Run distributed Splunk
Multi-site indexer clusters, search head clusters, deployers, deployment servers, heavy and universal forwarders, license managers. Installs, upgrades, capacity, retention, and the 2 a.m. version of all of it.
Principal Cloud Operations Engineer · Splunk & Observability
I've worn a lot of hats across 10+ years in enterprise IT, from operations analyst to engineering consultant. I got into Splunk doing security incident work, spent a year and a half consulting on it — a different client every few weeks — and now run logging and observability in-house for a software company's cloud operations org.
The work I'm proudest of is the unglamorous kind: taking five separate Splunk environments and making them one, then handing most of it to Ansible so it stays that way. I like the problems where the answer is a runbook someone else can follow.
What I do
Multi-site indexer clusters, search head clusters, deployers, deployment servers, heavy and universal forwarders, license managers. Installs, upgrades, capacity, retention, and the 2 a.m. version of all of it.
Onboarding across AWS, Azure, Oracle Cloud, Akamai, CrowdStrike, Qualys, Active Directory and a long tail of others — then the parsing, CIM mapping, dashboards, and alerts that turn it into something a team will actually act on.
Terraform for the infrastructure, Ansible for everything Splunk — installs, app deploys, config management. Rebuilding an environment should be the same playbooks with a different inventory file.
Selected work
These are written from my own notes. Specifics that belong to my employer — hostnames, index names, findings, anyone's name but mine — aren't here, and each page says what it left out.
Separate deployments had grown up around each product line, with duplicated apps, inconsistent access, and a server bill for each. I owned the lift-and-shift into a single Ansible-managed environment — and finished it after my one teammate left. It's since become the place AWS, Azure, and Oracle Cloud all send their logs.
Read the write-up →
A government-cloud environment had its vulnerability posture sitting in a scanner's dashboards that nobody checked on a schedule. I rebuilt them in Splunk, then went past replication: port baselining, weak-protocol detection, scan-freshness thresholds, all opening tickets automatically.
Read the write-up →
Clients hitting the management port got SSL verification failures. It turned out to be two independent problems that looked like one, and my first fix made the error change rather than go away — which is the part of this story I find most useful.
Read the write-up →
Splunk Professional Services across ticketing SaaS, paper manufacturing, title insurance, rail telematics, county government and healthcare. The engagements varied; the first question never did, and it's the reason most of them landed.
Read the write-up →
Experience
Deltek · Herndon, VA (remote)
SP6 / Aditum
Accenture · Greater Sacramento
BCforward · Greater Sacramento
Global TIES · UC San Diego
UC San Diego
Skills
Getting a source into Splunk is rarely the hard part. Working out what its events actually mean, normalising them so they'll join to everything else, and keeping the volume affordable — that's the job. This is what I've done it for.
I write Python and shell to get a job done — onboarding scripts, metric collection, installers — but I wouldn't call myself a software engineer, and I'd rather say so than find out in week two. Same with Prometheus and Grafana: I know what they're for and I haven't run them in anger. Both are on my list.
Certifications & learning
I majored in NanoEngineering, so I didn't get a formal education in information technology. What I did instead was go back and take the coursework — computer networking and computer science fundamentals — because the gaps were real and I'd rather close them than talk around them.
Networking. The OSI model, addressing and subnetting, the TCP/IP suite and the protocols on top of it, plus laying out network architecture in Visio. Three midterms and a final. The OSI model in particular has earned its keep — it's still how I break down a "Splunk is broken" ticket, layer by layer, until the problem has nowhere left to hide.
Computer science fundamentals. Seventeen chapters of Computer Science Illuminated: number systems and data representation, gates and circuits, computing components, low-level languages and pseudocode, algorithms, operating systems, file systems, information systems, networks, the web, and computer security.
Security. Separate self-study on cybersecurity fundamentals alongside the day job in SecOps.
Outside work
Most of these started because I wanted the thing to exist. A few of them taught me more than work did that year.
A volleyball rotation tool. Diagrams all six rotations for 4-2, 5-1 and 6-2 systems across base, serve-receive and defensive formations, drag-and-drop, with overlap-legality checking against the FIVB rule at the moment of serve. Share links encode the entire diagram in the URL, so there's no server and nothing to keep running.
A HomeKit ecosystem tying the house together — lighting, the garage door, climate and weather alerting, and perimeter monitoring. It's the same instinct as the day job at a much smaller scale: instrument the thing, then let it tell you when something changed.
Portraits and pets mostly, with a portfolio site I built to go with it — static, on Cloudflare Pages, with an image pipeline that strips EXIF and GPS at build time. I also shoot and cut volleyball footage, which is where the scriptwriting habit comes from.
Took a Python project off GitHub and modified it until it did what I wanted. Small, but it's how I got comfortable reading someone else's code instead of starting from scratch.
I coach people through interviews — friends, colleagues, anyone who asks. I keep notes for it the same way I keep notes for work. It's the same muscle as the office hours I run for Splunk: the job isn't finished when the thing works, it's finished when somebody else can do it too.
Contact
If you've got a Splunk estate that's grown in four directions, or you need someone who can own logging and observability end to end, I'd like to hear about it. Happy to talk through anything on this site in more detail.
Or skip the form — smartalecv@gmail.com · LinkedIn