1. Solid knowledge of SPL (Search Processing Language).
2. Strong knowledge on IRs and Notables of SIEM and ITSI
3. Experience with onboarding data from various sources (syslog, APIs, cloud services, etc.).
4. Proficiency in scripting languages (Python, Bash, PowerShell).
5. Familiarity with DevOps tools (Git, Jenkins, Ansible, Terraform).
6. Should have good troubleshooting experience.
Positive-to-Have
Splunk certifications and Experience with Cribl and AppDynamics