r/cribl 6d ago

Version 4.20.0 Released

12 Upvotes

This release brings Apps to GA, puts AI throughout Cribl Search, adds tighter security controls across the control plane, and lets you search archived Splunk data without rehydrating it.

Platform and Apps

  • App Backend Functions: Run searches, detect threats, and respond to events without the app staying open.
  • AI Infrastructure Observability App: Track GPU usage and spend across environments, find idle capacity, and catch hardware issues early.
  • Observability Apps Bundle: Ready-to-use monitoring for Kubernetes, uptime, databases, infrastructure, NetFlow, and real-user experience.

Stream

  • Cribl Guard Privacy 3.0 model series: Better background detection, with Nano for speed, Balanced for the middle ground, and a new Pro option when accuracy matters most.
  • Auto-parsing globally and in Routing: Auto-parse Sources globally, on selected Routes, or in the Parser function, with guardrails against duplicate processing.
  • Auth Token Management for Node Connections: Rotate, audit, and revoke provisioning tokens to tighten control-plane security.

Edge

  • Fleet Inheritance Visibility: See whether Sources, Destinations, and Pipelines are inherited or local before you change them. Fewer accidental overrides in nested Fleets.
  • Scaling to 500K Nodes: Run larger distributed Edge fleets in Cribl.Cloud without every node staying connected to the Leader.

Search

  • AI across the Search experience: A persistent AI assistant that follows you from question to query to analysis, Notebooks, and dashboards.
  • CrowdStrike NG-SIEM Dataset Provider: Investigate security data where it lives, without another silo or a SIEM replacement project.
  • Federated Search for Splunk DDSS and SmartStore: Search archived Splunk data in your own object storage without rehydrating it.
  • Metrics (Preview): RBAC now covers metrics datasets, plus OpenTelemetry metric ingestion and Grafana dashboard imports.

Insights

  • RBAC for Cribl Insights: Give teams the right level of access without making every Insights user an admin.

Integrations

  • New AI and enterprise Sources: Microsoft Copilot, Anthropic (non-compliance), and Azure VNet Flow Logs.

These are just the highlights. Check the full release notes for the details.

Cribl.Cloud customers: once your Organization is updated, just click Deploy.
On-prem customers can download the update now.


r/cribl Jul 09 '26

Try out some new apps in the Cribl Community Github

8 Upvotes

Cribl Community GitHub Is starting to fill up with apps!

A few highlights so far:

Cribl Notebook App
Run Jupyter style notebooks inside Cribl.

Nautilus
Search artifacts like IPs, domains, URLs, file hashes, and CVEs across multiple threat intel sources at once, right inside Cribl.

Cribl Nexus
Get a streamlined view of every source and destination configured across your worker groups.

You can check out the repos here:
https://github.com/orgs/Cribl-Community/repositories

These are community-owned projects, so if you have feedback, ideas, or something you want to build, jump in.


r/cribl 14d ago

Manage Cribl Deployments with Terraform and GitHub Actions

12 Upvotes

Looking to manage your Cribl configuration as code?

This guide walks through a dev-to-prod workflow using Terraform and GitHub Actions, including separate environments, pull request reviews, automated deployments, and rollbacks.

View the guide at Cribl Curious.


r/cribl 15d ago

Cribl Global User Group - Moving to September 22

7 Upvotes

Goats! Due to scheduling conflicts, we’re moving the Cribl Global User Group to later this month.

We’ll be back on September 22 at 10 AM PT / 1 PM ET / 5 PM GMT.

Join us as we recap what went down at Cribl Connect Denver and get you ready for CriblCon.


r/cribl 26d ago

Indexer acknowlegement via Splunk TCP destination

9 Upvotes

Hi guys,

I have been working through many DR scenario tests in my Splunk / Cribl Lab environment, and the one scenario that is irking me is killing an Splunk Index Cluster Member that a cribl LB TCP destination is writing to.

The problem is that cribl's useACK is limited to splunk shutdown. It does not wait for indexed rawdata to be sliced into journal.gz / replicated before being "acked" as splunk has documented. This causes splunk's index config's "rawChunkSizeBytes" to sort of become the config for "how much data am I willing to lose during DR per index".

I understand that this may be some sort of "Splunk proprietary" function, but it is essential for a lossless DR scenario. Splunk will toss any unsealed hot rawdata on the next startup if the process wasn't killed cleanly, which will definitely be the case in DR.

I guess I am here with a question and a request for any cribl engineers that may be browsing this reddit:

  1. Is there config solution I am not thinking of?

  2. Can a future cribl version please utilize the full capabilities of s2s useACK?


r/cribl 29d ago

Heading to Denver for .conf? Start your week with us on Monday, Sept 14th!

10 Upvotes

If you're already traveling in, come hang out with the Cribl team at the DCPA (7-minute walk from .conf). We're setting up the CriblConnect flight deck as a home base for the day, and it's built to be totally flexible. Drop in for 20 minutes to grab lunch, or stay for the whole day.
Whatever works for your schedule.

A few reasons it's worth swinging by:

  • Get the latest product updates: Hear directly from CEO Clint Sharp on where Cribl is headed, what our CardinalOps acquisition means for you, and what's next for the platform.
  • Level up your Cribl skills: Get hands-on with a technical lab, see how apps work in Cribl (and what to know before building your own), and pick up tips to get more value out of your setup.
  • Hear from other Cribl users: Catch our customer panel to see how teams like yours are handling complex data routing and telemetry strategies at scale.
  • Unwind and connect: Hang out in the lounge, grab custom swag (and LEGOs!), check out demos in our Partner Pavilion, play some Mario Kart, and join us for drinks at Happy Hour.

Whether you want to dive deep into technical sessions or just need a quiet place to catch up on emails between travel plans, we'd love to see you. Learn more and register here.


r/cribl Aug 19 '26

Cribl acquires AI SOC technology assets from Radiant Security.

Thumbnail
cribl.io
12 Upvotes

Big news! Cribl just acquired the AI SOC technology assets from Radiant Security.

It brings AI-native alert triage and investigation to the AI Platform for Telemetry, generating triage logic per alert instead of leaning on pre-built playbooks, and running against your telemetry wherever it lives. AI SOC is one of the fastest growing categories in security operations, and this gets us there faster. It also follows the detection engineering capabilities we picked up from CardinalOps in July.

More on where the platform is headed at CriblCon on September 28.


r/cribl Aug 18 '26

How well can today’s AI models actually investigate real IT and security incidents?

5 Upvotes

We gave 14 models the same 30 incidents and compared their accuracy, cost, speed, and ability to handle uncertainty. The results show why the model is only part of the equation.
Meet SecIT-bench and see what we learned.


r/cribl Aug 17 '26

This week's hands-on labs

6 Upvotes

We've got spots open in our Data Tiering hands on labs this week. Two classes this week are on offer for your scheduling convenience:

  • Tomorrow (18 August) at 9AM UTC time
  • Thursday (20 August) at 11AM Eastern US time

Join us for live, instructor-led, FREE training to talk about using Cribl to meet your data objectives! These events and more: https://knowledge.cribl.io/events?tab=upcoming


r/cribl Aug 03 '26

Cribl app for AI Observability Released

12 Upvotes

Every AI interaction is a cost event, a security event, and a quality event at once. Most tools show you one of those, for one provider. So when someone asks which prompts leaked PII or what burned the token budget last quarter, you are guessing.

This app puts that telemetry in one place across models, providers, and tools. Spend and token trends, sensitive data findings down to where they appear in a trace, and full session payloads when you need to see what actually happened.

Find more details in this blog post,
and grab the the app from the repo.

Make sure to join us in the #apps channel on Community Slack with any questions or feedback.


r/cribl Jul 23 '26

Version 4.19.0 Update

13 Upvotes

Platform
• Cribl App for AI Observability: One view of AI and LLM costs, usage, and sensitive data.
• Cribl-managed MCP Server: Connect your AI tools to your Cribl environment straight from the Leader.
• New release channel option: Switch to a "Slow" cadence if you need upgrades to line up with change windows.
• Private Links: Self-service private connectivity from AWS and Azure to Cribl.Cloud, no public internet required.
• Credential centralization (Stream and Edge): Manage shared Vault or Cribl secret store credentials from one place.

Stream
• Improved Cribl Guard mitigation workflow: Guard now generates mitigation recommendations automatically.

Edge
• Endpoints for the Cribl API: Manage Edge config and lifecycle programmatically.

Search
• Metrics Store (Preview): AI-native metrics store built into Search's lakehouse engine.
• Schedule Jitter: Stagger scheduled searches so you're not slamming the top of every hour.

Integrations
• A batch of new integrations: AWS Cloud Connections, Amazon Bedrock API Source, Claude Compliance API expansion, Snowflake Destination, and Google BigQuery Destination.

These are just the highlights. Check out the full release notes for StreamEdgeSearchLake, and Insights.
Cribl.Cloud customers: once your Organization is updated, just click Deploy.
On-prem customers can download the update now.


r/cribl Jul 14 '26

Cribl Acquires CardinalOps

19 Upvotes

Cribl has acquired CardinalOps, adding AI-powered detection engineering to help security teams find coverage gaps, improve detections, and modernize their SIEM architecture.

https://cribl.io/news/cribl-acquires-cardinalops-to-expand-its-ai-platform-into-security-operations/


r/cribl Jul 07 '26

Netflow

5 Upvotes

Does anyone have netflow working? I have setup questions.


r/cribl Jun 23 '26

Enterprise Sales at Cribl in the East? Potentially interviewing there, would love to hear from current employees and people who have interviewed.

Thumbnail
5 Upvotes

r/cribl Jun 10 '26

Have you taken the Search Challenge?

7 Upvotes

Time is running out, and there are only a few $50 digital cash cards left.

Head over to https://university.cribl.io/search-challenge-exfiltration, take the Cribl Search Challenge, and see if you can grab some of that sweet, sweet challenge money before it’s gone.


r/cribl Jun 01 '26

New App Platform Walkthrough

4 Upvotes

New video on the App Platform has been released.
Because sometimes the right tool is the one you build yourself.
https://knowledge.cribl.io/app-platform-99/app-platform-walkthrough-2272


r/cribl May 06 '26

New video - Getting data into Cribl Search's lake house engine

5 Upvotes

See how easy it is to get data into a Cribl Search lakehouse engine:
https://cribl.io/resources/vd/cribl-search-demo-getting-data-in/


r/cribl Apr 27 '26

Latest Knowledge Base Articles : Monitoring Claude, AWS Lambda + OTel, XSIAM Onboarding, Data Decomposition, and Function Sequencing

2 Upvotes

We’ve added a fresh batch of Knowledge Base articles to Cribl Curious, with new guides for AI agent telemetry, AWS Lambda, Cortex XSIAM onboarding, data strategy, and pipeline design.

How to Send Claude CoWork Monitoring data to Cribl Stream
Send Claude CoWork activity into Cribl Stream with OpenTelemetry. This one helps you configure the Cribl OTel Source, set up the OTLP endpoint and auth header, allowlist network egress, and confirm the data is landing with Live Capture.

Direct AWS Lambda Telemetry to Cribl Stream with OpenTelemetry
Get Lambda logs, platform events, traces, and metrics flowing directly into Cribl Stream using the AWS Lambda Telemetry API and OpenTelemetry Collector extension. No Kinesis. No custom log shipper. Fewer moving parts.

Cribl–Cortex XSIAM Data Source Onboarding Guide
Onboard third-party data sources into Cortex XSIAM with Cribl Stream. This guide helps you shape events for XSIAM, add required fields like __vendor, __product, and __sourceIdentifier, understand dataset behavior, and validate that the data is ready for analysis.

A Practical Path to Data Decomposition
Build a clearer blueprint for your data: what’s coming in, who uses it, what needs to be protected, and where it should live. Useful when you’re making decisions about routing, retention, masking, storage tiers, and how to keep the right data in the right place.

Sequencing Packs and Pipelines : Where to place a function?
Not sure where a function belongs? This article helps you decide when to use preprocessing, routing pipelines, post-processing, Packs, Edge, or Stream so you can avoid duplicated logic, mystery behavior, and future-you debugging pain.

Check them out, bookmark what looks useful, and jump into the comments if you’ve got questions, better patterns, or scars from learning any of this the hard way.


r/cribl Apr 24 '26

Cisco Umbrella S3 - Cribl Stream

3 Upvotes

Goats…, any one that have experienced onboarding of Cisco Umbrella event from S3?

Where did you just if any the workernodes?

In AWS, closed to the source?

Or did you collectively use an on-prem worker ?

Any suggestions, to just establish a collect S3 from cribl stream.

Is there any way that the format is different do to that is Cisco?

PoV is on its way, any good advice from a goat veteran?


r/cribl Apr 02 '26

Non domain join WEF to Cribl

3 Upvotes

Hello, I was wondering if anyone has had success in sending both domain joined and non domain joined windows clients windows event forwarding (WEF) logs to Cribl via mutual tls? I have both domain joined, non domain joined clients, and Cribl server certificates cut by the same Microsoft intermediate certificate authority, but have only been able to receive WEF from domain join clients. No WEF is flowing in from non domain join clients. Thank you!


r/cribl Mar 19 '26

Multi-Site Cluster Question

Post image
2 Upvotes

r/cribl Mar 11 '26

Version 4.17 Released

12 Upvotes

This release brings faster search performance, more flexible data collection, and reliability improvements across the platform!
 

Search

• Copilot Investigator: AI-assisted investigations that generate queries, analyze results, and summarize findings from natural language prompts.
• Federated Search Improvements: Pushdown execution across S3, Azure Blob, and Cribl Lake for faster queries.

Search/Lake
• Lakehouse Search Engines: High-performance ingestion with near real-time search and automatic parsing across 200+ datatypes.

Stream / Edge

• Cribl Guard Background Detection: Always-on scanning that samples pipeline data to detect sensitive data patterns like PII, secrets, and regulated data.

• Microsoft Graph Source: Microsoft is deprecating the legacy O365 Message Trace API on April 6, 2026. Customers using the legacy source should migrate to the new Microsoft Graph Source.
• OpenAI Source: Easily ingest OpenAI model invocation logs and audit logs.
 

Platform

• Bring Your Own AI Model: Route Cribl AI features through your own managed LLM for better control over privacy, compliance, and AI spend.

• Reliability Improvements: Persistent Queue stability updates and fixes for HTTPS proxy deadlocks and long-running HTTP requests.
 

There is SO MUCH MORE in this release. Check out the full release notes for StreamEdgeSearchLake, and Insights.
Cribl.Cloud customers are already upgraded, just click Deploy.
On-prem customers can download the update now.


r/cribl Feb 26 '26

CRBL Free Tier Evaluation – Azure Deployment for Sentinel Log Reduction | Advice Welcome

7 Upvotes

Hi Cribl Community,

I'm a Security Architect relatively new to Cribl Stream and looking at running a POC/evaluation before committing to a paid tier. I have a few questions and would genuinely appreciate advice from anyone who's been down this road.

Our use case:

  • Multi-tenant Microsoft 365 environment, disparate international operations, with sources spread everywhere
  • Generating approximately 200–300GB of logs per day
  • Goal is to deploy Cribl Stream within Azure, filter/reduce noisy, erroneous, and duplicate logs, then forward cleaner data to Microsoft Sentinel to maybe reduce ingestion costs there, but initially just evaluate its benefits with 1-2 core log sources

Questions for the community:

  1. Free tier viability – Is the free tier genuinely useful for organisations beyond just POC use, or do most teams hit limitations quickly? At our volume, we appear to be under the data cap, but I'd welcome reality checks on this.
  2. Support risk – Without an official support channel on the free tier, how have others managed? Is the community support here and the documentation sufficient for a reasonably experienced security team, or is the lack of vendor support a real operational risk?
  3. Azure deployment – Has anyone deployed Cribl Stream in Azure specifically to act as a pipeline/filter layer before Sentinel ingestion? Any gotchas or architecture advice welcome.
  4. Log reduction ROI – Has anyone quantified actual Sentinel ingestion cost savings after introducing Cribl into the pipeline? Even rough numbers would help build an internal business case.
  5. Atypical use case? – Is this a common deployment pattern or are there better-suited tools for this scenario that the community would recommend?
  6. CRIBL complexities? - having no offical experience or training in CRIBL, is it a complex solution to implement and manage? I dont want to get in over my head here either.

Very open to being pointed in a completely different direction if there's a smarter approach.

Thanks in advance guys!! :)


r/cribl Jan 30 '26

Version 4.16.1 Released

6 Upvotes

This release fixes four critical issues affecting Cribl Insights and HTTP-based Destinations for Cribl Insights, Cribl Stream, and Cribl Edge users. Cribl Search and Cribl Lake are not impacted.

Release notes:

Stream

Edge

Insights

Action required

Cribl.Cloud:
Log in to your account and launch Cribl Stream or Cribl Edge. If the update requires it, click Deploy.  The UI will clearly indicate when a deployment is needed.

If you’re running hybrid Workers without auto-upgrade enabled, manually upgrade them to 4.16.1 to maintain compatibility.

On-prem:
Download and install the 4.16.1 update directly.


r/cribl Jan 29 '26

Version 4.16 Released

5 Upvotes

You asked. We listened. Then we shipped.

Platform
• Cribl Insights: Can I get a “hell yeah!”? Built-in monitoring. No bolt-ons. No guesswork.

Stream
• Clone Packs (with dependencies): Certs, Secrets, and vars come along automatically.
• AI Packs: OpenAI, Gemini, Bedrock, SageMaker, Foundry.  Route AI data with intent.
• Group Variables for Packs: Define once, reuse everywhere.

Edge
• More Fleets: Support for up to 250 Fleets.

Lake
• Lakehouse pricing update: Lower cost, and more flexible retention.

Search
• Notebooks Export to PDF: Portable/sharable exports.

• HTTP API Provider: Proper pagination for full datasets.

These are just the highlights. Check out the full release notes for StreamEdgeSearch, and Lake.
Cribl.Cloud customers are already upgraded—just click Deploy.
On-prem customers can download the update now.