Cribl Application Support Engineer

NTT DATA Services•Frisco, TX
•$78,948 - $137,063•Onsite

About The Position

NTT DATA is seeking a Cribl Application Support Engineer to join their team in Frisco, Texas. This role involves providing L2/L3 production support and administration for the Cribl platform, with a primary focus on Cribl Stream. The engineer will be responsible for monitoring the health of Cribl components, troubleshooting various issues including data flow, connectivity, and service failures, and performing configurations and maintenance. The position also requires scripting for automation, handling ITSM tickets, maintaining documentation, and participating in on-call support. Collaboration with internal teams and external vendors is essential for issue resolution.

Requirements

  • 5+ years Administration, configuration, monitoring and troubleshooting of Cribl Stream
  • 5+ years experience with Cribl Components: Leader Nodes, Worker Nodes, Worker Groups, Sources, Destinations, Routes, Pipelines and Packs
  • 5+ years experience in Log/Data Processing: Log ingestion, routing, filtering, parsing, transformation, enrichment and troubleshooting
  • 5+ years experience with Linux/Unix command-line and system troubleshooting
  • 5+ years experience with Shell Scripting: Bash/Korn Shell scripting and operational automation
  • 5+ years experience with Python: Basic-to-intermediate scripting for support automation
  • 5+ years experience with Regex / JSON: Log parsing, filtering, data extraction and troubleshooting
  • 5+ years knowledge of JavaScript for Cribl functions, expressions and data transformations
  • 5+ years experience with Networking: TCP/IP, DNS, ports, firewall, SSL/TLS and connectivity troubleshooting
  • 5+ years knowledge of SIEM / Observability: Splunk, Elastic, Sentinel or similar platforms
  • 5+ years experience with ITSM: Incident, Change, Problem and Service Request management

Nice To Haves

  • Hands-on experience with Cribl Stream administration and production support.
  • Experience configuring and troubleshooting Sources, Destinations, Routes, Pipelines and Packs.
  • Understanding of Cribl Leader and Worker architecture and Worker Group management.
  • Experience with Splunk and/or Elastic Stack.
  • Knowledge of Kafka, Syslog, REST APIs and HTTP-based integrations.
  • Experience with AWS/Azure logging and monitoring services.
  • Knowledge of log-management, SIEM, observability, and security-monitoring concepts.
  • Experience troubleshooting high-volume log/data ingestion environments.
  • Experience with Git/version-control concepts.
  • Experience with ServiceNow or similar ITSM tools.
  • Understanding of high availability, capacity management, and disaster-recovery concepts.

Responsibilities

  • Provide L2/L3 production support/administration for the Cribl platform, primarily Cribl Stream.
  • Monitor Cribl Leader Nodes, Worker Nodes, Worker Groups, Sources, Destinations, Routes, Pipelines, and overall platform health.
  • Troubleshoot Cribl application/service failures, data-flow issues, and connectivity problems.
  • Investigate issues where logs/events are not received, delayed, dropped, incorrectly routed, or not reaching the target destination.
  • Configure and troubleshoot Sources, Destinations, Routes, Pipelines, Packs, and Functions.
  • Perform Cribl service start/stop, configuration changes, deployments, maintenance, and health checks.
  • Investigate alerts and production incidents using Cribl logs, monitoring dashboards, and OS logs.
  • Perform Root Cause Analysis (RCA) for recurring or critical incidents.
  • Support Cribl installation, configuration, patching, upgrades, and maintenance activities.
  • Troubleshoot issues across Linux/Unix servers, network connectivity, filesystem, CPU, memory, disk space, and system resources.
  • Troubleshoot TCP/IP, DNS, ports, firewall, certificates, SSL/TLS, and source-to-destination connectivity issues.
  • Monitor and troubleshoot data throughput, queues, backpressure, and performance-related issues.
  • Support integrations between Cribl and enterprise platforms such as Splunk, Elastic, Kafka, Syslog, Microsoft Sentinel, AWS, Azure, and other SIEM/observability platforms.
  • Write and maintain Shell/Python scripts for monitoring, health checks, log analysis, reporting, and operational automation.
  • Use Regex, JSON, and JavaScript for log parsing, filtering, transformation, enrichment, and troubleshooting where required.
  • Handle incident/change/problem/service-request tickets using ITSM processes.
  • Maintain SOPs, runbooks, operational documentation, and knowledge articles.
  • Participate in on-call/production support and major incident troubleshooting as required.
  • Coordinate with infrastructure, network, security, SIEM/observability, and application teams for issue resolution.
  • Coordinate with Cribl/vendor support for complex product-level issues.

Benefits

  • medical, dental, and vision insurance with an employer contribution
  • flexible spending or health savings account
  • life and AD&D insurance
  • short and long term disability coverage
  • paid time off
  • employee assistance
  • participation in a 401k program with company match
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service