Ask questions, get answers and engage with your peers
Known issue page(s) updated: CRIBL-45369 | Worker Process memory leaks while Collection jobs run
QuestionWhy does Members & Teams show the Admin role for users that I've granted the Owner role via group membership in my SSO IDP?Environment Cribl environment with SSO configured for login AnswerFor SSO users, the role in the Cribl UI is update
ObjectiveWrite an initial Getting Data In (GDI) datatype rule filter in Cribl Search Lakehouse using the correct available fields.EnvironmentCribl Search 4.17.0 (Lakehouse engines) Search > Data > Getting Data In Initial Datatype / Dataset rule
New known issue page(s) added: CRIBL-45369 | Worker Process memory leaks while Collection jobs run
SymptomWhen a destination, pipeline, or route is deleted from within a pack in the Cribl Stream UI, the resource appears to be removed. However, after a Commit & Deploy the resource reappears. Exporting the pack with local changes and re-importin
SymptomCribl Stream Worker pods deployed in Kubernetes show unexpectedly high CPU and memory usage even though processing and log-ingestion volume is low. One or more pods may later restart with OOMKilled.The two symptoms can have different causes. C
SymptomAfter a Cribl Stream Leader restart or configuration change, port 4200 is not listening and Workers or Edge Nodes cannot reconnect to the Leader.The Leader logs can include:Shutdown:CB:Failed name: SocketRouter Error: Cannot read properties of
New known issue page(s) added: CRIBL-45296 | Outpost TLS distributed setting failing on validation due to presence of lakeAzure entry in the payload
I am currently stuck on the lab (CC Admin - Stream | Stream Projects and Security Lab), specially task 3.2 and 3.3. I was unable to add the team to the project with the Editor role because permissions field was grayed out and did not allow me to sel
Hi,I’m a certified Cribl Admin user and finished all the admin user labs and course.currently working on Cribl Stream certification, I’m stuck with an issue I cant complete "Stream | Stream Projects and Security Lab” as it mentions that” In order to
We've noticed that when sending data to Splunk Cloud that originates from an on-prem Splunk Heavy Forwarder (e.g. syslog and API), the Splunk license cost differs depending on whether we send the data via Splunk LB (S2S) or Splunk HEC destiantions. W
We are currently working on a Linux log onboarding use case using Cribl Edge/File Monitor and forwarding the processed events to ADX/Sentinel.We have already built a pipeline that can parse some common Linux authentication events, especially from aut
I was cleaning my Cribl.Cloud instance, and deleted datasets that I no longer needed, unaware that these datasets were still being used by destinations in Stream. When going back to Stream afterwards, I could not load the Lake destination page and wo
An export of code is done to a json fromat only while on servers is used a yml fromat.IMHO, it should be possible to do import/export also in yml format. :)
Does Cribl have any documentation for pulling Workday report logs?
I'm getting 400 responses on a POST Body that I'm trying to pass through the state.latestTime within the POST body. I would like to know what is being posted.I don't seem to be able to get a debug log out of my REST Collector to see what it is POSTin
Hi all i am having issue parsing nested Json the event goes like { "records": [ { "time": "2025-12-18T17:25:46.3598689Z", "operationName": "Publish"}{"time": "2025-12-18T17:25:46.3598689Z", "operationName": "Publish"} ], "_time":
This message originated from Cribl Community Slack.Click here to view the original link.I have data that gets processed in STREAM that I want to send to LHE. Do I send it to search, destination or do I send it to something like a HEC destination an
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.