Enrichment: Better Data in > Better Response Times Out

Shawn Cannon, Threat Management Consultant – Aflac

Context is king–that’s why optimizing your data, enriching it in the stream, and having the ability to see it and tweak it before sending it into analytics tools or storage can be a game changer. When you are reviewing or correlating the data to troubleshoot, run investigations and respond, think how much time your team can save by having the right geolocation, asset, timestamp and even threat intel already associated with the log data?

We had a fun time making this work–and you can too. We’ll show how you can set up and use a Redis cache along with Cribl Stream to enhance your data before sending it to its destination. We’ll cover how we imported a 34 million row CSV file into Redis and use the Redis function to match fields to records to add a new field that is used for faster identification of data once it is in Splunk.

Play Video

Don't let the party end!

CriblCon might be over, but the learning doesn’t need to stop.

  • Cribl Curious: A Q&A site for the for getting all of your sources to the right destinations
  • Cribl User Group: A Virtual meetup to connect with fellow Criblers from around the globe. Check out previously recorded sessions too!
  • Cribl Community: The jumping off page for all things Cribl education and community.
  • Cribl University: Find the right learning path and certification for you to start using and getting value from Cribl’s portfolio of products.

So you're rockin' Internet Explorer!

Classic choice. Sadly, our website is designed for all modern supported browsers like Edge, Chrome, Firefox, and Safari

Got one of those handy?