Harish Kumar M.
Cybersecurity Engineer |Senior Splunk & Cribl Security Engineer | SIEM Engineering | SOC & Threat Detection | Log Optimization | Cribl Certified
- Role
- Splunk Cribl Engineer at Deloitte
- Location
- Dallas, TX, US
- LinkedIn followers
- 500 followers
About Harish Kumar M.
As a Splunk Engineer, I implemented and managed multiple Splunk environments to ensure optimal data processing and availability. I developed custom dashboards, alerts, and reports to enhance visibility into system performance and security incidents. I performed advanced search query optimization, improving search performance by 50%, and configured data ingestion pipelines to streamline log indexing. I also collaborated with security teams to implement proactive monitoring solutions, reducing incident response times significantly.As a Cribl Engineer, I designed and optimized log routing and transformation pipelines using Cribl Stream. My efforts led to a 30% reduction in storage costs by filtering irrelevant data and improving data enrichment workflows. I automated pipeline monitoring processes to ensure high availability and streamlined troubleshooting for data observability solutions integrated with Splunk and other tools.I hold a Master\'s degree in Computer Science from the University of Bridgeport and am proficient in tools like Splunk, Cribl, and related data engineering frameworks. I am passionate about optimizing data workflows and creating efficient, scalable log management solutions
Experience
Splunk Cribl Engineer
Jun 2023 — Present · Mission, TX, US
Worked as part of the Platform Engineering team to deploy and maintain a distributed Splunk architecture (Indexer Cluster, Search Head Cluster, Heavy Forwarders), supporting large-scale security log ingestion and log source onboarding to ensure platform reliability and scalability.• Built Terraform modules to automate the integration of GCP audit logs into Splunk; resolved deployment issues related to service account keys and log sink permissions.• Designed and maintained hybrid logging pipelines using Rsyslog and Cribl Stream, enabling efficient routing, filtering, data transformation, and normalization of logs across on-premises and multi-cloud environments (AWS, Azure, GCP).• Performed log source onboarding for 50+ data sources from Windows, Linux, GCP, firewall, and proxy environments;• Partnered with SOC and Cloud Engineering teams to create a new data pipeline automation workflow using Cribl pipelines and Terraform templates, minimizing configuration drift and manual setup.• Diagnosed and resolved ingestion failures in Pub/Sub events caused by malformed JSON; implemented parsing checks and retry logic within Cribl and Heavy Forwarders to stabilize the data flow.• Optimized search and dashboard performance using KV Store lookups, Data Model Acceleration, and SPL tuning to reduce latency and improve query speed.• Tuned and optimized security event correlation logic for key incidents such as failed logins, AV detections, and firewall denies; collaborated with SOC analysts to enhance alert fidelity and significantly reduce false positives across multiple log sources.• Documented SOPs, data flow diagrams, and operational runbooks for both Cribl and Splunk environments to streamline onboarding, troubleshooting, and scaling.• Participated in 24/7 on-call rotation; resolved indexer disk utilization issues, cluster replication failures, and ingestion bottlenecks during critical incidents.
Education
University of Bridgeport
Master's degree, Computer Science
MLR Institute of Technology
Bachelor's degree, Information Technology
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.