22 Aug
|
Tekskills
|
Chennai
Job Title: Splunk Architect
Work Location: CHENNAI, HYDERABAD
Skill Required: Splunk
Experience: 6-8 years
:
- Should be Splunk admin certified and Enterprise Splunk architect certification.
- Performing hands-on architecture, design, and development of systems in both managed & SaaS environments. Developed Splunk infrastructure and related solutions.
- Standardize and implement Splunk Universal Forwarder deployment, configuration and maintenance in Linux and Windows platforms
- Maintain, Manage and Monitor Splunk Infrastructure (Identify bad searches, dashboards and health of Splunk)
- Used User Behaviour Analytic to parse data into Splunk and detect anomalies in true positive events
- Used SNMP (Straightforward network management protocol) to monitor the application on the server
- Using Splunk Enterprise to perform data mining and analysis, utilizing various queries and reporting methods
- Analyzing and monitoring security-related technologies including host-based firewalls, host-based using IDS, LDP server configuration controls, logging, SIEM, monitoring tools, antivirus systems.
- Actively hunt for and dissect previously unidentified threats and differentiate between potential intrusion attempts and false alarms
- Monitor and detecting security use cases on Splunk e.g. SQL Injection, SQL Map, Burp-suit intruder
- Using Splunk Phantom Security Orchestration, Automation, and Response (SOAR)
system to evaluate notable event for correlation alert
- Develop alerts and timed reports Develop and manage Splunk applications
- Performed Splunk knowledge objects e.g. Configuration, Uploading data, field extraction, validation of boarded data, REGEX search, event parsing, and data transformation
- Use Splunk GUI development creating Splunk apps, searches, Data models, dashboards, and Reports using the Splunk query language.
- Perform index administration, maintenance and optimization and create data retention
- Create Splunk Applications, Splunk Dashboard and Visualizations.
- Expertise in scripting (PowerShell, Python, .net), CI/CD pipelines, Integrations with other tools
- Expertise in Splunk SPL (Search processing Language)
- Manage and troubleshoot Splunk accounts (create, delete, modify, etc.)
- Transfer Splunk log file in Json format to Elastic search
- Support Splunk on UNIX, Linux and Windows-based platforms. Assist with automation of processes and procedures
- Provided different method to install search head, forwarder and deployment servers and troubleshoot at the back end
- Implementing and maintaining Splunk infrastructure and configurations in a single environment and in a clustered environment
- Sound knowledge of Senior Architect role and Agile Methodologies
- Sound Knowledge of Splunk ITSI
📌 Splunk Architect (Chennai)
🏢 Tekskills
📍 Chennai