Cribl Application Support Engineer - REMOTE

NTT DATA Services•Frisco, TX
•$78,948 - $137,063•Remote

About The Position

NTT DATA is seeking a Cribl Application Support Engineer to join their team. This role will provide L2/L3 production support and administration for the Cribl platform, focusing on Cribl Stream. The engineer will be responsible for monitoring the platform's health, troubleshooting various issues including data flow and connectivity, and performing configuration changes, deployments, and maintenance. The position involves supporting Cribl installations, upgrades, and patching, as well as troubleshooting related to Linux/Unix servers, networking, and system resources. Additionally, the role requires supporting integrations with enterprise platforms, writing scripts for automation, handling tickets via ITSM processes, maintaining documentation, and participating in on-call support. Collaboration with internal teams and Cribl vendor support is also a key aspect of the role.

Requirements

  • 5+ years Administration, configuration, monitoring and troubleshooting of Cribl Stream
  • 5+ years experience with Cribl Components: Leader Nodes, Worker Nodes, Worker Groups, Sources, Destinations, Routes, Pipelines and Packs
  • 5+ years experience in Log/Data Processing: Log ingestion, routing, filtering, parsing, transformation, enrichment and troubleshooting
  • 5+ years experience with Linux/Unix command-line and system troubleshooting
  • 5+ years experience with Shell Scripting: Bash/Korn Shell scripting and operational automation
  • 5+ years experience with Python: Basic-to-intermediate scripting for support automation
  • 5+ years experience with Regex / JSON: Log parsing, filtering, data extraction and troubleshooting
  • 5+ years knowledge of JavaScript for Cribl functions, expressions and data transformations
  • 5+ years experience with Networking: TCP/IP, DNS, ports, firewall, SSL/TLS and connectivity troubleshooting
  • 5+ years knowledge of SIEM / Observability: Splunk, Elastic, Sentinel or similar platforms
  • 5+ years experience with ITSM: Incident, Change, Problem and Service Request management

Nice To Haves

  • Hands-on experience with Cribl Stream administration and production support.
  • Experience configuring and troubleshooting Sources, Destinations, Routes, Pipelines and Packs.
  • Understanding of Cribl Leader and Worker architecture and Worker Group management.
  • Experience with Splunk and/or Elastic Stack.
  • Knowledge of Kafka, Syslog, REST APIs and HTTP-based integrations.
  • Experience with AWS/Azure logging and monitoring services.
  • Knowledge of log-management, SIEM, observability, and security-monitoring concepts.
  • Experience troubleshooting high-volume log/data ingestion environments.
  • Experience with Git/version-control concepts.
  • Experience with ServiceNow or similar ITSM tools.
  • Understanding of high availability, capacity management, and disaster-recovery concepts.

Responsibilities

  • Provide L2/L3 production support/administration for the Cribl platform, primarily Cribl Stream.
  • Monitor Cribl Leader Nodes, Worker Nodes, Worker Groups, Sources, Destinations, Routes, Pipelines, and overall platform health.
  • Troubleshoot Cribl application/service failures, data-flow issues, and connectivity problems.
  • Investigate issues where logs/events are not received, delayed, dropped, incorrectly routed, or not reaching the target destination.
  • Configure and troubleshoot Sources, Destinations, Routes, Pipelines, Packs, and Functions.
  • Perform Cribl service start/stop, configuration changes, deployments, maintenance, and health checks.
  • Investigate alerts and production incidents using Cribl logs, monitoring dashboards, and OS logs.
  • Perform Root Cause Analysis (RCA) for recurring or critical incidents.
  • Support Cribl installation, configuration, patching, upgrades, and maintenance activities.
  • Troubleshoot issues across Linux/Unix servers, network connectivity, filesystem, CPU, memory, disk space, and system resources.
  • Troubleshoot TCP/IP, DNS, ports, firewall, certificates, SSL/TLS, and source-to-destination connectivity issues.
  • Monitor and troubleshoot data throughput, queues, backpressure, and performance-related issues.
  • Support integrations between Cribl and enterprise platforms such as Splunk, Elastic, Kafka, Syslog, Microsoft Sentinel, AWS, Azure, and other SIEM/observability platforms.
  • Write and maintain Shell/Python scripts for monitoring, health checks, log analysis, reporting, and operational automation.
  • Use Regex, JSON, and JavaScript for log parsing, filtering, transformation, enrichment, and troubleshooting where required.
  • Handle incident/change/problem/service-request tickets using ITSM processes.
  • Maintain SOPs, runbooks, operational documentation, and knowledge articles.
  • Participate in on-call/production support and major incident troubleshooting as required.
  • Coordinate with infrastructure, network, security, SIEM/observability, and application teams for issue resolution.
  • Coordinate with Cribl/vendor support for complex product-level issues.

Benefits

  • medical insurance
  • dental insurance
  • vision insurance
  • flexible spending account
  • health savings account
  • life insurance
  • AD&D insurance
  • short term disability coverage
  • long term disability coverage
  • paid time off
  • employee assistance
  • 401k program with company match
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service