Benefits of the Integration
Stronger security insights: You can ensure that only high-fidelity, well-structured data from across a virtually unlimited catalog of data sources lands in Fabric Eventstream, improving detection accuracy and accelerating investigations.
Lower operational costs: Filtering and routing only the data that you need helps avoid paying to ingest, store, and analyze redundant or low-value data in Fabric.
Faster analytics and decision-making: With clean, enriched data, teams can build dashboards, run queries, and operationalize insights more quickly.
Read the integration blog post: https://cribl.io/blog/better-together-cribl-and-microsoft-fabric-just-got-radically-simpler/
How to Get Data Flowing
This is a built-in integration with a dedicated Cribl data source in the Real-Time hub in the Fabric portal.
Select "Cribl" from the list of sources and Fabric will provision everything for you
After provisioning Eventstream in the Fabric portal, configure the Fabric Real-Time Intelligence destination in Cribl Stream
Configure the generic and optional settings
Copy the bootstrap server, topic, and connection string from the Cribl Source you created in the Fabric portal.
The SASL JASS password will go under “Authentication” and will be stored in a secret.
Stream will start sending data as it becomes available