Splunk ITSI Engineer (Tier II / Tier III)

Cognizant · Karnataka, India

Full-time · Senior · Posted 10 days ago

This role sits within Cognizant's engagement with one of our most strategic global technology clients — a world leader in enterprise networking, cybersecurity, and observability. You will work on complex ITSI environments at enterprise scale, directly supporting mission-critical service health and monitoring operations.

About The Role

We are seeking a Splunk ITSI Engineer to investigate and resolve complex service health and visibility issues across our enterprise monitoring environment. This role demands deep hands-on knowledge of ITSI components, strong analytical thinking, and a relentless focus on data accuracy and service reliability.

What You Will Do

Investigate and resolve complex ITSI incidents including KPI calculation failures, episode correlation anomalies, and Service Analyzer inconsistencies
Troubleshoot performance issues affecting dashboards, Glass Tables, and service views
Guide customers on ITSI configuration optimisation, KPI design strategies, and service modelling improvements
Optimise KPI searches for performance efficiency and accurate service health scoring
Fine-tune adaptive thresholds and anomaly detection behaviour
Analyse and maintain service dependency trees, entity discovery, and normalisation
Diagnose and resolve KV Store issues including data corruption, locking/contention, replication failures, and performance bottlenecks
Review and optimise Glass Tables, Service Analyzer views, and deep-dive dashboards
Analyse and troubleshoot episode generation logic and aggregation policies
Optimise correlation searches and notable events for better incident detection accuracy
Identify bottlenecks in large-scale ITSI deployments and recommend improvements
Create and maintain technical documentation, SOPs, runbooks, and troubleshooting playbooks

What You Bring

Strong knowledge of KPI creation, thresholding, service modelling, and episode review
Deep understanding of SPL, search optimisation, and scheduling
Experience with Search Head Clustering and Replication
Familiarity with KV Store internals and troubleshooting
Linux system administration and log analysis skills
Basic networking knowledge

Technical Skills Splunk ITSI

SPL
Linux
Search Head Clustering
KV Store
JIRA
Git
AWS/Azure/GCP

Sign up to apply