Deployment & Architecture
-
Deploy Splunk Enterprise / Distributed Architecture
-
Configure Indexers, Search Heads, Forwarders
-
Implement clustering (Indexer / SH Cluster)
2️⃣ Log Source Onboarding
-
Configure Universal Forwarders & Heavy Forwarders
-
Create data inputs (syslog, API, cloud integrations)
-
Index creation and retention policy configuration
-
Field extraction, sourcetype validation, and parsing
3️⃣ Detection & Use Case Engineering
-
Develop SPL-based detection queries
-
Create correlation searches in ES (Enterprise Security)
-
Implement Risk-Based Alerting (RBA)
-
Fine-tune alerts to reduce false positives
-
Conduct use case gap analysis
4️⃣ Log Validation & Troubleshooting
-
Validate ingestion pipeline (Forwarder → Indexer → Search Head)
-
Troubleshoot parsing, indexing, and timestamp issues
-
Monitor ingestion delays and indexing queues
-
Optimize search performance
5️⃣ Platform Maintenance
-
Monitor license utilization (Daily indexing volume)
-
Perform Splunk upgrades and app updates
-
Backup configurations and validate restore
-
Performance tuning and resource optimization
6️⃣ MSS & SOC Support
-
Dashboard creation and SOC visibility enhancements
-
Alert lifecycle improvements
-
Support threat hunting queries
Continuous detection improvement aligned with MITRE