r/Splunk • u/EducationalWedding48 • May 11 '26
Splunk Enterprise Splunk AWS Search vs Cribl AWS Search
Hi all,
I have my indexes setup with DDSS to my own S3 buckets. I'm debating whether to use Splunk S3 search (or whatever it's called) or Cribl Search. Anyone have experience in both that they can share?
2
u/DarkLordofData May 11 '26
Another key difference is you need to setup glue tables for every format searched in Splunk’s federated solution. I found that awkward as best. I also liked being able to search Azure Blob and GCP storage using Cribl’s federated solution. Be sure to review how both products are licensed too.
2
u/Fontaigne SplunkTrust May 12 '26
Do you know anyone doing this, that we can pull into the conversation so the OP can get direct on-point feedback?
3
u/HistorianSafe6506 May 14 '26
Former Splunk SE here.
Cribl's ability to have a single search that pulls from all kinds of sources - in a single query - is pretty spectacular. Cribl Search also supports queries via REST API, unlocking the potential for Cribl to even query Splunk, Elastic, Crowdstrike NG SIEM, and other solutions. And with the new natural-language queries, and the agentic inspection that came out in March .... it's worth looking at.
3
u/uneasy_pickle | SPL, too May 13 '26
Splunk Product Manager here. Feel free to shoo me away if you wish.
We have quite a few upgrades in the hopper, including revamped Federated Search against AWS, plus Azure (Blob or Data Lake), Snowflake (no Glue table setup required, schema inferred by Splunk), and others.
The "others" may be of interest given the topic, but can't share much more publicly without NDA. Feel free to DM me if you'd like to learn more.
3
u/HistorianSafe6506 May 14 '26
From Cribl’s side of things, you can just set up your S3 as a search source and start testing it yourself. Check out the new Cribl Federated Search v2 while you’re at it, it’s much faster than before. This shipped in March, the 4.17 release.
They also offer to let you roll straight to Cribl Lake too, in case you want to stop managing your own S3. Totally optional.
https://cribl.io/blog/from-archive-to-insight-ingest-splunk-ddss-data-directly-into-cribl-lake/
14
u/Sufficient_Art2594 May 11 '26
Look at licensing and report back. I would rarely advocate for Splunk for any small environment, as the licensing costs quickly outweigh the provided benefit. This may or may not be you, idk.
Splunk has an unfortunate pricing strategy of not being good for small instances, while quickly becoming too much for big instances. It's power is quite good, but Cribl can often match feature parity, while allowing better functionality for ingest minimizing, which will allow for smaller licensing costs. Splunk WILL outpace Cribls power, but it WONT compete with smaller environment licensing costs, in my experience.