AI is so hot right now. More data, more problems am I right? Anyway, Cribl 4.19 adds some AI stuff and some not AI stuff. I know you’re just so antsy to read what’s new that you probably skipped this intro paragraph. I won't keep you any longer. Go get ‘em champ!
If you made it this far in the five sentence intro, go check out #talk-telemetry-gatherers in our community slack, it’s pretty cool.
Cribl.Cloud
App layer
Cribl’s app framework gives you a new way to create tailored Cribl experiences that match your own workflows. You can now build and install custom apps right inside Cribl, using Cribl APIs and AI-assisted tools like Cursor to create focused UIs, dashboards, and workflow shortcuts that reflect how your teams work. Apps can be developed locally, previewed live in Cribl, and imported through files, URLs, or Git repos.
With our app layer, you can shape Cribl around the way you actually work. Instead of forcing every team into the same product flow, our app layer lets you create lightweight, purpose-built experiences that tap into Cribl’s underlying platform for recurring tasks or environment-specific workflows. That means faster internal workflows, more room for tailored use cases, and a practical path to extend Cribl without building and maintaining separate tools.
Cribl-managed MCP
Cribl’s MCP server is now embedded directly into the Cribl Leader as a Cribl-managed capability, making it a first-class platform feature instead of a separately deployed via Docker. You can now easily connect MCP-compatible AI tools and agents to Cribl using existing authentication, access controls, and administrative settings. This provides a simpler, more secure, and more enterprise-ready path for AI-driven workflows on top of Cribl.
Cribl Insights pt. 2
You can enable monitoring, metrics, and alerting for non-main Workspaces in addition to their main Workspace. Your teams gain visibility into the Workspaces that run their business, including dev, test, and production environments. This helps you monitor Workspace health more consistently, reduce operational blind spots, and move faster.
Multi-region Workspaces
Now you can provision Workspaces in any supported region, independently of the Organization region. If you have global footprints, you can now locate Workspaces within geographic and political boundaries as needed to meet standards for compliance, data residency and sovereignty, and local processing. You gain more control over where data is processed and stored, making it easier to meet data residency, sovereignty, compliance, and performance requirements across global teams and environments.
Stream
Centralized credentials
You can define credentials once and retrieve them from HashiCorp Vault or Cribl’s built-in secret store for use across Stream and Edge. Manage shared credentials from one governed location instead of copying them into individual configurations. Your security and operations teams gain a cleaner, safer way to manage credentials at scale, reducing credential sprawl and simplifying rotation. Keep your secrets out of your GitOps pipelines and config files, without breaking your deployment flow.
Edge
Cribl API expansion
Cribl is expanding its public API with Edge‑focused endpoints so you can drive Edge configuration and lifecycle operations programmatically. From scripts or automation tools, your teams can list and manage Edge Nodes, push updates, and integrate Edge control into their broader platform workflows. Platform and automation teams can now treat Edge as part of their standard infra-as-code and tooling stack. That makes it easier to roll out changes consistently, tie Edge actions to CI/CD or orchestration pipelines, and reduce manual, click‑driven administration when fleets grow.
Search
Schedule Jitter
Schedule Jitter smooths out system load by preventing scheduled searches from all running at the same time. By introducing a controlled, random delay (shut up, it makes sense) within a configurable window, it spreads execution across the hour instead of creating a spike at the top of the hour. This reduces burst pressure and intermittent slowness while preserving the intended search time window, helping teams maintain reliable performance without data gaps or overlaps.
Integrations
Amazon Bedrock
Cribl now includes a native Amazon Bedrock Source tile in Stream, making it easier to collect Amazon Bedrock model invocation logs and audit logs through the existing AWS Bedrock integration. The initial release is built on an S3/SQS ingestion pattern using the cribl-aws-bedrock-io Pack, with dedicated inputs for invocation and CloudTrail data.
Snowflake
Snowflake now exists as a native Cribl Destination, allowing teams to stream data directly into Snowflake’s streaming service without relying on Kafka or S3-based ingestion patterns. The initial release supports configuring a Snowflake Destination per table for a more direct and streamlined integration.
Google BigQuery
Google BigQuery also gets a Destination tile, allowing your teams to stream data directly from Cribl Stream into BigQuery tables without first routing through Google Cloud Storage. The initial release supports configuring the GCP project, dataset, table, location, ingestion mode, and authentication for a more direct BigQuery integration.
IBM Cloud Object Storage
We’re adding a native IBM Cloud Object Storage destination to Cribl, making it easier to send data directly to IBM COS with a purpose-built integration rather than depending on generic S3 compatibility.
Conclusion
Wow. That sure is some cool stuff! I can’t believe you read it all straight through with no AI summarization! I’m proud of you. If you haven’t already, go check out the accompanying “On Release Days We Wear Teal” YouTube video for this release / blog. Leon is pretty funny, too (no he didn’t bribe me to say that). Make sure to stop by in another two months to check out What’s New then, too. XOXO Cribl Girl.








