Summary
Overview
Work History
Skills
Certification
Timeline
Generic

Sai Aditya Ponna

Bournemouth,ENG

Summary

  • • Overall 5+ years of eXperience in various domains such as Splunk Admin / Developer, Web Application security testing and generating reports using tools. Worked with Splunk 5.X,6.X 7.x product, all components and distributed Splunk architecture.
  • •Knowledge on configuration files in Splunk (Props.conf, Transforms.conf, output.conf).
  • Experience working on Splunk 5.x, 6.x, 7.x Splunk Enterprise Security 6.x, Splunk DBConnect 1.x, 2.x ,3.x on distributed Splunk Environments and Clustered Splunk Environments on Linux and Windows operating systems.
  • Extensive experience in Installation, Configuration, and Migration, Troubleshooting and Maintenance of Splunk, andApache Web Server on different UNIX flavors like Linux.
  • Experience in installing and using Splunk apps for UNIX and Linux (Splunknix)
    Experience in Splunk development creating Apps, Dashboards, Data Models, etc.
  • Experience on Splunk Enterprise Deployments and enabled continuous integration on as part of configuration management.
  • Experience in Correlating events from a Network, OS, Anti-Virus, IDS/ IPS, Firewalls or Proxies and analyzing them for possible threats.
  • Experience with Splunk Searching and Reporting modules, Knowledge Objects, Administration, Dashboards, Clustering and Forwarder Management.
  • Extensive analytical and troubleshooting experience with both hardware and software. Broad-based professional background lending to an expanded understanding of diverse business processes.
  • Created and Managed Splunk DB connect Identities, Database Connections, Database Inputs, Outputs, lookups, access controls.
  • Monitored Database Connection Health by using Splunk DB connects health dashboards, JBoss and Apache Tomcat.
  • Expertise in creating accurate reports, Dashboards, Visualizations and Pivot tables for the business users.
  • Configured Splunk Searching and Reporting modules, Knowledge Objects, Administration, Add-On's, Dashboards, Clustering and Forwarder Management.
  • Hands on development experience in customizing, visualizations, configurations, reports and search capabilities using customized Splunk queries.
  • Experience in Dynatrace and app Dynamics for using System Health Check, Availability.
  • Knowledge about Splunk architecture and various components (indexer, forwarder, search head, deployment server), Heavy Forwarder and Universal forwarder, License model.
  • Designing and maintaining production-quality Splunk dashboards.
  • Using Splunk and ELK for Business Logic Errors and Exceptions and Good Experience on ELK for Log Search Tool, Log stash and Data Visualization Tool.
  • Good experience in Splunk, WLST, Shell scripting to automate and monitor the environment routine tasks.
  • Good Experience on Splunk IT Service Intelligence and worked Splunk ITSI Glass Table Visualization.
  • Worked on data center operation and migration across Unix and Linux platforms • Good understanding of OSI Model, TCP/IP protocol suite (IP, ARP, TCP, UDP, SMTP, FTP, and TFTP).
  • Ability to work independently as well as a team member. Experienced in Troubleshooting and Back and Recovery.
  • Expert in installing and configuring Splunk forwarders on Linux, Unix and Windows.
  • Installed and used Splunk Enterprise Security App to identify and address emerging security threats.
  • Upgraded and Optimized Splunk setup with new discharges.
  • Experience in troubleshooting log on boarding issues using forwarder.
  • Expert in Building and deploying Instances that indexed more than a TB/Day.
  • Experience in installing and configuring AppDynamics controller on different environments to enable monitoring solution for the external website to track the performance of applications.
  • Integrated different tools with AppDynamics and provided self-healing / self-servicing solutions for application teams.
  • Expertise in installing, configuring, managing, upgrading, monitoring and troubleshooting SQL Server.
  • Extensive experience in Data Warehouse, Data mart, Data Integration and Data Conversion project.
  • Expertise in scripting for automation, and monitoring using Shell, Python scripts. Experienced in all data processing phases, from the Enterprise Model, Data Model (Logical and Physical Model), and Data Warehousing (ETL).
  • Using Splunk and ELK for Business Logic Errors and Exceptions and Good Experience on ELK for Log Search Tool, Log stash and Data Visualization Tool.

Overview

6
6
years of professional experience
1
1
Certification

Work History

Splunk Python Developer

S & L IT Solutions
01.2024 - Current
  • Responsible for installation and maintenance of new network connections for the customers.
  • Congured all the required devices and equipment for remote vendors at various sites and plants.
  • In-depth expertise in the implementation of analysis, optimization, troubleshooting, and documentation of LAN/WAN networking systems.
  • Manage enterprise security systems, identifying key security risks, and reporting risks to management with recommendations for corrective action utilizing NIST frameworks.
  • Design and Implementation of Bluecoat Proxy Infrastructure. Upgrading Radware Appwall WAF (Web application firewall) and hotfixes and patches.
  • Supported nationwide LAN infrastructure consisting of Cisco 4510 and Catalyst 6513.
  • Worked with Cisco routers 2600, 2900, 3600, 3800, 7200 and 7600 and switches 2900, 3560, 3750, 4500, 4900, 6500
  • Perform ISO 27001, PCI and SOX Audits and drive them to the closure of findings.
  • Developed Cyber Security Standards on NIST Frameworks and insured their proper implementation to reduce the risk of vulnerability to IT assets.
  • Implementing various policies as per client compliance to restrict web access, troubleshooting proxy-related access issues and generating Internet access reports using Websense web proxy
  • Responsible for administering, maintaining, and configuring a 24 x 7 highly available, Splunk apps for theproduction portal environment.
    Installed, configured and administered Splunk Enterprise Server and Splunk Forwarder on Redhat Linux and Windows servers.
  • Setup Splunk Forwarders for new application tiers introduced into theenvironment and existing applications.
  • Built dashboards, views, alerts, reports, saved searches using XML, Advanced XML and Search Processing language (SPL) as and when required.
  • Performed Field Extractions and Field Transformations using the Regular Expressions in Splunk.
  • Worked in data-flow design for data ingestion, transformation and analytics layers.
  • Creating compliance rules, extracting Security risks and auditing the policies in rewall using Tufin firewall monitoring tool
  • Reviewed encryption logs and DLP logs to regulate use base technological risk violations
  • Spl splunk programming language
  • Upgrade, managing and troubleshooting various issues with Cisco IPS
  • Rules implementation, log analysis, logical troubleshooting and managing various Checkpoint products-Power-1, UTM-1, Smart-1 appliances and Cisco ASA appliances
  • Wrote Python scripts to parse XML documents and load the data in database.
  • Part of Disaster Recovery Datacentre’s Security Con guration and Management team

Splunk Developer/Admin

TCS
01.2023 - 12.2023
  • • Knowledge about Splunk architecture and various components (indexer, forwarder, search head, deployment server), Heavy and Universal forwarder, andLicense model.
  • • Standardized Splunk agent deployment, configuration and maintenance across a variety of UNIX and Windows platforms, • Troubleshooting Splunk server and agent problems and issues.
  • • Created Dashboards, reports, scheduled searches and alerts. • Developed and implemented Software Release Management strategies for various applications according to the agile and DevOps process.
  • • Provide Regular support guidance to Splunk project teams on complex solution and issue resolution.
  • • Involved in standardizing Splunk forwarder deployment, configuration and maintenance across UNIX and Windows platforms.
  • • Developed Perl and shell scripts for automation of the build and release process.
  • • Integrated Service Now with Splunk to generate the Incidents from Splunk.
  • • Created many of the proof-of-concept dashboards for IT operations and service owners which were used to monitor application and server health.
  • • Expertise in Actuate Reporting, development, deployment, management and performance tuning of Actuate reports.
  • • Parsed, Indexed, andSearched concepts Hot, Warm, Cold, Frozen bucketing.
  • • Onboard new log sources with log analysis and parsing to enable SIEM correlation.
  • • Subject matter expert in best practices, security protocols, PKI, and other security-related issues.
  • • Analyzed large datasets to identify metrics, drivers, performance gaps and opportunities for improvement.
  • • Worked on large datasets to generate insights and communicate insights to guide strategic roadmap.
  • • Performed field extraction using IFX in an event action.
  • • Very good understanding of software development life-cycle (SDLC) process, Followed Agile scrum and story maps for dev tracking.
  • • Involved in interacting with business owners, Developers and business analysts in improving the application.
  • • Implemented JMS to generate appointment logs.
  • • Used Splunk tool to analyze the logs in the applications.
  • • Gained in depth knowledge on Ant build and Web Sphere servers.
  • • Involved in handling various Incident and request related to the application.
  • • Involved in monitoring the ticketing tool and taking the ownership of the tickets.
  • • Worked on various defects analysis and fixed the
  • • Problem record analysis and solution providing.
  • Environment: Splunk 6.1.3, Splunk 6.2, Unix, Oracle 11g, Service Now, MS SQL Server 2012, SQL server, Python Scripting
  • Debugged complex software issues, leading to a more stable product release
  • Adapted quickly to new technologies and programming languages, enhancing overall team productivity

Splunk Engineer

Virtusa Consulting Services
06.2022 - 10.2022
  • Worked on splunk cloud on boarding of different log sources like oracle, Linux, AWS etc.
  • Built custom add-ons in splunk cloud for SIEM purpose.
  • Recent hands on experience with data ingestion / onboarding into Splunk
  • Installation, maintenance and upgradation of splunk components.
  • The ability to de-code and debug complex splunk queries.
  • Created Summary searches and reports; In depth knowledge of Splunk license usage and safeguarding from violation.
  • Experience in optimizing searches and implemented post processing on dashboards.
  • Installation and configuration of Splunk apps to onboard data sources into Splunk..
  • Project involves security event monitoring, analysis, triage incident alerting and reporting using Splunk Enterprise, Splunk ITSI, Splunk ES, Splunk Phantom, AppDynamics and more SIEM tools
  • Configurations with deployment server, indexers, search heads, serverclass.conf, server.conf, apps.conf, props.conf,
  • Created Summary searches and reports; In depth knowledge of Splunk license usage and safeguarding from violation
  • Experience in optimizing searches and implemented post processing on dashboards.
  • Managed Splunk configuration files.
  • Moved configuration files through non-production testing as needed.
  • Experience in installing, configuring, and administration of web servers.
  • Manage SPLUNK user accounts (create, delete, modify, etc.)

Splunk Developer

Atos
02.2020 - 05.2022
  • Onboard new log sources with log analysis and parsing to enable SIEM correlation.
  • Configuration of inputs.conf and outputs.conf to pull the XML based events to Splunk cloud indexer.
  • Knowledge about Splunk architecture and various components (indexer, forwarder, search head, deployment server), Heavy and Universal forwarder, License model.
  • Managed conversion of waterfall documentation into user stories and acceptance criteria, to support Agile software development
  • Created test cases to support test automation
  • Facilitated story estimation meetings using poker planning technique
  • Planned and managed support for problem & incident management processes
  • Conducted User Acceptance Tests (UAT) with select stakeholders
  • Designed mock-up screens used for data collection web-forms
  • Conducted peer reviews for user stories and acceptance criteria
  • Create & prioritize a backlog of requirements through development of User Stories in SDLC module
  • Analysed data using MS Excel functions including filters, pivot tables, and conditional formatting
  • Created user interface specifications to support the development of user interfaces
  • Created user manuals to aid users
  • Splunk configuration that involves different web application and batch, create Saved search and summary search, summary indexes.
  • Worked on log parsing, complex Splunk searches, including external table lookups.
  • Use techniques to optimize searches for better performance, Search time vs Index time field extraction. And understanding of configuration files, precedence and working.
  • Responsible for administering, maintaining, and configuring a 24 x 7 highly available, Splunk apps for production portal environment.
  • Installed, configured and administered Splunk Enterprise Server and Splunk Forwarder on Redhat Linux and Windows servers.
  • Setup Splunk Forwarders for new application tiers introduced into environment and existing applications.
  • Built dashboards, views, alerts, reports, saved searches using XML, Advanced XML and Search Processing language (SPL) as and when required.

Splunk Engineer/Admin

Carbynetech India Pvt Ltd
07.2018 - 12.2019
  • Installed, configured and administered Splunk Enterprise Server and Splunk Forwarder
  • Created Splunk Apps using XML and Web Components. Knowledge of app creation, user and role access permissions.
  • Created tags, Event types, field lookups, using regular expressions, aliases for search-time outputs and visualizations.
  • Experience with Splunk search construction with ability to create well-structured search queries that minimize performance impact.
  • Created Splunk app for Enterprise Security to identify and address emerging security threats through the use of continuous monitoring, alerting and analytics. Experience in working on Splunk
  • Authentication methods, like LDAP Configuration, Creation of roles in Splunk.
  • Worked with Splunk app for Enterprise Security to identify and address emerging security threats through the use of continuous monitoring, alerting and analytics.
  • Extensive experience in Data Warehouse, Data mart, Data Integration and Data Conversion project.
  • Expertise in scripting for automation, and monitoring using Shell, Python scripts.
  • Experienced in all data processing phases, from the Enterprise Model, Data Model (Logical and Physical Model), and Data Warehousing (ETL).
  • Expertise in requirement gathering, developing Performance Test Plans, test strategy, test analysis and summary report preparation.
  • Experienced in working across business team to collect non-functional requirements, formulate scalable test strategies, and enforce performance testing.
  • Created custom app configurations (deployment-apps) within SPLUNK to parse, index multiple types of log format.
  • Create or Enhance Dashboards, Visualizations, Statistical reports, scheduled searches, alerts, summary indexes and knowledge objects.
  • Hands on experience in customizing Splunk dashboards, visualizations, configurations using customized Splunk queries.
  • Building queries/dashboards to detect and illustrate capacity trends, constraints, and risks
  • Analysis for onboarding requests to determine fit for Splunk/monitoring platform
  • Have knowledge of Splunk admin tasks such as installing, configuring, monitoring and tuning
  • Performing support on Splunk & Monitoring platform components.
  • Setting up a highly flexible monitoring set up for some major applications through involved SDLCs such as web logic, web sphere, Tomcat, Apache, Mule, database, Ping servers among various data centers.
  • Partnering with other cross-functional teams to identify tasks and drive them to completion on schedule
  • Engaging and assisting other teams with issue identification and resolution utilizing Splunk/monitoring platforms.
  • Ensuring support tickets are fully updated with the most current data. Provide proper escalations and handoffs to management and support staff

Skills

  • Python and Ruby proficient
  • Excellent problem-solving abilities
  • Windows and Linux
  • QA tools
  • Excellent diagnostic skills
  • Expert in Java, PHP and Perl
  • Database design
  • System upgrades
  • System backups
  • Data backup and retrieval
  • Troubleshooting
  • TCP/IP
  • VoIP Installation
  • Project Management
  • Agile/Scrum
  • Data Monitoring
  • Visualizations
  • FISMA, NIST
  • Remote Technical Support
  • LAN and WAN Assessment
  • Data Analysis
  • Tracking and Documentation
  • User Support
  • Network Configuration
  • Linux, Mac OS, Windows Nmap, Nessus, Wireshark, Metasploit
  • AWS
  • JIRA, Azure DevOps, Rally
  • Python
  • Analytical Skills

Certification

Splunk Enterprise Security Admin

Timeline

Splunk Python Developer

S & L IT Solutions
01.2024 - Current

Splunk Developer/Admin

TCS
01.2023 - 12.2023

Splunk Engineer

Virtusa Consulting Services
06.2022 - 10.2022

Splunk Developer

Atos
02.2020 - 05.2022

Splunk Engineer/Admin

Carbynetech India Pvt Ltd
07.2018 - 12.2019
Sai Aditya Ponna