Job Summary
Summary - Splunk (L3)
________________________________________________________________________________________________________
Manage SIEM Solution and Supporting Unit for HCL and its global customers
Splunk admin L3 (Over all 10+) years of work experience but minimum 8 years of relevant experience in Splunk cloud/on-prem enterprise & ES
Key Responsibilities
Certifications (must) 1) Splunk Power User 2) Splunk advance Power user 3) Splunk Admin 4) Splunk ES admin 5) Splunk Cloud admin Certifications (optional) 1) Splunk Architect 2) Splunk consultant 3) Cribl Certified Observability Engineer Stream User (CCOE Stream User) 4) Cribl Certified Observability Engineer Stream Administrator(CCOE Stream Admin) Responsibilities/Expected experience on • Resources should have extensive experience of data onboarding from different data sources like Network devices ,IDS/IPS logs, Threat intel ,Infrastructure logs (windows, Linux) ,Application logs ,Cloud based applications , SAAS based application , Database logs (SQL, ORACLE etc), proxy/web server logs ,LDAP/AD , DNS logs etc. • Worked on log aggregate tools like Syslog-ng,rsyslog,Haproxy,Nginx etc .. • Cloud ingestion - Using Splunk forwarders, Use API, Scripted, HEC, and Applications • Forwarder management • Manipulating raw data • Installing and managing applications • Experience on Splunk apps/add-on , how these can be used to onboard data or for CIM compatibility • E
Skill Requirements
Certifications (must) 1) Splunk Power User 2) Splunk advance Power user 3) Splunk Admin 4) Splunk ES admin 5) Splunk Cloud admin Certifications (optional) 1) Splunk Architect 2) Splunk consultant 3) Cribl Certified Observability Engineer Stream User (CCOE Stream User) 4) Cribl Certified Observability Engineer Stream Administrator(CCOE Stream Admin) Responsibilities/Expected experience on • Resources should have extensive experience of data onboarding from different data sources like Network devices ,IDS/IPS logs, Threat intel ,Infrastructure logs (windows, Linux) ,Application logs ,Cloud based applications , SAAS based application , Database logs (SQL, ORACLE etc), proxy/web server logs ,LDAP/AD , DNS logs etc. • Worked on log aggregate tools like Syslog-ng,rsyslog,Haproxy,Nginx etc .. • Cloud ingestion - Using Splunk forwarders, Use API, Scripted, HEC, and Applications • Forwarder management • Manipulating raw data • Installing and managing applications • Experience on Splunk apps/add-on , how these can be used to onboard data or for CIM compatibility • Expe
Other Requirements
Educational Qualification: Bachelors and above degree in Computer Science, Information Technology, MIS, Engineering