Ask questions, get answers and engage with your peers
Stream, Lake, Search - End-to-end observability and tracing for AI, LLM applications, and agents View App
Stream - Unified integration hub for Cribl worker groups View App
Edge View App
Stream, Lake, Search View App
SymptomA user needs permission to create, edit, and delete users without access to Fleet, Worker Group, node, or product configuration.Self-managed Cribl Stream does not provide a built-in role with this exact scope.EnvironmentCribl Stream 4.19.0 or
Stream, Search, Edge, Lake - Display an app user's identity details. View App
We've noticed that when sending data to Splunk Cloud that originates from an on-prem Splunk Heavy Forwarder (e.g. syslog and API), the Splunk license cost differs depending on whether we send the data via Splunk LB (S2S) or Splunk HEC destiantions. W
SymptomA Cribl Stream notification is created successfully, but the notification does not appear in the configured Discord channel.The Cribl notification service logs report an HTTP 400 response similar to the following:{ "level": "error", "message
SymptomCribl Stream notifications do not reach Microsoft Teams after migrating from an Office 365 Incoming Webhook Connector to a Microsoft Teams Workflow webhook.A manual curl request to the new webhook URL succeeds from the Leader, but notification
New known issue page(s) added: AI-4634 | Guard: \"Apply\" button adds all recommendations
We are currently working on a Linux log onboarding use case using Cribl Edge/File Monitor and forwarding the processed events to ADX/Sentinel.We have already built a pipeline that can parse some common Linux authentication events, especially from aut
I was cleaning my Cribl.Cloud instance, and deleted datasets that I no longer needed, unaware that these datasets were still being used by destinations in Stream. When going back to Stream afterwards, I could not load the Lake destination page and wo
An export of code is done to a json fromat only while on servers is used a yml fromat.IMHO, it should be possible to do import/export also in yml format. :)
Does Cribl have any documentation for pulling Workday report logs?
I'm getting 400 responses on a POST Body that I'm trying to pass through the state.latestTime within the POST body. I would like to know what is being posted.I don't seem to be able to get a debug log out of my REST Collector to see what it is POSTin
Hi all i am having issue parsing nested Json the event goes like { "records": [ { "time": "2025-12-18T17:25:46.3598689Z", "operationName": "Publish"}{"time": "2025-12-18T17:25:46.3598689Z", "operationName": "Publish"} ], "_time":
This message originated from Cribl Community Slack.Click here to view the original link.I have data that gets processed in STREAM that I want to send to LHE. Do I send it to search, destination or do I send it to something like a HEC destination an
This message originated from Cribl Community Slack.Click here to view the original link.Has anyone had their destinations drop off but only for the UI? I had about 8 Cribl TCP destinations drop off the UI but when I open an individual node that is on
I am seeking technical guidance on configuring a Database Collector to connect to a Windows SQL Server using Domain/Windows Authentication from a Linux-based Worker Node.We are currently running Cribl Stream version 4.17.Our Worker Nodes are running
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.