Case Study

How A National Energy Company Leverages Cribl Stream to Support Critical Infrastructure Around the Globe

star-round-framed
Highlights

“WE ORIGINALLY TRIED TO DO FILTERING ON THE HEAVY FORWARDERS, SO WE WERE EXCITED TO BE ABLE TO USE CRIBL FILTER PACKS INSTEAD. AFTER A SIMPLE PLUG AND PLAY, WE WERE UP AND RUNNING IN NO TIME.”

“THE ENRICHMENT CAPABILITIES OF STREAM MAKES IT EASY TO TAG DATA CORRECTLY AT INGEST, SO IT ENDS UP IN THE RIGHT DESTINATION AT THE END OF THE DAY.”

Share:

Heading the SOC, CERT Operations, and serving as the Incident Response manager at an energy company is undoubtedly a demanding and multifaceted role. Especially for a national energy provider that operates subsidiaries and critical infrastructure globally, spanning across various regions.

With enormous amounts of data comes great responsibility — which is why the SOC/Cert manager for this national energy company chose to implement Cribl Stream into their monitoring and security environments. Stream is described as:

“A pipelining technology that allows you to route data from any log source to any log consumer, and at the same time, filter it, clean it up, split it out, and do all kinds of funky stuff with it.”

The SOC/Cert manager has been routing data and doing the aforementioned “funky stuff” since the early days of Cribl. They implemented Stream while building the SOC for the organization. The energy company’s team manages and secures an air-gapped data center while partnering with an MSSP for alerting and Tier 1 response. Cribl’s routing capability makes it possible for the right data to get to the right destination to accelerate incident detection and response–ensuring no data is lost in the process.
A Pipeline Between Heavy Forwarders and Various Splunk Instances

The energy company has multiple Splunk instances in operation. Cribl Stream serves as the data pipeline that allows them to pump all of their traffic from various geographical locations both to regional instances for compliance and remediation, as well as to their central SOC, and then to their MSSP. Because they have traffic going to and from places all over the world–sometimes from regions with very low bandwidth-–they filter data in Cribl to clean data up at the source and contain their Splunk license as much as possible.

In a recent conversation with the SOC/Cert manager, they described how useful Cribl packs have been to operations across the business:

“We’re using them for all the firewalls and for Windows — Palo Alto Networks, FortiGate, Cisco ASA. It would have been an absolute nightmare to manage all of them without Cribl Packs.”

Since they’re running multiple pipelines for every data source, they also use Stream to enrich their data, tagging it correctly at ingest so that it ends up at the right index at the end of the day.
Cribl Cluster-to-Cluster Compression

If you’re running a site-to-site VPN internationally like the energy company is, compression becomes a necessity — otherwise, you could be wasting bandwidth on data you don’t really need. Because of the national importance of the data moving through their infrastructure, the team can’t afford to lose a single log, so they have some fairly large Cribl clusters running in various locations.

An added benefit for these regions with low bandwidth is Cribl Stream’s persistent queuing feature, which ensures no data is lost if networks go down. Stream spools the data ( retention is set to 7 days) and when the network comes back up the data ships to its intended destination.

Cribl Stream’s Fast Time to Value
When we asked the team how quickly they were able to see value from Stream, they were happy to share their thoughts:

“The minute we started piping stuff everywhere, we saw value instantly. It’s a product that has an immediate ROI. To give you context, I previously ran a 1.5TB Splunk license in this environment, and we were able to pull that down to a 1TB license. That's a 33% percent savings, so Cribl more than pays for itself.”

With Cribl Stream in place, the team feels confident that they are getting all the data they need and aren’t losing anything important along the way. If you’re looking for similar warm fuzzy feelings from your infrastructure, check out our Cribl Sandboxes to learn more about our solutions, and join our community to get support from other Cribl users.

TL;DR

About Cribl

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s vendor-agnostic solutions to analyze, collect, process, and route all IT and security data from any source or in any destination, delivering the choice, control, and flexibility required to adapt to their ever-changing needs. Cribl’s product suite, which is used by Fortune 1000 companies globally, is purpose-built for IT and Security, including Cribl Stream, the industry’s leading observability pipeline, Cribl Edge, an intelligent vendor-neutral agent, and Cribl Search, the industry’s first search-in-place solution. Founded in 2018, Cribl is a remote-first workforce with an office in San Francisco, CA.

Learn more: cribl.io
Try now: Cribl Sandboxes
Join us: Slack community
Follow us: LinkedIn and Twitter

Pixel Mask

So you're rockin' Internet Explorer!

Classic choice. Sadly, our website is designed for all modern supported browsers like Edge, Chrome, Firefox, and Safari

Got one of those handy?