Cribl Observability Consultant (Cribl Stream Engineer)
Job Summary
Were looking for a hands-on Cribl Consultant to enable our Cribl platform and onboard Splunk data sources through Cribl Stream. Youll build data pipelines that filter shape and route data to Splunk improving data quality and reducing ingest volume and cost.
Set up and configure the Cribl Stream platform: Leader Worker Groups Sources Destinations Routes and Pipelines.
Onboard Splunk data sources through Cribl Stream including traffic from Splunk Universal Forwarders and Heavy Forwarders (Splunk-to-Splunk and HEC).
Build and maintain data pipelines using Cribl functions for filtering parsing masking sampling enrichment and aggregation.
Stream data from Cribl to Splunk indexers and Splunk Cloud keeping sourcetype index and field alignment intact.
Reduce data volume by dropping low-value events and fields and measure the ingest and license savings.
Validate data before and after onboarding so it arrives complete and in the right format in Splunk.
Monitor Cribl health and throughput and troubleshoot data flow issues across Cribl and Splunk.
Document pipelines routing logic and onboarding standards and support knowledge transfer to internal teams.
35 years in data engineering observability or log management.
Hands-on experience with Cribl Stream: Sources Destinations Routes Pipelines and Packs.
Cribl certification (such as Cribl Certified Observability Engineer or Cribl Stream Admin).
Experience building data filtering and data pipelines for log and event data.
Working knowledge of Splunk architecture especially the Universal Forwarder (UF) Heavy Forwarder (HF) and indexer and how data flows between them.
Familiarity with Splunk sourcetypes indexes and and .
Understanding of data formats and parsing: JSON syslog key-value and regex.
Scripting in JavaScript Python or Bash.
Experience with Cribl Edge Cribl Lake or Cribl Search.
Experience with cloud data sources (AWS CloudTrail CloudWatch S3).
Experience with Splunk Cloud or Splunk-to-Cloud migrations.
Splunk certification (such as Splunk Enterprise Certified Admin).
Required Skills:
Hands-on experience in AWS architecture and application migration. Experience managing multi-account AWS environments governance and cross-account access. Strong knowledge of key AWS services including EC2 S3 VPC IAM RDS Aurora Lambda ECS/EKS CloudWatch and CloudTrail. Experience with AWS migration tools including Application Migration Service and Database Migration Service. Understanding of AWS security networking high availability and disaster recovery. Experience with Terraform or CloudFormation and CI/CD workflows.