-
Maintenance Release - Version 4.7.2
A new maintenance release is ready for you. Some hi-lights: Cribl Stream In-Product Sizing Calculator: We’ve introduced an in-product sizing calculator for Cloud worker groups. This new feature will help you efficiently size and optimize your deployments. Cribl Edge PowerShell Support for Windows Edge Nodes: You can now…
-
Cannot POST /api/v1/search/jobs
In both the API Reference (with authenticated session) and via Python, I started running into an issue with submitting queries to the POST /search/jobs API to submit a remote query to Cribl Search. Despite the fact that it's a POST endpoint, and I'm using the headers generated by the API Reference, I receive the following…
-
How to pass syslog message without additional timestamp
I am trying to forward an exact duplicate of the syslog message. I have the route going thru passthru to not change the data. But I am getting the timestamp and original message host added to the message. Thoughts? Source: Syslog on 514/tcp/udp. Pipeline: passthru Source Data: <164>:Jul 23 12:34:15 CDT: %ASA-auth-4-987654:…
-
Issue: Can't forward syslog messages from custom app to Cribl Cloud
I have an application which is running on a Virtual Machine & this app is responsible for generating syslog messages. My goal is to forward these syslog messages to a source configured on Cribl Cloud. I went through the documentation, however I am not able to understand that how can I forward these messages. I know the…
-
Encoded Space char as %20 on Collect URI
Hi, I have an API endpoint which require parameter to use a time string in the format of %Y-%m-%d %H:%M, which e.g. look something like this: https://host/api/v1.0/endpoint?start=2024-06-21 14:00&end=2024-06-21 15:00 However when I put this on the URL, it always get converted to a value of 2024-06-21%2014:00 using example…
-
Unable to get collection tasks to run after Discover on REST API Collector
I have a REST API Collector which look at retrieving a number of records containing an ID which then need to be fed into a collection task as input for a 2-stage API call. While the Discover task has successfully retrieved the records with the ID, and I can see that in debug log the collection task has pick up the ID and…
-
Debugging POST Body for HTTP REST Collector
I'm getting 400 responses on a POST Body that I'm trying to pass through the state.latestTime within the POST body. I would like to know what is being posted. I don't seem to be able to get a debug log out of my REST Collector to see what it is POSTing. What it's deriving from state.latestTime. Anyone know where I can find…
-
S3/Blob storage folder selection as source
Hi Team, I am a Cribl Certified Engineer and have been working on a use case which is described below, but I haven't achieved the expected output. The use case involves an S3/Blob Storage where we have one bucket containing 2-3 folders. The source should be a specific folder, and from that folder, I need to ingest data to…
-
Search Configuration help - CloudTrail S3 bucket path and search
I'd like to search a CloudTrail S3 bucket. What I want to search is "in all accounts" and only in "US-EAST-2" region for event name:"Assume Role". I'm not sure if I configured the Dataset correctly and/or how to do the search. Regarding the Dataset bucket path. This is the S3 folder layout:…
-
Cribl Stream Worker on RHEL with SELinux
Hi, have anyone successfully deployed Cribl on RHEL based host that comes with SELinux enabled? While I have managed to get Cribl manually run, I've hit into issues when trying to enable Cribl on boot as a service. Looking at the entries from "journal -xe", it's throwing up errors to do with SELinux denying the processs…
-
Cribl Stream - Collect journalctl events with a Splunk UF to Cribl Stream in individual events
Hello, Here I have a small picture of how the environment is structured: Red arrow -> Source Splunk TCP (Cribl Stream) I'm trying to forward the journald data from the Splunk Universal Forwarder to the Cribl Worker (Black to blue box). I have configured the forwarding of the journald data using the instructions from…