Nilesh Bakliwal is Solution Delivery Manager in Cyber and Strategy Risk Services group within Deloitte Risk & Financial Advisory having specialization in designing and implementing Splunk architecture for both on-premises and AWS/Azure Cloud environments, as well as automating the ingestion of logs from various AWS accounts and Azure subscriptions into the SIEM platform.
He has more than 11+ years of experience in the field of Information Technology which also includes skills in the Unix/Linux system programming, administration, and AWS/Azure Cloud technologies and HPE Arcsight implementation, setting up Splunk ITSI and ES, and Cribl and managing Security Operations and Splunk architect for one of the largest Oil and Gas company client and have experience of managing 20+ members.
Around 8.6+ years of experience in the field of Information Technology which includes skills in the Unix/Linux system programming, administration, ITIL, and around 6 years in configuring, implementing and supporting Splunk Infrastructure across Linux and developing splunk dashboards and reports as a site reliability Engineer (SRE)., RHCSA/RHCE, RHEV, OpenStack, Splunk Certified User, Splunk Certified Power User, Splunk Certified Admin from Intellipaat, ITIL Foundation, Team Lead, 3, Successfully completed various projects., Unix/Linux System Administrator, 6, RHEL5.8, RHEL6, RHEL7, Unix, CentOS, Ubuntu, Open BSD, Nagios, Splunk Enterprise 6.x, Splunk Enterprise 7.x, Bitbucket, svn, Git, Puppet, BigipF5, Nginx, Proxmox, RHEV, AppDynamics, Strong installation, configuration and troubleshooting skills, Dependable and strong team player, Can provide visionary efforts to the projects, Quick Learner, Incident Management/Alert Monitoring, 02/2012, 07/2013, Worked as a L1 support executive in Incident Management, alert monitoring, Change Management, Release Management, ITIL processes. Functional knowledge of Jira ticketing tool and Confluence documentation tool., Linux/Splunk Administrator, 08/2013, 03/2016, Major flavors of Linux (RedHat, CentOS). Installation, Administration, Troubleshooting, of the servers. Memory and disk space management. Patching and upgradation of OS. Configuration of Apache, postfix and various other services. Restart the servers and applications as per requirements. Good hands on with monitoring and alerting tools (Nagios and Splunk). Configuration, customization, maintenance, upgradation to new version, Configuring Host and Service checks, monitoring Threshold Management. Bigip F5/Nginx LB. Tasks creation of VIP, pools and manages certificate profiles, basic editing of iRule, Upgrades. Server Provisioning. Server Installation through Puppet/Foreman. Patching through mcollective/ansible. RHEL Upgradation through mcollective/ansible. Virtualization in Proxmox/RHEV. Virtual Host Creation & Cloning. VLAN tagging. Resources maintenance of virtual servers. Python and shell scripting., Splunk Administrator/Architecture/Developer, 04/2016, current, Highly skilled in Splunk to build, configure and maintain different environments and in-depth knowledge of log analysis generated by linux Operating Systems. Install and monitor Splunk Forwarders on linux servers. Use Search Processing language (SPL) for creating dashboards, views, alerts, reports and saved searches. Expertise in extracting fields using regex and creating good Splunk queries. Customize dashboard visualizations using xml, css. Install and configure various splunk inbuilt apps like Palo Alto, Dmarc, Fireye and various others. Configuration of Splunk data inputs by understanding various parsing parameters like index, source, source type, index sizes, index locations, read/write timeout values, line breaks, event breaks, time formats etc during index-time. Skilled in deploying, configuring, administering and upgrade of Splunk servers (indexers, search heads) and forwarders. Develop customized application configurations in splunk to parse, index multiple types of log format across all application environments. Manage Splunk Enterprise licenses. Develop Splunk indexes and manage their retention lifecycle. Create roles for the application and app sharing permissions for the different roles. Optimized the search performance of Splunk queries and reduced the time for loading the dashboards. Extracted complex Fields from different types of Log files using Regular Expressions. Experience in setting up dashboards for senior management and production support- required to use SPLUNK. Fixing splunk internal errors/bugs. Also developed dashboards in Appdynamics using various metrics.