About the Integration:
Cribl gives AWS-first teams a native Bedrock source tile for bringing model invocation logs and audit data into Stream without stitching the collection flow together manually. The integration makes Bedrock telemetry easier to operationalize for security, governance, and AI observability workflows.
Benefits and Use Cases:
Collect both Bedrock invocation activity and audit-oriented AWS log data from a single native source experience.
Route and process LLM telemetry in Cribl Stream before sending it downstream
Support troubleshooting, usage analysis, and cost monitoring for Bedrock-based apps
Redact sensitive prompt and completion content before delivery to analytics and observability tools
How to Get Data Flowing:
Enable Amazon Bedrock model invocation logging and the related AWS audit logging you want Cribl to collect.
Configure the AWS-side S3 and SQS pattern the integration expects so new Bedrock data is written to S3 and announced through queues.
Create the Amazon Bedrock API Source in Cribl Stream and set the AWS region, IAM role, and queue values used by the Bedrock pack inputs.
Connect the source to your pipelines so you can parse, filter, enrich, or mask Bedrock activity before routing it downstream.
Verify that both invocation and audit events are arriving, and confirm the worker group has outbound access and the right AWS permissions for S3 and SQS.