- Create IAM users, roles and policies to support least privilege initiative.
- Responsible to managing over 60+ EC2 instance (windows/Linux) to support Splunk.
- Configured AWS Systems manager to patch Instances using tags.
- Responsible for review and implementing cost savings suggestions provided by AWS Trusted Advisor Service
Created Highly Available Environments using Auto-Scaling and Load Balancers
- Responsible for all Splunk operations and maintenance
Designed and configured Splunk enterprise for data ingestion of less than 100GB/day.
- Manage Splunk User Accounts (Roles, Privileges)Troubleshoot and resolved Splunk server and agent problems and issues.
- Configured Splunk to ingest logs from Servers and Applications,
- Created/developed Splunk content and dashboards, technical add-ons for various technology, and conducted data on boarding, normalization, and analysis to support the desired dashboards, reports and notables.Helped end-users to fine tune and optimize the queries
- Splunk cluster migration sizing and deployment/upgrade and management.
- Splunk instance performance tuning and optimization (OS and app level)
- Managing and administering Splunk multisite cluster.
- Deployment and management of UF agents.
• Data sources onboarding using syslog, Splunk DB
connect, Universal Forwarder, API, etc.
• Custom Technology Add-ons development for custom
log parsing.
• IT infrastructure deployment and management (On-
prem with VMware Esxi, Vcenter and AWS)