Principal Engineer
CurrentI am working in helping select and architect a SIEM system. I took the client through an extensive evaluation process and Splunk was chosen as the choice system. As I have extensive experience with this product, I did building the Splunk core product along with Splunk Enterprise Security. This has involved the following:Evaluating and designing the underlying architectureInstalling the Splunk software in line with best practiceEvaluating ingestion points and data sourcesOn-boarding dataConfiguring dashboards and alertingDeploying and managing universal forwarders to the estateDeployment of custom apps with transforms and props, CIMTraining SoC operative to use the systemSupport and administration of the platform