Independent Consultant
Information Technology/IT
Worldwide
Canada
India
Saudi Arabia
United Arab Emirates
United States
English
Tamil
16+ years of overall experience in Enterprise IT Infrastructure Services – Consulting, Solution Design, Service Transition, Service Delivery, Project Management and IT Transformation.
Multi years’ experience in managing large scale projects, new Process on-boarding & existing architecture support.
Expert in Data Visualization, Analytics, Log & Data Management, Data Integration & Analysis.
Multi years’ hands on experience with Data Streaming technologies – like Splunk, Kafka, ELK Stack
Senior Splunk architect/ ELKStack consultant/ Log Management team manager for Enterprise Security & Data engineering team.
Broad understanding of multiple IT technology areas: Data Center, Container & Cloud Computing technologies [SaaS/IaaS/PaaS], Computing Services, Storage, Networks, Database Concepts, Analytics & End User Computing.
Multi years of experience in Federal/State and Local government contracts, Payment Card Industry, Banking, Information Media & Telecom.
Develop best practices, design, develop, configure, and implement large-scale solutions for Splunk, ELK-Stack & Kafka.
Experience in managing log ingestion of overall 30+ TB's on daily basis using multiple tools like Kafka, Elastic search & Splunk
• Achievements:
Reduced 50% license cost for Splunk by redesigning the entire log flow management using Kafka & ELK-Stack. Redesigned entire event forwarding architecture by reducing the dependency on individual endpoint forwarders. Completed Data Source Assessments for Windows & NW’ing logs to optimize everyday license usage in Splunk.
Created number of Splunk Enterprise Security related use cases [responsible for creating more than 200 customized usecases] based on customer and business needs. Integrated log ingestion into Splunk from Android and IOS devices using Splunk Mint. Designed data Ingestion from different Data-Inputs like AWS Kinesis, Elastic Beats, Splunk Forwarders & HEC, Modular & Scripted inputs, TA’s & Syslog’s. Created customized TA’s [inbuild] for data parsing and extraction. Design Secure transformation of log data from Source to the Indexers. Have written many Regex, GROK, Shell & Python scripting for custom data ingestion/parsing/extraction from and in to Splunk & Elasticsearch. Expert in Splunk Performance tuning using [SI/RA/DMA] & SPL tuning for optimum performance. Created many adaptive response actions in Splunk ES to route the post actions to various third-party tools. Created all sorts of Splunk & Elastic KO’s like Dashboards, Alerts, Reports, Glass-Tables, Lookups, KVStore, Data-models, Pivots, Macros, Tags, Fields, Aliases, Events.
Below are some of the data sources, I have integrated with Splunk & Elastic.
.NW - Cisco / Juniper / PAN / F5-BigIP
.FW - Checkpoint / Cisco
.WAF – Imperva / AWS WAF
.OS - Windows / Nix / VMWare
.AV/IDS/IPS - McAfee / Cylance / Sourcefire
.IMT/CMDB – ServiceNow / Jira
.AIPOS, Threat Orchestration & Threat intelligence – TruStar / D3 / RecordedFuture
.Email - O365 / Proofpoint
.DataStream - Kafka / AWS Kinesis / Kinesis Firehose
.AWS – CloudTrail / CloudWatch
.Wireless Mobile management - Cisco Meraki
.VPN, Identity & Authentication - RSA / Pulse Secure / Ping
.Cloud Security – Qualys / Aqua
.API management - Apigee Edge
Achievements:
Below are some of the data sources, I have integrated with Splunk & Elastic.