About the Integration
Cribl adds a native Sysdig Cloud NSS source so teams can ingest Sysdig data into Stream through a dedicated HEC-based source tile instead of a generic connector pattern. Paired with the Sysdig pack for OCSF transformation, the integration helps joint customers normalize, control, and route Sysdig telemetry into SIEMs, threat analysis tools, and long-term retention platforms.
Key Features & Use Cases:
Ingest Sysdig Cloud NSS data through a native Sysdig-branded source tile.
Reuse the existing HEC protocol for faster onboarding and simpler deployment.
Transform Sysdig data toward OCSF using the paired Sysdig pack.
Route normalized Sysdig telemetry to SIEM, retention, and threat-analysis workflows downstream.
How to Get Data Flowing:
Create the Sysdig Cloud NSS source in Cribl Stream, choose a worker group, and configure the listener address, port, and HEC endpoint path for the feed.
Add one or more auth tokens for Sysdig to use, and enable TLS if you want Sysdig to send over HTTPS.
Save the source, commit and deploy the configuration, then create a Cloud NSS HEC feed in Sysdig Secure that points to http(s)://<host>:<port><hec-endpoint> with the token in the Authorization header.
Send Sysdig data to the supported /event or /raw endpoint, depending on whether you are forwarding structured HEC JSON or CSV/raw JSON payloads.
Verify ingestion with Live Data and logs, and confirm your firewall allows inbound traffic from Sysdig’s regional outbound IPs and that ACK is not requested because this source does not support HEC indexer acknowledgements.