Source description
About the role
Splunk Developer
Position : Splunk Developer
Job Duties :
Designing, deploying, testing, troubleshooting, and maintaining the Enterprise SIEM (Splunk) Environment including configuration issues, deployment problems, and role-based accesses across Windows, Linux, and cloud. Working with a data feed owner, and processing intake requests to instruments data feeds into Splunk. Designing Python modules with event generator to write timestamped events to a Splunk specified index. Utilizing the Splunk SDK’s to interact with all of the endpoints in the Splunk Enterprise REST API from a web page interface. Developing the UNIX/Python script to connect to endpoint, and setting the parameters to submit the request. Using Splunk SimData, SDC CLI, an application scaffolding tool, Splunk Data Stream Processor, Splunk Data Discovery in the process of data pipeline. Developing Puppet modules to manage configurations and deployments to remote Splunk Universal Forwarders and Splunk Clusters. Integrating with third-party visualization tools like Google Charts, (charting library from Google), Rickshaw, (A time series visualization library based on d3).Developing client module (splunklib. client) and providing an abstraction layer over the REST API, allowing to access the endpoints in a stateless, Pythonic approach. constructing the binding layer, and uses its HTTP capabilities to access the REST API. Writing python modules to stream XML reader and abstracting over the details of the Splunk XML responses and providing access the stream of data. Support QA Analysts through validation of defect reporting and tracking. Testing different apps and technology addons on dev/test environment before applying in to Production. Deploy customized apps to development, staging/QA, and production environments as necessary. Collaborating with the engineering, development, integration, and test teams in the development and deployment of the new Splunk platform.
Work Location :
various unanticipated work locations throughout the United States; relocation may be required. Must be willing to relocate.
Minimum Requirements:
Education : Bachelor’s degree in Computer Science, or closely related fields
Experience:
None
Job Order No : 9853201.
This position is eligible for a referral bonus through our employee referral program
Position : Splunk Developer
Job Duties :
Creating Modular Inputs using Splunk API & Python to onboard data to Splunk: (25% of work time)Creating Data Onboarding configuration for custom home-grown application as well as from standard OEM applications.Writing Python or Shell scripts to consume application API’s so that custom applications can send data to Splunk.Creation of generic Splunk App/Add-on so as to make Splunk self-service tool enterprise wide and for end to end automation of data onboarding to SplunkConfiguring integration with Splunk premium Apps (Splunk ES, Splunk ITSI, Splunk UEBA & Splunk Infrastructure) and develop customization & build advance features.
Writing Splunk’s SPL (Search Processing Language) to create Reports, Alerts & Custom Dashboards: (25% of work time)As a part of Enterprise Monitoring team, it is critical to monitor in real time all the security incident, Network Health & Application Outrages and bring it to triage.Creating Real-time Dashboards, Alerts, reports and custom visualization enabling Realtime monitoring.Writing Splunk’s SPL to develop user interactive & analytical reports for Production Support.Developing Advanced visualizations with user interfacing in Splunk using D3.js, HTML5 & CSS.Manages Splunk knowledge objects (fields, extractions, tags, event types, lookups, workflow actions, aliases, macros, and etc.)Write SQL Queries in DB Connector of Splunk for leveraging data from Oracle/MS SQL & My SQL.
Working on Data Normalization, Anonymization of PII data, Enrichment of data using external sources and mapping it to Common Information Model (CIM): (10% of work time)Normalizing non-standard/unstructured logs to a common information model so as to be efficiently map it to a data model and common information model.Working to map the data fields as per the respective technology/domain into compatible field formats & knowledge objects. Developing correlation of data from different domains to derive inference & correlation analytics as a part of this job activity.Developing Splunk Enterprise Security & Splunk IT Service Intelligence data model with Common information model
Developing custom application using Ansible & Bigfix on Splunk for end to end automation for Incident creating & Alarm Point: (10% of work time)Working on Analyzation of current incident and draft probable automation solutionsCreating Ansible Playbooks and roles to do end to end automation leveraged by Splunk.Integrating with Service Now, CMDB & Alarm Point to properly route critical incidents automatically to Alarm point.Developing Ansible and Big Fix scripts to automate deployment of applications and track incident status.Develop Application Performance Monitoring (APM) in Splunk by integrating with other monitoring tool for Unified monitoring console
Developing Regex (Regular Expression) for field extractions, data parsing & event correlation: (10% of work time)Creating Regular expressions for Splunk Index time field extractions and search time field extraction.Developing & Enhancing the regular expression to be efficient enough to give faster result and less extraction time leading to real time analytics.
Creating correlation content for Splunk Enterprise Security (ES) using Security Usecase and transforming them into Playbooks: (10% of work time)Migrating Security use cases & critical monitoring from existing SIEM to Splunk ES.Working on Enhancing security correlation searches to reduce false positive and make robust security operation center.Creating CICD (Continuous Improvement & Continuous Development) pipeline for single view monitoring, incident management & issue analysis.Configuring & Managing threat intelligence feeds from various external sources to enrich the security incident and for proactive threat detection.
Develop ML Algorithm’s in Splunk to detect Outliers & Abnormality to make informed business decision using Splunk’s MLTK (Machine Learning Toolkit): (10% of work time)Detailed study and analysis of historical security logs, incidents and their response action to build machine learning model for faster & adaptive responsive action.Developing Machine Learning algorithm to predict probable security Incidents, Device failures and Malware attacks.Creating various analytics dashboard using Machine learning on historical data to detect new unknown malware and cryptographic attacks. Working on developing a platform based on Splunk to automatically self-address the incident depending upon the previously occurred similar incident.
Work Location :
various unanticipated work locations throughout the United States; relocation may be required. Must be willing to relocate.
Minimum Requirements:
Education : Bachelor’s degree in Computer Science, Computer Information Systems, or related fields
Experience:
None
Job Order No : 9850124.
This position is eligible for a referral bonus through our employee referral program
More at HCL Global Systems
Related open roles
Sr. Enterprise Application Developer
Location not specified
Sr. Big Data Engineer
United States
ETL Developer
Location not specified
Sr. Developer
United States
Sr. Software Developer I
Jobs located in Farmington Hills, MI and various unanticipated locations throughout the U.S.
Sr. TIBCO Developer
Location not specified