Splunk Cloud implementation and Success Planning
-
- Onboarding data sources that require custom development work unique to Costco's environment. Custom work involved creating Splunk apps with custom event-breaking, time stamping, field extraction, and mapping to Splunk
datamodels. - Created reports and dashboards related to monitoring the health of data inputs and Splunk itself.
- Troubleshooted numerous issues from simple permissions settings to fixing broken data inputs.
- Created custom apps and views in Splunk to support a smooth end user experience, and separate the experience from administrative use cases
- Onboarding data sources that require custom development work unique to Costco's environment. Custom work involved creating Splunk apps with custom event-breaking, time stamping, field extraction, and mapping to Splunk
Drove efforts to simplify and centralize detection engineering
-
- Defined detection engineering processes and procedures for creating,
maintaining, and tuning rules in Splunk. - Created tools within Splunk to streamline the detection engineering creation process and tuning process with a focus on abstracting the more technical parts of Splunk so that the process would be more accessible to all.
- Identified problematic rules from the previous implementation that would not be transferred to the new implementation due to lack of threat intelligence or looking at the wrong telemetry.
- Defined detection engineering processes and procedures for creating,