Logstash Developer Engineer – L2

SISA Information Security Pvt LtdBengaluru, KarnatakaOn-siteFull-timeJunior, 1–2 yearsListed 1 hour ago

Apply now

About this role

Logstash Developer Engineer – L2

###

### Role Summary
We are looking for a hands-on Logstash Developer Engineer – L2 responsible for developing, enhancing, troubleshooting, and optimizing Logstash pipelines and Grok parsers for diverse security and infrastructure log sources. The engineer should independently handle complex parsing and ingestion issues while ensuring zero log loss, accurate ECS field mapping, and optimal pipeline performance .
### Key Responsibilities

- Develop, enhance, test, and deploy Logstash pipelines and Grok patterns for security, network, cloud, application, database, and OS log sources.
- Independently troubleshoot Not Grokked events, parsing failures, log drops, delays, incorrect tagging, and pipeline-routing issues .
- Parse and normalize logs into Elastic Common Schema (ECS) or defined SIEM schemas.
- Work with Grok, Dissect, JSON, KV, Mutate, Date, Ruby and other Logstash filters .
- Validate raw-to-parsed event flow and ensure all intended fields are correctly extracted and mapped.
- Handle multiline, nested JSON, variable-format and high-volume log sources.
- Troubleshoot end-to-end ingestion across Syslog/Filebeat/Elastic Agent → Logstash → Kafka/Redis → Elasticsearch/SIEM environments.
- Perform Grok regression and validation before production deployment to ensure no field loss or parsing rework .
- Optimize Logstash configurations for throughput, CPU/memory utilization, queue management and pipeline stability.
- Diagnose Elasticsearch indexing/mapping errors related to ingestion pipelines.
- Work with REST APIs and API-based collectors; working knowledge of Python for log collection/transformation is preferred.
- Perform RCA for recurring parsing/ingestion issues and maintain SOPs, KEDB, validation checklists and lessons learned .
- Provide L2 support, technical guidance and KT to L1/Integration engineers, reducing dependency on individual developers.
- Coordinate with SOC, Integration, Product and Engineering teams for complex issues and production deployments.

### Required Technical Skills
Must Have: Logstash, Grok/Dissect, Regex, Elasticsearch, ECS mapping, Linux, Syslog, JSON, REST APIs, troubleshooting and performance optimization. Good to Have: Kafka, Redis, Filebeat/Elastic Agent, Python, Git, SQL, cloud log sources (AWS/Azure/GCP), SIEM platforms and cybersecurity log-source knowledge.
### Expected L2 Competency
The candidate should be capable of independently owning a log source from raw-log analysis through Grok development, validation, deployment and production stabilization . L2 engineers should troubleshoot complex ingestion problems, perform RCA, optimize existing pipelines, mentor junior engineers, and deliver solutions with minimal rework and dependency on senior resources .
### Key Success Measures

- Grok/parser accuracy and ECS compliance
- Reduction in Not Grokked/parsing backlog
- Minimal post-deployment defects and rework
- No unintended log loss or ingestion delay
- Faster parser development and issue-resolution turnaround
- Pipeline stability and performance
- Quality of RCA, KEDB and technical documentation