Senior Syslog Engineer
Fully remote work flexibility within India.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Required Skills
- AWSCybersecurityKafkaSparkLinux
Requirements
- Deep hands-on expertise with syslog-ng and large-scale syslog pipeline engineering.
- Strong understanding of syslog protocols and standards, including RFC3164, RFC5424, TCP, UDP, and TLS-based ingestion.
- Proven experience designing advanced filtering, routing, parsing, and regex optimization strategies.
- Strong knowledge of performance tuning parameters such as log-iw-size, log-fifo-size, flush_lines, disk-buffer management, and flow control.
- Experience handling high-volume event processing environments exceeding 10K–100K+ EPS workloads.
- Strong Linux troubleshooting and debugging skills using tools such as tcpdump, netstat, ss, top, and strace.
- Familiarity with SIEM platforms including Splunk, ELK, QRadar, or similar technologies.
- Understanding of distributed ingestion and streaming technologies such as Kafka or Spark is preferred.
- Knowledge of cloud-based infrastructure environments, particularly Amazon Web Services, is advantageous.
- Familiarity with security log sources including firewalls, IAM systems, endpoints, and network devices is a plus.
Responsibilities
- Design, implement, and optimize high-throughput syslog-ng configurations and log ingestion architectures.
- Develop advanced filtering, routing, and parsing logic to improve log quality, normalization, and noise reduction.
- Monitor and optimize pipeline performance related to CPU usage, memory consumption, throughput, buffering, and latency.
- Build scalable, fault-tolerant, and resilient syslog infrastructures capable of processing high event-per-second (EPS) workloads.
- Troubleshoot ingestion issues including message loss, duplication, out-of-order events, backpressure, and network-related failures.
- Optimize buffering, batching, flow control, and disk-based queue management mechanisms within syslog-ng environments.
- Collaborate with SIEM platforms such as Splunk, ELK, or QRadar to ensure seamless data ingestion and integration.
- Implement best practices for structured and unstructured log parsing, secure syslog transmission, and protocol compliance.
- Conduct capacity planning, load testing, and performance validation for enterprise-scale logging systems.
- Develop reusable test frameworks, standards, documentation, and configuration guidelines for syslog environments.
View Full Description & ApplyYou'll be redirected to the employer's site