexing or parsing related request.
- Application/platform log source types onboarding (S/M/L efforts)
- Application/platform log source types onboarding maintenance activity
- Operation alert creation and maintenance
- Validating existing monitoring metrics and work with support team to fine tune parameters and alerting.
- Provide support for user management activities (onboarding - offboarding users).
- Analysis and improvement of configuration of data collection and data
- Perform detailed evaluation of Information Systems audit and security log requirements.