Source

Splunk Search

Schedule, execute, refine, and redact Splunk searches

Run simple or complex queries against Splunk software search heads, including real-time searches. Cribl’s integrations provide controls for scheduling searches, breaking events, and redacting and transforming event fields.

How Does It Work

This is a built-in integration between Splunk software Search and Cribl Stream’s Splunk software Search Source or Collector.

  • Configure Cribl Stream to read data from Splunk software Search via Sources > (Collector >) Splunk software Search.

  • Specify the search head/endpoint, query, schedule, output format, and optional authentication, Breaker, and other parameters.

  • Stream will start ingesting Splunk software data on the schedule you specify.

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s suite of products to collect, process, route, and analyze all IT and security data, delivering the flexibility, choice, and control required to adapt to their ever-changing needs.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on-Sandboxes for those interested in how companies globally leverage our products for their data challenges.