Architect and implement Cribl Stream/Edge solutions, designing security architectures aligned to specific customer operational requirements.
Reduce ingest up to 30% using keep/drop logic, sampling, and field whitelisting while maintaining SOC-relevant fidelity
Design scalable ingestion and routing workflows for high-volume security telemetry, ensuring reliable integration and validation across Palo Alto, Splunk, QRadar, and SentinelOne with format and field-level expectations met.
Define worker topology and routing patterns for scale and reliability (throughput planning, environment separation, failover strategy).
Troubleshoot end-to-end onboarding blockers across collection, parsing, routing, and destination validation, confirming successful delivery through repeatable tests and stakeholder signoff.