Sr Splunk Admin
CurrentResponsibilites :• Designed Splunk Enterprise 6.5, 7.0,7.1 & v8 infrastructure to provide high availability by configuring clusters across two different data centers.• Create documentation on build, deployment, and sustainment processes and procedures for application use in cloud capable datacenter• Installed, Configured, Maintained, Tuned and Supported Splunk Enterprise serverv8,7.x/6.x/5.x.• Performed Field Extractions and Transformations using the RegEx in Splunk.• Monitor and support services with a variety of services such as Splunk (ES, UBA, ITSI & ITOA), SCOM & OMS 2016, SCCM, AppDynamics, ExtraHop and other proprietary systems• Responsible for Installing, configured and administered Splunk Enterprise on Linux and Windows servers.• Supported the upgradation of Splunk Enterprise server and Splunk Universal Forwarder from 6.5 to 6.6.• Installation and implementation of the Splunk App for Enterprise Security and documented best practices for the installation and performed knowledge transfer on the process.• Responsible for creating/versioning/testing of scripts (Bash, PowerShell), AWS Cloud Formation templates, Chef, Nagios, Maven/Ant, Git, Jenkins, Perl, and Ruby to achieve a high-level of automation• Minimum 3 years of experience using Splunk in a 24x7 environment• Analysed the 22 reports to determine the conversion of the reports either using FID tables and views or using Free Form SQL.• Operate, develop for, and maintain the Splunk log management infrastructure, leverage knowledge on a number of security technologies, information security, and networking