Skip to main content
Question

Can we ingest data off the wire into Cribl?

  • March 11, 2025
  • 8 replies
  • 26 views

Is it possible to use Cribl to analyse network traffic in a similar way to Splunk Stream App? Can we ingest data off the wire into Cribl?

8 replies

  • Employee
  • March 11, 2025

We don't have a sniffer like this


Jon Rust
Forum|alt.badge.img
  • Employee
  • March 11, 2025

but you can send the result of a sniffer into Cribl. For example: Splunk Stream -> Cribl -> destination


  • Author
  • New Participant
  • March 11, 2025

Thanks for clarifying


  • Employee
  • March 11, 2025

`tcpdump` in Exec :stuck_out_tongue:


Some other products that might be interesting and can integrate with Cribl:» https://www.elastic.co/beats/packetbeat|PacketBeat» https://www.elastiflow.com/|ElastiFlow


  • Employee
  • March 11, 2025

If you can get the sniffer output into cribl, you could make some aggregations from that stream. Send the aggregations to one of your tools, and save the stream to cheap, quickly rotating storage.Depends on what you're looking for.


  • Cribl Founder
  • March 11, 2025

What wire data specifically are you interested in? There's not much on the wire anymore that isn't encrypted.

DNS over HTTPS is going to be standard on most browsers in the next year or two which will start to minimize even that dataset which was probably the last bastion of unencrypted wire data


  • Employee
  • March 11, 2025

We get a fair amount of value from just raw flows (not that a sniffer is the best way to get those).