Cribl Stream

Get the data you need, in the format you want, wherever it needs to go.

Collect, reduce, enrich, and route data in real time, without blowing your budget.

In a nutshell

Simplify how you manage telemetry data

Cribl Stream is the industry's leading observability pipeline, letting you collect, reduce, enrich, and route telemetry data from any source to any tool, in the right format.

Stream is your go-to solution for handling the variety and volume of telemetry data without blowing up your budget.

Whether you're dealing with megabytes or petabytes, Cribl Stream scales easily and gives you the flexibility and control to handle any data, your way.

Benefits

More streaming, less screaming

Cribl Stream gives you the flexibility, control, and efficiency to manage data smarter, cut costs, and get actionable insights—while reducing complexity and improving tool performance.

NETWORK.svg

Onboard telemetry sources seamlessly

Connect quickly to 80+ data sources and destinations, or use Cribl Packs for seamless integration. No complex setup required.

SCALE.svg

Scale for every workload

Cribl Stream adapts as you grow, handling small volumes and massive enterprise-scale deployments with ease.

PROTECT.SECURITY.svg

Enhance data security

Use strong encryption and granular access controls so only authorized people can see sensitive data.

DATA HYGIENE.svg

Cut down on data clutter and costs

Boost performance and lower costs by stripping out unneeded fields or events, so your team and tools focus on what actually matters.

OPTIMIZE LOGS.svg

Optimize your data to get the job done

Easily tailor data with Stream's data processing capabilities, or map, filter, and transform events with our AI-powered Copilot Editor.

MANAGEMENT.svg

Control data with precision

Set detailed data policies and standards to keep compliance on track and manage data precisely across its lifecycle.

Customer success

Cribl Stream for the win

I spent a couple of weeks casually working through Cribl pipelines to get the most optimization out of the gate. We’re reducing 9.25TB of daily EDR data down to a little over 5TB a day — 41% reduction. Now we retain data for investigations for 45 days instead of seven.
Sheldon CarmichaelInformation Security Architect, Sally Beauty

41%

REDUCTION IN DAILY EDR DATA (FROM 9.25TB TO 5TB)
Read case study

Features

Why Cribl Stream?

Flex your data handling capabilities

With Cribl Stream, you can adapt quickly to changing telemetry requirements.

Use Copilot Editor to map schemas, transform, and filter data with plain language prompts.

Integrate with 80+ sources and destinations and use portable Packs to move entire pipelines as reusable bundles.

From small deployments to enterprise scale, Stream fits your needs without new infrastructure or agents.

Get more from your data with less effort

Highlights

All your logs, none of the hassl.

Meet Cribl as Code: Developer choice with zero compromise

Cribl as Code gives security, IT, and engineering teams programmatic control to automate, configure, and manage their Cribl environment.

Use REST APIs, Python, Go, and TypeScript SDKs, or Terraform to onboard sources, build and maintain pipelines, and standardize workflows faster, at any scale, with no vendor lock-in.

Check out the docs
Cribl as Code Screen Image

Capabilities

Feature highlights

Collect.png
Collect

Get telemetry from any source

Cribl Stream is your telemetry butler, serving up any format for any of your analytics tools.

Use Stream observability pipelines as your universal receiver to collect from any data source: pull from all your agents and push-based sources, rapidly onboard new data using AI-guided schema mapping, collect telemetry from agents, batch endpoints, and APIs, and recall data from low-cost storage when you need it.

reduce.png
Optimize

Shed your data deadweight and give your licenses some breathing room

Control costs, improve performance, and optimize licenses by reducing log volume.

Filter out irrelevant events and fields using plain language, apply generic transformations, and auto-map schemas for analytics-ready data.

Use dynamic sampling to filter events or roll up logs into metrics to cut volume.

Keep a full-fidelity copy in low-cost storage or your data lake, and replay it when you need it.

shape.png
Shape

Get insights you can actually use

Turn your data into decision-ready information.

Translate and transform data from all of your sources into the formats your tools expect.

Enrich logs with third-party data for a more complete picture.

Stream collects from all of your sources and shapes it into actionable logs and metrics for analysis.

Route.png
Route

Send data to the teams and tools that need it

Send your data where it works best: Splunk Software, Elastic, New Relic, DataDog, or offload to Cribl Lake for long-term retention.

Route data to the right tools by translating it into the required formats, or use Packs to slash onboarding time.

Let teams pick their analytics environments without deploying new agents or forwarders.

replay.png
Replay

Store now, replay later

Replay data on demand from Cribl Lake, S3, or your favorite low-cost lake.

Store data affordably and pull it back only when needed for security audits, incident investigations, operational recovery, or just peace of mind.

simplifymanagement.png
Reduce

Reduce your operational footprint

Consolidate data flows into a central tier for collection, processing, and routing.

Simplify data management and ease the load on your teams while keeping full control of your data.

Differentiators

Key differentiators of Cribl Stream

DIRECTIONAL.SIGN.svg

Open

Ingest, transform, and route data without lock-in

Collect telemetry from any source, transform it as needed, and deliver it to any destination with confidence.

Onboard new tools without rolling out more agents or collectors.

search-icon.svg

Focused

Built for IT and Security data scale

Stream is purpose-built for the volume, velocity, and variety of logs, metrics, and traces in modern IT and security environments.

5_Analytics.svg

Performant

Engineered for petabyte-scale throughput

Process billions of events per second with sub-millisecond latency and massive scalability on-prem, in the cloud, or hybrid.

NETWORK.svg

Versatile

Fits any architecture, any workflow

Deploy Stream on its own or as part of a unified data engine that slots cleanly into your ecosystem.

Flexibly route, enrich, and reduce data to meet the needs of every team and tool.

Customer-Success.svg

Proven

Trusted by leading enterprises to deliver results

Cribl Stream is battle-tested in complex, global environments, reducing petabytes of daily data, cutting ingest and storage costs, and scaling from initial pilots to mission-critical deployments without re-architecture.

Customers rely on Stream to meet strict performance, compliance, and resiliency requirements while keeping optionality across their SIEM, observability, and data lake stacks.

FAQ

Frequently Asked Questions

Integrations

Streamline workflows

Stream + Edge.png
Edge

Optimize data at the source

Using Cribl Edge? Add Cribl Stream to further filter, process, and forward data so only high-value data reaches your analytics tools.

Handle massive datasets more efficiently while cutting bandwidth and storage costs.

Stream + Lake.png
Lake

Streamline data storage and access

Connect Cribl Stream with Cribl Lake for a unified data management experience that covers both real-time streams and your deepest data lakes.

Enhance storage and retrieval for stronger analysis and better decisions.

Tech Docs

Learn the ins and outs

2Resource - Docs - Cribl Stream.jpg

About Cribl Stream

3Resource - Docs - Basic Concepts.jpg

Basic Concepts

4Resource - Docs - Getting Started Guide.jpg

Getting Started Guide

7Resource - Docs - Distributed Quick Start Guide.jpg

Distributed Quick Start

8Resource - Docs - Deployment Planning.jpg

Deploying Cribl Stream Software

9Resource - Docs - Stream Tips and Tricks.jpg

Tips and Tricks

get started

Ready to get started?

Cribl Stream transforms how you handle data. Easily ingest, process, and route it to where it needs to go.

Start using Stream today to unleash the power of your data!

Forbes ABSE
FortuneCyber - Award
ForbesCloud -  Award
Deloitte 500 White - Award