Home
›
General Discussions
We have updated our
Terms of Service
,
Code of Conduct
, and
Addendum
.
General Discussions
Discuss general Cribl topics with your peers.
«
1
2
3
4
5
6
7
…
14
»
Discussion List
Anyone have a good set up for querying Azure AD?
Answered ✓
Tony Reinke - Cribl
2.9K
views
1
comment
0
points
Most recent by
Tony Reinke - Cribl
September 2023
Cribl Stream Leader on Fargate, the container keeps running with unhealthy health check.
Answered
Joel Yue
2.9K
views
1
comment
0
points
Most recent by
Tony Reinke - Cribl
September 2023
Injesting sysmon logs via Elastic API and events are getting dropped
Answered
Joel Yue
2.6K
views
1
comment
0
points
Most recent by
itsjustjordyn
September 2023
Would my destination see the srcIP field as a string or as an IP field?
Answered
wcall_cribl
9.5K
views
9
comments
0
points
Most recent by
itsjustjordyn
September 2023
Any reason my leader doesn't want to grab 4.03?
Answered
JP Bourget
3.5K
views
2
comments
0
points
Most recent by
Ben Marcus
September 2023
Moved: Processing Syslog messages and sending to Splunk
Closed
Michael Donnelly
1
view
0
comments
0
points
Started by
Michael Donnelly
September 2023
Dynamic Date in API URL
Answered
Tony Reinke - Cribl
2K
views
1
comment
0
points
Most recent by
Ryan Hennessy
September 2023
Moved: would it be possible to use the same encryption key in an Edge fleet and in a Stream worker …
Closed
Maliha Balala
1
view
0
comments
0
points
Started by
Maliha Balala
September 2023
Is there documentation for implementing local storage archival and replay functions?
Answered ✓
Neil Parisi
4.1K
views
6
comments
0
points
Most recent by
xpac xpac
September 2023
how would i configure encryption from a splunk uf to cribl cloud?
Answered ✓
Franky Laarits
3.2K
views
4
comments
0
points
Most recent by
Jon Rust
September 2023
Is it possible to configure Cribl to sign the commits to Github?
Answered ✓
Closed
Eugene Katz
1.7K
views
1
comment
0
points
Most recent by
Ben Marcus
September 2023
Recurring UI problem with one worker group. Leader restart helps temporarily.
Answered
Eugene Katz
16.6K
views
19
comments
0
points
Most recent by
Eugene Katz
September 2023
For wildcards to reference existing field names in an eval, how do you reference those field names?
Answered
Brett Windom
3.3K
views
3
comments
0
points
Most recent by
Ahmed Kira
September 2023
Troubleshooting file monitor permission issue
Answered
Ryan Hennessy
7.9K
views
11
comments
0
points
Most recent by
Ryan Hennessy
September 2023
Query on simplifying JSON to CSV conversion.
Answered
hgoolya
7.2K
views
12
comments
0
points
Most recent by
hgoolya
September 2023
is there a way to remove the metric event but still send it to splunk not as a metric
Answered
Ahmed Kira
11.5K
views
14
comments
0
points
Most recent by
Ahmed Kira
September 2023
Can I add a field that isn’t added to _raw, like not show up in the JSON that is the event?
Answered
Jon Rust
14.7K
views
19
comments
0
points
Most recent by
Jon Rust
September 2023
Has Cribl considered Panther as a new possible Destination?
Answered
Eugene Katz
9.9K
views
11
comments
0
points
Most recent by
Eugene Katz
September 2023
Optimize sourcetype assignment in pipeline
Answered
Franky Laarits
5.4K
views
5
comments
0
points
Most recent by
Franky Laarits
September 2023
Is there a way to do POST to Cribl api endpoint (`/api/v1/version/sync`) from pipeline/destination?
Answered ✓
Closed
Martin Prado
5.8K
views
6
comments
0
points
Most recent by
Martin Prado
September 2023
Is there an easy way to view all the HEC tokens in a HEC source?
Answered
Shawn Cannon
3.3K
views
3
comments
0
points
Most recent by
Shawn Cannon
September 2023
Best practice when adding event breakers to sources with different teams using the same source?
Answered
Franky Laarits
3.7K
views
3
comments
0
points
Most recent by
Franky Laarits
September 2023
Does Cribl have a checkpoint feature, similar to Splunk's fishbucket feature?
Answered
Robbert Hink
7.2K
views
7
comments
0
points
Most recent by
Brandon McCombs
September 2023
is there a function that works with tabular data, like `top` output from linux?
Answered
Franky Laarits
7.5K
views
9
comments
0
points
Most recent by
Franky Laarits
September 2023
Moved: How do the Windows Edge Nodes extract Windows Event logs and forward them to Cribl?
Closed
Maliha Balala
1
view
0
comments
0
points
Started by
Maliha Balala
September 2023
Are there default limits for JSON processing and are they tunable?
Answered
Jeremy Prescott
17.6K
views
20
comments
0
points
Most recent by
Brandon McCombs
September 2023
Preserving dual values for a field in parser function extract mode.
Answered
Eugene Katz
16.6K
views
19
comments
0
points
Most recent by
Eugene Katz
September 2023
Query about global variable behavior with event values
Answered
Eric Reusche
15.4K
views
25
comments
0
points
Most recent by
Eric Reusche
September 2023
i applied a scheduler but it's not working
Answered
lstropole
2.5K
views
2
comments
0
points
Most recent by
Paul Dott
September 2023
does cribls collector for rest api support jwt?
Answered
Thomas Vogt
6.6K
views
8
comments
0
points
Most recent by
Jon Rust
September 2023
«
1
2
3
4
5
6
7
…
14
»
Categories
All Categories
7
Announcements
1
AppScope
15
Cloud
33
Edge
17
Search
239
Stream
9
Packs
2
University
393
General Discussions
Job Board
Popular Tags
Stream
93
Edge
43
Search
22
Splunk
19
AWS
16
Syslog
15
S3
13
API
12
Cribl
11
Cloud
11
Windows
11
Pipeline
10
Packs
8
JSON
8
User Groups
7
CriblCon
7
Rest Collector
7
Leader
6
Azure
6
RegEx
6
AppScope
6
Collector
5
Workers
5
Community
5
fields
5