Splunk Developer & Admin Resume
Irving, TX
SUMMARY
- Over 7 years of experience in configuring, implementing and supporting Splunk Server Infrastructure across Windows, UNIX and Linux.
- Experience with a variety of operating systems protocols and tools, depending on the type of platform or application.
- Experience in SAML 1.1 Artifact and SAML 2.0 SAMLPOST.
- Successfully upgraded SiteMinder from r12 to r12.52, 6.x to 12.x, 5.x to 6.x and involved in SunOne Directory Server upgrade from 5.1 to 5.2 and 5.2 to 6.3
- Proficiency in Splunk 5.x / 6.x Development, System integration under cross platform consisting of Red Hat Linux and Windows operating system.
- Engineered Splunk to build, configure and maintain heterogeneous environments and in - depth knowledge of log analysis generated by various systems including security products
- Architecture various components within Splunk (indexer, forwarder, search head, deployment server), Heavy and Universal forwarder, Parsing, Indexing, Searching concepts, Hot, Warm, Cold, Frozen bucketing, License model.
- Upgraded and Optimized Splunk setup with new discharges.
- Worked on Setup Splunk Forwarders for new application levels brought into environment. Extensive experience in deploying, configuring and administering Splunk clusters.
- Helped application teams in on-boarding Splunk and creating dashboards, alerts, reports etc.
- Developed custom app configurations (deployment-apps) within Splunk in order to parse, index multiple types of log format across all application environments.
- System Administration familiar with Windows Servers, Red Hat Linux Enterprise Servers, Solaris and IBM AIX servers.
- Created and configured websites and application pools in IIS and worked extensively on .Net deployments in Windows space.
- Experience in Shell scripting and extensively used Regular expressions in search string.
- Worked broadly on firm wide Enterprise Releases and DR events.
- Understood Network Firewalls, Load-balancers, LDAP and complex network design.
- Experience in Optimized search queries using summary indexing.
TECHNICAL SKILLS
Splunk Modules: Splunk 5.x / 6.x, Splunk Enterprise, Splunk Cloud, SplunkonSplunk, Splunk DB Connect, Splunk Enterprise, Splunk Hadoop and BigData, Splunk ITService Intelligence.
RDBMS: MS SQL SERVER 2005/2008/2008 R2, Oracle 8i/10g/11g
Data Warehousing: Informatica Power Center 9.5/9.1/8.5/8.1.1/7.1.2, Informatica designer, Workflow Manager, Work flow Monitor, DataMart, Mapplet, Transformations and Autosys.
Directory Servers: Sun ONE Directory Server 5.x, 6.0
Tools: Toad, SQL Lite Speed, BMC Remedy, Putty
Web Servers: IIS 5.0/6.0, Apache
Cloud Platforms: Amazon AWS, Cloud Stack, Open Stack
Operating Systems: Windows Server 2003/2008, Red Hat Enterprise Linux 3-6, UNIX (AIX, Sun Solaris 7-10)
Application Servers: BEA Web Logic 8.1, Tomcat 3.3/4.1.3/5.5
PROFESSIONAL EXPERIENCE
Confidential, Irving, TX
Splunk Developer & Admin
Responsibilities:
- Installed, configured and administered Splunk Enterprise Server 6.0.4 and Splunk Forwarder 6.2.0 on Redhat Linux and Windows severs.
- Experience on Setup Splunk Forwarders for new application tiers introduced into environment and existing applications.
- Worked closely with Application Teams to create new Splunk dashboards for Operation teams.
- Troubleshoot and resolve the Splunk - performance, log monitoring issues; role mapping, dashboard creation etc.
- Created Splunk app for Enterprise Security to identify and address emerging security threats through the use of continuous monitoring, alerting and analytics.
- Created Regular Expressions for Field Extractions and Field Transformations in Splunk.
- Anonymize the PII (Personally Identifiable Information) data in Splunk
- Masked sensitive information such SSN numbers, Addresses when showing results in Splunk.
- Configured Splunk for all the mission critical applications and using Splunk effectively for Application troubleshooting and monitoring post go lives
- Created Dashboards and Reports to show Login count of each application, to show which app resources being accessed more, Number of failed logins, statistics on High hitting applications.
- Created Shell Scripts to install Splunk Forwarders on all servers and configure with common configuration files such as Bootstrap scripts, Outputs.conf and Inputs.conf files
- Configured Splunk forwarder to send unnecessary log events to "Null Queue" using props and transforms configurations to reduce license costs.
- Developed a custom application in Splunk Fetched the data from databases using "DB Connect Application"
- Extensively involved in troubleshooting the issues and document the problem resolutions for future references.
- Experienced in attending the bridge calls for production issues and non-prod issues and involved application teams or database teams or networking teams to resolve the issues and involved in Root cause analysis for the issues encountered.
- Also provided 24/7 on call support for all the production applications.
- Involved in developing complex scripts to automate batch jobs.
- Developed a POC on usage of Puppet Configuration Management tool.
Environment: Splunk Enterprise Server 6.2.0, Universal Splunk Forwarder 4.x.x/5.x.x/6.x.x, RedHat Linux, IBM HTTP Web Server 6.1/7/8, Oracle, HACMP 5.4, HTML, Java Script, XML, Wily Introscope 9.x, IIS 7, Windows 2003, Windows 2008 R2, Python (Jython), Regular Expressions.
Confidential, San Antonio TX
Splunk Developer/ Admin
Responsibilities:
- Developed scripts and Splunk reports to improve demand and capacity planning
- Troubleshot and rectified platform and network issues using Splunk / Wireshark
- Assisted operations in hardware and software upgrades in a cloud environment
- Brought other members of the team up to speed using Splunk to monitor application performance
- Assisted QA team in setting up new test environments.
- Supported Solutions Engineers on production deployments
- Developed scripted inputs into Splunk using Perl and Ruby for near real time analysis of binary call detail records, reducing mean time to resolution
- Served on a companywide committee to select technologies and vendors in order to improve data warehousing and enhance business intelligence reporting
- Led user adoption of Splunk across the organization through departmental case studies and training
- Architected a hardware solution to virtualize network functions and support applications using VMware across multiple data centers
- Experience in Splunk server configurations (web, indexing retention, authentication, etc.) Splunk data onboarding operations (inputs, SQL, index-time configurations) Splunk data parsing operations (search-time field extractions, event types, tags)
- Maintain documentation including: what work has been done, what is left to do, and site-specific procedures documenting the Splunk environment.
- Create event processing Manage timestamps and indexes for field extractions
- Experience in troubleshooting in a Splunk Enterprise environment
- Integrate Splunk with the existing operational tool kit.
Environment: Splunk 6.1.x, 6.2.x, XML, SPL, Shell Scripting, Unix/Linux, Windows, Perl, Ruby, Wireshark
Confidential, Chandler, AZ
Splunk Developer/ Admin
Responsibilities:
- Prepared, arranged and tested Splunk search strings and operational strings
- Involved in requirement gathering to create reports and Dashboards as requested
- Responsible for end-to-end monitoring of the business related applications
- Helped the higher management by developing Dashboards to understand more about the available data
- Created feasible Splunk environmental usage by adding more search heads for multiple indexers
- Lead the upgrade of Splunk from version 5 to version 6
- Used Hot, Warm, Cold buckets for indexing and searching of the data
- Created Splunk saved searches, Event types and macros, thus reducing the complexity of the search to the business users
- Involved in implementing real time data analytics through Splunk
- Created Dashboards for continuous monitoring of the applications
- Created reports, scheduled searches and alerts
- Also generated reports using pivots (with UI) instead of using Splunk Processing Language
- Part of POC validation team for IT operations on Splunk implementation
- Installed and maintained Splunk forwarder in different platforms
- Effective monitoring of the logs through alerts, responding on it and escalating critical issues to the high level teams
- Responsible for configuring and maintaining Splunk apps for production environment
Environment: Splunk 5.x6.0. 6.0. X, SPL, Linux, UNIX, Windows, XML
Confidential, Richmond VA
Splunk Developer
Responsibilities:
- Ingesting logs to geologically distributed Splunk infrastructure.
- Getting data in, Creating, Managing Splunk apps and Infrastructure. Data inputs in detail, Index administration, maintenance and optimization
- Getting data in and create & managing Splunk apps
- Developed robust, efficient queries that will feed custom Alert, Dashboards and Reports.
- Worked on Splunk search processing language, Splunk dashboards and Splunk dbconnect app.
- Publishing data into Splunk through configurations such as inputs.conf, severclass.conf, server.conf, apps.conf and Outputs.conf configurations
- Distributed search and Search performance tuning
- Perform installation, configuration management, license management, data integration, data transformation, field extraction, event parsing, data preview, and Apps management of Splunk platform
- Standardize Splunk forwarder deployment, configuration and maintenance across a variety of Unix platform
- Troubleshoot Splunk server and forwarder problems and issues Introduction to large-scale Splunk deployment; Monitoring and troubleshooting
- Worked on repository to create and manage user profiles.
- Customized the dashboards and KPI's for better manageability of overall performance.
- Wrote UNIX Shell scripts for threshold check for the incoming files.
- Very Good experience on SplunkSearch Language and Regular expressions.
- Installation and implementation of several kind of visualizations to SplunkDashboards.
- Monitor the applications and server infrastructure for optimization, performance and Utilization metrics.
- Developed robust, efficient queries that will feed custom Alert, Dashboards and Reports.
- Good knowledge about Indexer and Search head clustering.
- Doing deeper analysis of data using event correlations across indexes and various source types to generate custom reports for senior management.
Environment: Splunk, Splunk Universal forwarder, Sideview utils, Data Models, Server management, Dashboards, Search processing language (SPL)
Confidential, Dublin, OH
Splunk Engineer
Responsibilities:
- Ingesting logs to geologically distributed Splunk infrastructure.
- Extensive use of Splunk Search Language and Regular expressions for various needs.
- Experience in developing dashboards and customizing them.
- Experience in upgrading and deploying indexer and search head clusters.
- Installation, Configuration, and Troubleshooting on MS SQL 2008/2008R2 enterprise application server.
- Creation and maintenance of Databases, SQL logins, roles and user permissions.
- Good at administration skills on SQL common tasks like Backups, Restore and SQL Jobs.
- Designing databases based on the specifications.
- Created user accounts and roles and assigned them to different users.
- Taking backups regularly, restoring whenever required.
- Experience in implementing Hunk for Cloudera Hadoop cluster.
- Experience with UNIX and Windows command line interface
- Migrating from MS SQL Server .
- Implemented Always on High availability and Disaster recovery on all migrated instances.
- Automating Database refreshes on SQL Server.
- Maintaining and monitoring the production, development, and test database server environment.
- Designing Databases based on the specifications.
- Schedule and troubleshooting jobs.
Environment: MS-SQL Server 2008/2008R2/2005, Splunk, Windows 2003, Toad, BMC Remedy, HTML, .NET, Hunk.
Confidential
SQL Database Administrator
Responsibilities:
- Creating and managing of databases, Performance monitoring, troubleshooting, enhancing high availability and disaster recovery solutions.
- Tested and configured automated routine maintenance tasks like performance tuning, indexes and stored procedures, checked deadlocks and created scheduled jobs.
- Created and managed schema objects such as tables, views, stored procedures, and triggers and maintained Referential Integrity.
- Created new database objects like Procedures, Functions, Packages, Triggers, Indexes and Views using T-SQL in Development and Production environment for SQL Server.
- Developed Database Triggers to enforce Data integrity and additional Referential Integrity.
- Developed SQL Queries to fetch complex data from different tables in remote databases using joins, database links and formatted the results into reports and kept logs.
- Used SQL Profiler and Query Analyzer to optimize DTS package queries and stored procedures
- Involved in performance tuning and monitoring of both T-SQL.
- Involved in data migration and data integration.
- Prepared test reports and bug logs for the testing done and reporting the status to Sr. Management.
- Served as developer for the solutions designed by other team members.
Environment: SQL server 2005, Oracle 9i Server, SQL Plus, PL/SQL, Query Analyzer, SQL Profiler, DTS, Import/Export tools, SQL Server Agent, SQL Server Enterprise Manager, SQL Jobs, SQL Alert, VB Script, SCO Unix, ODBC, JDBC, Database Engine Tuning Advisor, Windows 2005 Server.
