Experience in both On-Prem & SaaS design, implementation, and support of Splunk (Indexers, Forwarders, Search-Heads Setup etc.)
- Experience with implementing and administering Splunk.
- Experience in SPLUNK core/ITSI implementation preferably in service provider network with strong UNIX/Windows knowledge.
• Hands on multi-site cluster and all Splunk components.
• Hands all sorts of log onboardings techniques in Splunk like (Monitoring, DB connect, HEC, Syslog & Rest API) for ITSI Analysis.
• Support large-scale deployments with data feeds from multiple tier deployment on premise data centers.
• Develop reliable, efficient queries that will feed custom alerts, Dashboards, Macros and all kind of knowledge objects
• Develop new Splunk Heavy Forwarders based on requirements by following standard procedure.
• Expertise in data onboarding flow Inputs(inputs.conf), Parsing (Props & transforms), Indexing (indexes.conf) and Searching (Props & transforms)
• Expertise in data summary creations (Summary Index, Report acceleration and Data model acceleration), extensively used most of knowledge objects & components in Splunk, implemented best practices in platform.
• Fluent with Linux OS, including knowledge of applications such as rsyslog / syslogng / net-snmp
• Understand logging methods such as syslog / SNMP
• Knowledge on scripts (python, JavaScript, etc.) as needed in support of data collection or integration
• Hands on AWS platforms (Needs to create EC2 instance and integrate all type (cloud watch, description, kinesis) of logs into Splunk)
Nice to have: • Splunk Admin Certification
• Experience with databases.
• Familiarity with server-side scripting
• Has a broad experience from either a development or operations perspective
• Expert understanding in data analytics, Hadoop, MapReduce, visualization is a plus
• Experience working in a software engineering environment is a plus
• Drive complex deployments of Splunk dashboards and reports while working side by side with the customers to solve their unique problems across a variety of use cases
• Assist internal users of Splunk in designing and maintaining production-quality dashboards.