“WE ORIGINALLY SAW STREAM AS A VISUALLY FRIENDLY TOOL FOR PROPS AND TRANSFORMS ON THE FLY, BUT IT GREW FROM THERE. WITH THE DIFFERENT CAPABILITIES IN ENRICHMENT AND DATA ROUTING PIPELINES, IT’S TURNED INTO A TOOL THAT’S DOING A LOT OF GOOD FOR US.”
Some types of data, like time series or machine data, do really well in a tool like Splunk — while other, more voluminous sources are better suited for a destination like Elastic. Routing larger or text-based data sources to Splunk can cause formatting issues that slow down searches, so it’s important that each source ends up in the best tool for the job or team analyzing the data.
The agency is also using Cribl Stream to enrich data at ingest time to fully replace the custom Python script they currently use. Instead of running that script and dealing with MaxMind lookups and MaxMind database (MMDB) files manually, they use Cribl Stream to add geolocation tags to events.
This strategy will have a number of benefits — enrichment at ingest saves time and processing resources resulting in faster analysis of very large data sources. There are also time savings on the back end:
Since not all logs come with properly formatted timestamps, the agency will be able to rely on Cribl Stream to ensure they’re accurate. Reliable timestamps will assist investigators in creating more precise case timelines as well.
Cribl makes open observability a reality for today’s tech professionals. The Cribl product suite defies data gravity with radical levels of choice and control. Wherever the data comes from, wherever it needs to go, Cribl delivers the freedom and flexibility to make choices, not compromises. It’s enterprise software that doesn’t suck, enables tech professionals to do what they need to do, and gives them the ability to say “Yes.” With Cribl, companies have the power to control their data, get more out of existing investments, and shape the observability future. Founded in 2018, Cribl is a remote-first company with an office in San Francisco, CA. For more information, visit www.cribl.io or our LinkedIn, Twitter, or Slack community.