Job Description
Job Description:
Key Responsibilities:
Design and implement end-to-end Splunk solutions including data ingestion, parsing, indexing, and search optimization.Develop and maintain custom correlation rules, alerts, dashboards, and visualizations to support security monitoring and incident response.Onboard new log sources from infrastructure, security, application, and cloud systems using best practices (e.g., via UF, HF, syslog, APIs).Perform regular health checks, indexer and search head performance tuning, license usage monitoring, and configuration backups.Support threat detection initiatives by translating security use cases into actionable Splunk queries and alerts.Assist in troubleshooting ingestion failures, parsing errors, and inefficient searches.Collaborate with SOC, threat intelligence, and infrastructure teams to ensure data relevance, completeness, and quality.Maintain Splunk Enterpri...