Senior Splunk Engineer/admin Resume
Lexington, KY
SUMMARY:
- 7+ years of extensive experience years inSplunk, Linux/UNIX, PLSQL, SQL DBA. Monitoring, Data Analytics performance tuning Troubleshooting and Maintenance of Data Base.
- Creating accurate reports, Dashboards, Visualizations and Pivot tables for the business users.
- Experience withSplunkSearching & Reporting modules, Knowledge Objects, Administration, Add - On's, Dashboards, Clustering and Forwarder Management.
- Created and ManagedSplunkDB connect Identities, Database Connections, Database Inputs, Outputs, lookups, access controls.
- Expertise in Installation, Configuration, Migration, Trouble-Shooting and Maintenance ofSplunk, Passionate about Machine data and operational Intelligence.
- Experienced on Integrating Splunk with Windows Active Directory and LDAP.
- Installing and usingSplunk apps for UNIX and Linux (Splunknix).
- Extensive experience and actively involved in Requirements gathering, Analysis, Reviews.
- Expertise in Actuate Reporting, development, deployment, management and performance tuning of Actuate reports.
- Implemented workflow actions to drive troubleshooting across multiple event types inSplunk.
- Experience onSplunkEnterprise Deployments and enabled continuous integration on as part of configuration (props.conf, Transforms.conf, Output.confg) management.
- Experience in designating and troubleshooting the Splunk components through configurations.
- Experience withSplunkSearching and Reporting modules, Knowledge Objects, Administration, Add-On's, Dashboards, Clustering and Forwarder Management.
- Adept in log parsing, complexSplunksearches, including external table lookups.
- Experience using Splunk in 24/7 environment including Splunk Search Processing Language(SPL), splunk reporting and dashboard creation.
- Experience onSplunkdata flow, components, features and product capability.
- Experience onSplunksearch construction with ability to create well-structured search queries that minimize performance impact.
- Expert on Splunkquery language & Monitored Database Connection Health by usingSplunk DB connects health dashboards.
- Collecting detailed usage of Amazon Web servers.
- Experience withSplunk technical implementation, planning, customization, integration with big data and statistical and analytical modeling.
- InstalledSplunkDB Connect 2.0 in Single and distributed server environments and Parsing, Indexing, Searching concepts Hot, Warm, Cold, Frozen bucketing.
- Expert in usingSplunkwith shell script in creating scripts for various activities like Generating Server Status and Health reports, Deployments on large scale configuration of servers.
- Hands-on Database Design & Development experience in both Oracle and MS SQL.
- Writing PL/SQL stored procedures, functions, triggers to meet new features to be incorporated in the system to implements business rules.
- Monitored the indexes by troubleshooting any corrupt indexes by removing fragmentation from indexes.
TECHNICAL SKILLS:
Splunk Modules: Splunk 6.3, Splunk 6.2, Splunkon Splunk, Splunk Enterprise, Splunk DBConnect, Splunk Cloud, Splunk Web Framework.
Networking: TCP/IP Protocols, Socket Programming, DNS.
IDE: Force.com IDE, Eclipse 3.5, Sublime, Web Sphere Integration Developer.
Scripting: Java, Shell scripting, Perl scripting, Batch, python, JavaScript, pig, HIVE.
Operating Systems: Windows XP Pro / Vista/ ME, Windows Server 2008, Red Hat Linux 4.x/5.x/6.x.
Database: Oracle, MySQL, HDFS.
Web Services: SOAP and REST.
Server: Apache HTTP Web server, IIS, Oracle Application Server, Apache Tomcat.
PROFESSIONAL EXPERIENCE:
Confidential, Lexington, KY
Senior Splunk Engineer/Admin
Responsibilities:
- Installed, Configured and administrated Splunk Enterprise and Splunk forwarders on Windows Servers and Linux Servers.
- Created historical and real-time Dashboards, reports and alerts.
- Experience in working on Deployment Server and Deployment Client Architecture to manage the forwarders across application environment.
- Monitoring the Splunk infrastructure (Identify bad searches, dashboards and overall health of splunk) and collaborate with respective teams to improve performance.
- Worked closely with System Administration and Application Teams to create new SplunkDashboards for Operation teams.
- CreateSplunkSearch Processing Language (SPL) queries, Reports, Alerts and Dashboards.
- Created Regular Expressions for Field Extractions and Field Transformations in Splunk.
- Understanding in Splunk configuration files and its precedence.
- Created Splunk app for Enterprise Security to identify and address emerging security threats through the use of continuous monitoring, alerting and analytics.
- Implemented Search head clustering to facilitate the users to get seamless experience across search heads without interruption.
- Managing Search head cluster architecture by deplorer in order to give common apps across the cluster.
- Used techniques to optimize searches for better performance, Search time vs. Index time field extraction.
- Used Dynamic drilldown for defining custom destinations in the dashboard.
- Experience in working on Splunk Authentication methods, like LDAP Configuration, Creation of roles in Splunk.
- Created Dashboards to web application Admins to show user flow for End to End Architecture. Through which they can detect the Workflow for particular user session.
- Created Search commands like stats, chart, time chart, transaction, tables etc.
- Extracted complex Fields from different types of Log files using Regular Expressions.
- Managing the Splunk buckets by defining appropriate ageing policy across indexes in order to maintain the standard retention policy. created and managed External Lookups in Splunk to match event data with description created field aliases across application events
- Customizing simple XML using custom CSS stylesheets and Java script files.
- Reduced license costs by sending all unnecessary log events to “nullQueue” configured in props and transforms file.
- Created Shell Scripts to install Splunk Forwarders on all servers and configure with common configuration files such as Bootstrap scripts, Outputs.Conf and Inputs.Conf files.
- Extensively involved in troubleshooting the issues and document the problem resolutions for future s.
- Created Monthly Splunk Reports to the Application Team to monitor the application activity.
- Integrate Spunk Web console with Splunk Mobile App using Mobile Access server Add on.
Environment: Splunk 6.3/6.2,Splunk Enterprise Server, Universal Splunk Forwarders, RedHat Linux, HTML, Java Script, XML, Windows 2008 R2, Windows 2012 R2, Python, Regular Expressions.
Confidential, NYC
Senior Splunk Engineer/Admin
Responsibilities:
- Install, configure and administerSplunkEnterprise Server 6.0.4 andSplunkForwarder 4.x.x/5.x.x/6.x.x on Redhat Linux and Windows severs.
- SetupSplunkForwarders for new application tiers introduced into environment and existing applications.
- Experience in working on Deployment Server and Deployment Client Architecture to manage the forwarders across application environment
- Worked closely with Application Teams to create newSplunkdashboards for Operation teams.
- Troubleshooting and resolved theSplunk- performance, search poling, log monitoring issues; role mapping, dashboard creation etc.
- Established indexes and retention policy of buckets; developed user roles to complement operational and security utilization. Set-up common sourcetypes using pre-trained datasets and constructed sourcetypes of unique data.
- CreatedSplunkapp for Enterprise Security to identify and address emerging security threats through the use of continuous monitoring, alerting and analytics.
- Created Regular Expressions for Field Extractions and Field Transformations inSplunk.
- Extensively usedSplunkSearch Processing Language (SPL) queries, Reports, Alerts and Dashboards
- ConfigureSplunkfor all the mission critical applications and usingSplunkeffectively for Application troubleshooting and monitoring post go lives.
- Supported 8+Splunksearch Heads, 50 + Indexers, 3200 + forwarders.
- Created Dashboards and Reports to show Login count of each application, to show which app resources being accessed more, Number of failed logins, statistics on High hitting applications.
- Involved in helping the UNIX andSplunkadministrators to deploySplunkacross the UNIX and windows environment
- Created Java API to extract data from the Oracle Database
- Developed scripts (Python, JavaScript) as needed in support of data collection, reporting and presentation requirements.
- Created Shell Scripts to installSplunkForwarders on all servers and configure with common configuration files such as Bootstrap scripts, Outputs.conf and Inputs.conf files.
- Created Splunk Search Processing Language (SPL) queries, Reports, Alerts and Dashboards.
- Involved in bridge calls for production issues and non-prod issues and involved application teams or database teams or networking teams to resolve the issues and involved in Root cause analysis for the issues encountered. Also provided 24/7 on call support for all the production applications.
- On a scheduled basis, configure backups, verify custom reports, manage log source groups, and validate log sources with client.
- Review and apply any newly available and applicableSplunksoftware or policy updates routinely.
- ManagedSplunkuser accounts (create, delete, modify, etc.)
- Add /Remove log sources. Troubleshoot issues with log sources or systems with vendor, and report system defects as needed.
- Maintain current functional and technical knowledge of theSplunkplatform and future products.
Environment: Splunk6.x, Splunk Enterprise and Splunk modules, java, python, java script Web Logic server 8.x/9.x/10.x/11g, Tomcat 6.0, IBM HTTP Server, Microsoft IIS 7.0, Apache 2.x,Oracle 11g/10g,Wily Introscope 8.x, JSP, EJBs, JMS, HTML, XML, JRUN, SSL, JDBC, JMS, JNDI
Confidential, Riverwoods, IL
Splunk Engineer
Responsibilities:
- Deployed Spunk universal forwarder across various applications to collect the data.
- Deployed syslog and snmp receiver architecture to collect data from network devices.
- Responsible to filter the unwanted data in heavy forwarder level thereby reducing the license cost.
- Implemented various parsing steps to route data to desired index at the HF level.
- Implemented anonymizers in forwarder level to mask the customer sensitive data.
- Established indexes and retention policy of buckets; developed user roles to complement operational and security utilization. Set-up common sourcetypes using pre-trained datasets and constructed sourcetypes of unique data.
- Able to manage distributed search across set of indexers.
- OptimizedSplunkfor peak performance by splittingSplunkindexing and search activities across different machines.
- Extracted complex Fields from different types of Log files using Regular Expressions.
- Able to create fields through IFX, Splunk Web and via Splunk configurations.
- Able to analyze and correlate the events through Spunk grouping commands such as transaction join and append.
- Created pig scripts to transform extract data and transform the data from HDFS.
- Generate HIVE Scripts and create views for reports.
- Created HTML dashboards with java scripts and CSS to create customized visualizations.
- Prepared, arranged and testedSplunksearch strings and operational strings.
- Created and configured management reports and dashboards.
- Implemented prediction in application events using Splunk Algorithms.
- Good knowledge in building Splunk Apps for custom application requirement.
- Provide inputs for identifying best fit architectural solutions - deployment for Splunk project.
- Created Dashboards to monitor CPU Performance Peak, Memory Leakage.
- Monitor and trackSplunkperformance problems, administrations and open tickets withSplunkif there is need.
- Responsible for Scheduling and Automating Database tasks - Jobs, Alerts, Emails, Notification.
- Maintained and managed the application errors during production.
- Created Splunk Dashboards to capture the Authentication breaches across application.
- Scheduled Reports to find the login defaulters across organization/application.
- Created EVAL Functions where necessary to create new field during search run time.
- Worked on the Windows Servers and RHEL Linux OS deployments. Worked on VM creation, templates, clones and snapshots.
- Managed VMs specification, upgrade of VM Tools and VM hardware.
Environment: Splunk Enterprise Server, Splunk Forwarder, Shell, PowerShell, RedHat Linux, HIVE, HDFS, Pig, Java Script, Windows 2008 R2, Windows 2012 R2
Confidential
PL/SQL Developer
Responsibilities:
- Involved in the design, coding, deployment and maintenance of the project.
- Acted as a single point contact for the Database related activities like developing/ creating tables, procedures and functions for the java developers. Involved in designing of the application using UML (Unified Modeling Language).
- Written PL/SQL procedures to extract the daily promoted and demoted Employees from the HR database.
- Developed various reports by using SQL.
- Loading of data (Data Migration) from legacy system to custom tables using SQL LOADER.
- Developed stored procedures and triggers to facilitate consistent data entry into the database.
- Written Stored Procedures using PL/SQL functions and procedure for common utilities.
- Participated in system analysis and data modeling, which included creating tables, views, indexes, synonyms, triggers, functions, procedures, cursors and packages. Created programming code using advanced concepts of Records, Collections and Dynamic SQL.
- Used advanced Bulk technologies (FOR ALL, BULK COLLECT) to improve performance. Developed installation scripts for all the deliverables. Performed functional testing for different Oracle Forms application functionalities.
- Performed unit testing, system testing and integration testing.
- Worked on Oracle database to design Database schema, created Database structure, Tables and Relationship diagrams.
Environment: Oracle 11g, SQL, PL/SQL, Proc *C, Java Script, UNIX, Windows NT/XP
