Cribl puts your IT and Security data at the center of your data management strategy and provides a one-stop shop for analyzing, collecting, processing, and routing it all at any scale. Try the Cribl suite of products and start building your data engine today!
Learn more ›Evolving demands placed on IT and Security teams are driving a new architecture for how observability data is captured, curated, and queried. This new architecture provides flexibility and control while managing the costs of increasing data volumes.
Read white paper ›Cribl Stream is a vendor-agnostic observability pipeline that gives you the flexibility to collect, reduce, enrich, normalize, and route data from any source to any destination within your existing data infrastructure.
Learn more ›Cribl Edge provides an intelligent, highly scalable edge-based data collection system for logs, metrics, and application data.
Learn more ›Cribl Search turns the traditional search process on its head, allowing users to search data in place without having to collect/store first.
Learn more ›Cribl Lake is a turnkey data lake solution that takes just minutes to get up and running — no data expertise needed. Leverage open formats, unified security with rich access controls, and central access to all IT and security data.
Learn more ›The Cribl.Cloud platform gets you up and running fast without the hassle of running infrastructure.
Learn more ›Cribl.Cloud Solution Brief
The fastest and easiest way to realize the value of an observability ecosystem.
Read Solution Brief ›Cribl Copilot gets your deployments up and running in minutes, not weeks or months.
Learn more ›AppScope gives operators the visibility they need into application behavior, metrics and events with no configuration and no agent required.
Learn more ›Explore Cribl’s Solutions by Use Cases:
Explore Cribl’s Solutions by Integrations:
Explore Cribl’s Solutions by Industry:
Try Your Own Cribl Sandbox
Experience a full version of Cribl Stream and Cribl Edge in the cloud.
Launch Now ›Get inspired by how our customers are innovating IT, security and observability. They inspire us daily!
Read Customer Stories ›Sally Beauty Holdings
Sally Beauty Swaps LogStash and Syslog-ng with Cribl.Cloud for a Resilient Security and Observability Pipeline
Read Case Study ›Experience a full version of Cribl Stream and Cribl Edge in the cloud.
Launch Now ›Transform data management with Cribl, the Data Engine for IT and Security
Learn More ›Cribl Corporate Overview
Cribl makes open observability a reality, giving you the freedom and flexibility to make choices instead of compromises.
Get the Guide ›Stay up to date on all things Cribl and observability.
Visit the Newsroom ›Cribl’s leadership team has built and launched category-defining products for some of the most innovative companies in the technology sector, and is supported by the world’s most elite investors.
Meet our Leaders ›Join the Cribl herd! The smartest, funniest, most passionate goats you’ll ever meet.
Learn More ›Whether you’re just getting started or scaling up, the Cribl for Startups program gives you the tools and resources your company needs to be successful at every stage.
Learn More ›Want to learn more about Cribl from our sales experts? Send us your contact information and we’ll be in touch.
Talk to an Expert ›Ed Bailey is a passionate engineering advocate with more than 20 years of experience in i... Read Morenstrumenting a wide variety of applications, operating systems and hardware for operations and security observability. He has spent his career working to empower users with the ability to understand their technical environment and make the right data backed decisions quickly. Read Less
A reference architecture is a lovely document, but they rarely help engineers and architects implement their tools effectively. Most reference architectures offer plenty of suggestions and ideas, but not enough context. We will explore ways to make reference architectures more useful while reducing reliance on the vague and dreaded “It Depends.
Cribl has just released its first official reference architecture. The authors worked hard to give you the context and guardrails to make sure your Cribl deployment is successful right from the start. I’ll supplement their efforts, by sharing a mental model on how to approach your first Cribl Stream deployment.
Reference architectures, no matter how comprehensive they are, fall short of providing engineers and architects the necessary context they need to succeed. Diagrams and data points might not be sufficient to guide you in a unique security and observability data environment. So much of the wandering through the wilderness of the reference architecture has to do with the open-ended nature of the document. The document cannot anticipate every requirement, resulting in broad guidance that can be challenging to implement practically.
This gap between generic guidance and a useful deployment architecture is a problem in technology that hinders teams from getting fast value from their new toy. Unfortunately, this leaves the team in FAFO mode, which is not useful and requires rework that diminishes the initial value of the tool.
After many years of doing this wrong, and earning an advanced degree in FAFO along the way, I finally figured out that the best method for getting value from a reference architecture is to start at the end. This does not make sense at first glance but will make more sense as I give an example or two.
The Cribl Reference Architecture gives you helpful guidance and formulas for deploying to production. But, deciding what to base your formulas on and what to design towards is a business conversation that cannot be entirely addressed in the reference architecture. So it’s crucial to follow some key steps and start at the end.
In the observability and security data world, it is common to base these formulas on daily data ingestion. This is a sound place to start since it is the baseline for minimum compute and storage requirements, but it’s more important to also consider a more critical factor related to your business needs. To address this, have a direct conversation with your business.
Your observability and security platforms are critical to monitoring your environment. It is how your teams see what is going on, so they can respond appropriately to issues and threats.
Answering these critical business-level questions is necessary to size and architect your deployment correctly.
Your team has opted for Cribl Stream to manage cost growth and improve data quality with the help of an advanced observability pipeline. As the data architect, you want to design the most optimal deployment architecture for your use cases. In addition to considering daily data volume, you also want to avoid the previous issues that occurred when a massive spike in data caused your infrastructure to fail.
Starting with the end in mind, you:
Your leaders will weigh the risks with the cost of mitigation and give you an answer. Most likely the right solution will fall somewhere in between where partial outages are prevented and major outages become partial outages.
Your leaders have set the goal of sizing for 2x normal data volume, at 20 TB per day, which gives you a clear requirement to design towards using the Cribl Stream sizing guide. Asking the right questions helps you set a concrete goal for your design, rather than just guessing. To avoid the risk of being wrong, work with your leaders and define your end state prior to deploying your new Cribl Stream architecture.
My advice for anyone going through this process for the first time is to be prepared for the possibility that you might not like the decision your business leaders give you. You might feel like they are not listening to you. Remember their job is to base their decisions by weighing costs vs risk, and your job is to bring these risks to their attention. If your concerns are not addressed, it’s important to let it go and not let it consume you. Not every risk can be addressed, and that’s just a reality. However, make sure to document your concerns through emails and memos. This will come in handy when chaos ensues and you need to explain why a certain issue occurred. Then you get to wave the emails in the air when the same leaders want to know why your security monitoring failed during high load. It will make you feel better and maybe next time the leaders will listen to you.
To speed up the deployment process, begin by defining the desired end state with your business leaders. Clear requirements are crucial for the successful deployment of any new tool. Ask your business leaders the right questions, and then work backward so you know how to implement the tool’s reference architecture to get the best results for your team.
I’d love to hear your feedback on getting started with Cribl Stream. Feedback is a gift, and I want to know if something doesn’t make sense or if I’m not covering something. Connect with me on LinkedIn or join our community Slack, and let’s talk about your experience deploying Cribl Stream.
Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s suite of products to collect, process, route, and analyze all IT and security data, delivering the flexibility, choice, and control required to adapt to their ever-changing needs.
We offer free training, certifications, and a generous free usage plan across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started. We also offer a hands-on Sandbox for those interested in how companies globally leverage our products for their data challenges.
Experience a full version of Cribl Stream and Cribl Edge in the cloud with pre-made sources and destinations.
Classic choice. Sadly, our website is designed for all modern supported browsers like Edge, Chrome, Firefox, and Safari
Got one of those handy?