Wednesday, November 28, 2018

Splunk Admin Roles and Responsibility

Primary Responsibilities:


  • Create and implement Splunk based solutions.
  • Create Splunk Reports and dashboards.
  • Perform data analysis via Splunk queries.
  • Utilize project management skills to prioritize future project objectives.
  • Drive adoption of Splunk across multiple teams.
  • Develop Corrective Action documents for all Business Services.
  • Troubleshoot customer problems and respond to customer requests.
  • Provide training to new team members as required.
  • Document Fix Requests for incidents requiring system changes (system, configuration and code).
  • Perform other related duties as assigned.
  • Ensure communication regarding Partner impacting incidents.



  • Design, implement, and optimize Splunk applications.
  • Develop Splunk infrastructure and related solutions as per automation toolsets.
  • Install, test and deploy monitoring solutions with Splunk services.

  • Hands on Splunk experience in HLD & LLD design and implementation
  • Strong experience in Splunk customization and development to integrate multiple tools, data normalization, algoritham, etc.
  • Experience in Infrastructure and application data processing and development of custom solution
  • Experience in security log analytics will be added advantage
  • Good communication and presentation skills
- provided by Dice

- Administering Splunk and Splunk Apps to include developing new or extending existing Apps to perform specialized functionality.

- Integrating Splunk with a wide variety of legacy data sources.

- Consulting with customers to customize and configure Splunk to meet their requirements.

- Assisting with training application and infrastructure teams not familiar with Splunk.

- Mentoring team members with less experience to assist in Splunk related activities.

- Working closely with Infrastructure, Application, Development and Business or project teams on Splunk.

- Engaging application and infrastructure teams to establish best practices for utilizing Splunk data and visualizations.

- Communicating with customer stake holders including leadership, support teams, and system administrators.

- Creating and maintaining engagement process and documentation related to architecture, operational processes and training material for Splunk.

- Min 3+ years of professional experience with system administration and System Event and system integrations.

- Min 3+ year of work experience with Splunk real-time processing architecture and deployment; Splunk dashboard design a big plus.

- Strong experience in Splunk configuration files, RegEx and comfort in using the Linux CLI and Windows.

- Experience in SOAP, REST API, web-based technologies and scripting languages including JavaScript, Python, Perl and shell scripting, XML, HTML.

- Experience in requirements analysis, engineering, and testing in real world environments.

- Knowledge of TCP/IP and networking fundamentals, MQ, SFTP, SSL.

- Experience in Splunk DB Connect, ITSI, HEC is a plus.

- Strong communication, written, and verbal skills with the ability and comfort level to do presentations to potential and existing customer audiences of 5-30 people.

- Bachelor in an IT related concentration.

- Experience with software development, system architecture, and/or databases a plus.

- Splunk certification(s) a plus but not required.

Splunk Overview

Splunk Products

SPLUNK PLATFORM
  • Splunk Enterprise
  • Splunk Cloud
  • Splunk Light
SPLUNK FOR IT OPERATIONS
  • Splunk IT Service Intelligence
  • Splunk Insights for Infrastructure
  • Splunk Insights for AWS Cloud Monitoring
  • VictorOps
SPLUNK FOR SECURITY
  • Splunk Enterprise Security
  • Splunk User Behavior Analytics
  • Splunk Insights for Ransomware
  • Phantom
Splunk Admin Importance in the industry
Building a Simple Splunk Environment
  • Google Cloud Compute Instances Creation.
Who can learn Splunk Admin
  • Freshers
  • Experienced System Admin Experienced Professionals.
  • Who wants to start their career with Splunk
Splunk Career Scope & Why Splunk trending in the market.

Watch Splunk Admin Tutorial for Beginners

Splunk Administration Curriculum

  • Splunk Installation
  • License Management
  • Getting Data in
  • Managing Apps
Building a Basic Production Environment
  • Splunk Configuration Files
  • Universal Forwarder
  • Forwarder Management
Getting Data In
  • Monitor Inputs
  • Network Inputs
  • Scripted and Modular Inputs
  • Windows Inputs
  • Fine-tuning Inputs
Managing Indexes and Users
  • Splunk Indexes
  • Index Maintenance and Optimization
  • Users, Roles, and Authentication
Parsing
  • Parsing Phase and Data Preview
  • Manipulating Raw Data
  • Field Extraction
Scaling Searches and Monitoring
  • Distributed Search
  • Search Performance Tuning
  • Implementation issues in large-scale deployment
  • Distributed Management Console
Reference Site :
https://www.usaonlinetraining.com/splunk-admin