Summary
Overview
Work History
Education
Skills
Timeline
Generic

Kowsalya

Summary

Results-oriented Splunk SIEM Engineer with 6+ years of experience in enterprise security monitoring, SIEM administration, log management, and observability solutions. Experienced in designing and supporting scalable monitoring platforms, onboarding diverse log sources, developing security use cases, dashboards, alerts, and SPL-based searches to improve security visibility and operational efficiency. Strong experience working with banking, healthcare, and financial services environments, supporting enterprise security operations through log ingestion, event correlation, incident investigation support, and platform optimization.

Overview

7
7
years of professional experience

Work History

Splunk SIEM & Observability Specialist

HCLSoftware
India
05.2024 - Current
  • Led the deployment and management of Splunk Enterprise and Splunk Cloud to monitor and analyse logs and metrics from on-premises and cloud-based infrastructure, improving system observability across multiple environments.
  • Administer and support enterprise Splunk environments for security monitoring and application observability across hybrid environments.
  • Design and implement log onboarding solutions for applications, servers, infrastructure components, and cloud-based workloads.
  • Configure and maintain data ingestion pipelines to ensure reliable collection, indexing, and availability of security and operational logs.
  • Develop SPL searches, dashboards, reports, and alerts to support security monitoring and operational visibility.
  • Implement security monitoring use cases by analyzing requirements and translating them into effective searches, alerts, and dashboards.
  • Support SOC teams by improving log visibility, validating data availability, troubleshooting ingestion issues, and tuning alerts.
  • Manage Splunk platform administration activities including installation, configuration, upgrades, patching, health checks, and troubleshooting.
  • Support Splunk clustered environments including Search Head Cluster, Indexer Cluster, Deployment Server, and License Management.
  • Implement OpenTelemetry Collector for centralized collection of logs, metrics, and distributed traces.
  • Perform performance tuning activities including search optimization, ingestion troubleshooting, and platform health monitoring.

Application Security Analyst

Cognizant Technology Solution
Kuala Lumpur
02.2023 - 04.2024

Company Overview: Client - UK-based leading bank.

  • Supported SIEM operations and security monitoring activities for enterprise banking applications.
  • Worked closely with SOC teams to improve security visibility and monitoring capabilities.
  • Performed log analysis and event investigation to support security incidents and operational issues.
  • Onboarded application, server, database, middleware, and infrastructure logs into Splunk.
  • Developed SPL searches, dashboards, reports, and alerts based on security and monitoring requirements.
  • Supported security use case implementation through event correlation and alert configuration.
  • Assisted SOC teams during incident investigations by validating log availability and analyzing security events.
  • Troubleshot log ingestion issues, missing events, parsing issues, and data availability problems.
  • Collaborated with security and application teams for new application onboarding and monitoring enhancements.
  • Supported security configuration activities related to enterprise authentication and access management platforms.

Splunk Engineer

Cognizant Technology Solution
India
10.2019 - 02.2023
  • Company Overview: Client - UK-based leading bank.
  • Implemented log forwarding architecture using Splunk Universal Forwarders,and configured heavy forwarders for high-volume data transfer.
  • Administered the Splunk environment for enterprise-wide log management and monitoring, supporting the integration of multiple data sources, such as servers, applications, and network devices.
  • Troubleshot and resolved performance issues within Splunk instances, including search slowdowns, indexing problems, and configuration conflicts.
  • Managed data retention policies and automated index rotation to optimize disk space usage, and ensure compliance with data retention standards.
  • Integrated Splunk with third-party tools to collect the logs to monitor, and implemented a ticketing tool such as ServiceNow for automated ticket creation based on critical events and incidents.
  • Developed specific content necessary to implement security use cases and transform it into correlation queries, templates, reports, rules, alerts, dashboards, and workflows.

Education

Bachelor of Technology - Information Technology -

Anna University - India
05-2019

Skills

Splunk: Splunk Enterprise, Splunk Cloud, Splunk Observability Cloud, Universal Forwarder, Heavy Forwarder, Search Head Cluster (SHC), Indexer Cluster, Deployment Server, SPL, Log Onboarding, Dashboards, Alerts, Platform Administration

SIEM & Security: SIEM Administration, Security Monitoring, Log Analysis, Event Correlation, Incident Investigation, Security Use Case Development, Alert Tuning, Root Cause Analysis, Threat Detection

Observability: OpenTelemetry Collector, Infrastructure Monitoring, Application Monitoring, Metrics, Logs, Distributed Tracing

Cloud & DevOps: AWS, Terraform, CloudFormation, Azure DevOps, Azure Pipelines

Operating Systems: Linux (RHEL), UNIX, Windows Server

Tools & Collaboration: Git, GitHub, GitLab, Bitbucket, Azure Repos, Jira, Confluence

ITSM: ServiceNow, BMC Remedy

Timeline

Splunk SIEM & Observability Specialist

HCLSoftware
05.2024 - Current

Application Security Analyst

Cognizant Technology Solution
02.2023 - 04.2024

Splunk Engineer

Cognizant Technology Solution
10.2019 - 02.2023

Bachelor of Technology - Information Technology -

Anna University - India
Kowsalya