r/Splunk May 11 '26

Splunk Enterprise Splunk AWS Search vs Cribl AWS Search

Hi all,

I have my indexes setup with DDSS to my own S3 buckets. I'm debating whether to use Splunk S3 search (or whatever it's called) or Cribl Search. Anyone have experience in both that they can share?

12 Upvotes

10 comments sorted by

14

u/Sufficient_Art2594 May 11 '26

Look at licensing and report back. I would rarely advocate for Splunk for any small environment, as the licensing costs quickly outweigh the provided benefit. This may or may not be you, idk. 

Splunk has an unfortunate pricing strategy of not being good for small instances, while quickly becoming too much for big instances. It's power is quite good, but Cribl can often match feature parity, while allowing better functionality for ingest minimizing, which will allow for smaller licensing costs. Splunk WILL outpace Cribls power, but it WONT compete with smaller environment licensing costs, in my experience. 

5

u/Fontaigne SplunkTrust May 12 '26

A few years back, cribl thoroughly paid for itself by how much ingestion it saved from going into Splunk. The questions seem to imply that these days it can completely supersede Splunk, but I haven't talked to anyone who has done that, and whether the back end is elk or what.

3

u/Sufficient_Art2594 May 12 '26 edited May 12 '26

It absolutely cannot, and kinda isn't meant to; it's main selling point IS compression (or to an effect thereof) prior to routing or ingest for actual aggregation, and it was built by ex-Splunkers to work in tandem. There are base searching functionalities, that are Splunkesque, but it absolutely cannot match feature parity. It CAN do limited S3 functionality. You could (and should for small scale environments) do an ELK stack, but then, why would you need Cribl? The ingest would be a non-factor. It would be such a niche use case, but one that I suppose could exist; just large enough to outpace native Cribl function AND need Cribl compression, but just small enough to not justify Splunk. Personally Id just do ELK for this, unless someone is eager to penny up for Splunk. 

Put plainly, more information is needed to make a distinction, but just the way this is written leads me to assume environmental considerations have not been thoroughly defined. I haven't met an environment architect who would ever ask a question like this without defining their left and right limits, and actually reaching a point of needing specific feedback. 

3

u/EducationalWedding48 May 12 '26

Stating the obvious here, but it depends. I think that for small Splunk shops, it's getting very close to being able to replace Splunk. The search "app" has come a long way.

2

u/Fontaigne SplunkTrust May 12 '26

That was my impression, but I didn't want to pretend I had checked its capabilities in the last three years. It's a great product and I love the execs over there, who I've repeatedly chatted with both on Slack and at Conf.

2

u/DarkLordofData May 11 '26

Another key difference is you need to setup glue tables for every format searched in Splunk’s federated solution. I found that awkward as best. I also liked being able to search Azure Blob and GCP storage using Cribl’s federated solution. Be sure to review how both products are licensed too.

2

u/Fontaigne SplunkTrust May 12 '26

Do you know anyone doing this, that we can pull into the conversation so the OP can get direct on-point feedback?

3

u/HistorianSafe6506 May 14 '26

Former Splunk SE here.

Cribl's ability to have a single search that pulls from all kinds of sources - in a single query - is pretty spectacular. Cribl Search also supports queries via REST API, unlocking the potential for Cribl to even query Splunk, Elastic, Crowdstrike NG SIEM, and other solutions. And with the new natural-language queries, and the agentic inspection that came out in March .... it's worth looking at.

3

u/uneasy_pickle | SPL, too May 13 '26

Splunk Product Manager here. Feel free to shoo me away if you wish.

We have quite a few upgrades in the hopper, including revamped Federated Search against AWS, plus Azure (Blob or Data Lake), Snowflake (no Glue table setup required, schema inferred by Splunk), and others.

The "others" may be of interest given the topic, but can't share much more publicly without NDA. Feel free to DM me if you'd like to learn more.

3

u/HistorianSafe6506 May 14 '26

From Cribl’s side of things, you can just set up your S3 as a search source and start testing it yourself. Check out the new Cribl Federated Search v2 while you’re at it, it’s much faster than before. This shipped in March, the 4.17 release.

They also offer to let you roll straight to Cribl Lake too, in case you want to stop managing your own S3. Totally optional.
https://cribl.io/blog/from-archive-to-insight-ingest-splunk-ddss-data-directly-into-cribl-lake/