Use of Project with nested fields
I have a field that is nested. I can search with the full name without an issue but when I try to use it with project, I do not get any values back. I have tried to wrap the field with single and double quotes. That results in the value for the field to be the name of the field. The goal is to get a list of all the…
Data collected using REST Collector getting appended in a single file, how to resolve?
TLDR : JSON Collected from API, parsed through Pipeline, should have three JSON files in S3, but have two where one file have 2 JSON object appended, need help to find out the reason Hi All, At first, I want to say, no this is not an event breaker issue, as much as my understanding. Let me explain. I am trying to get some…
Is replay actually a feature in itself or just a technique implemented via a Source with different
Starting in version 4.3, Cribl Stream supports replaying data that has been exported as Parquet, using either the S3 Collector or the Filesystem Collector. Meanwhile, the Azure Blob Storage and Google Cloud Storage Collectors support ingesting data in Parquet format, but do not support replay. I am glad to see that Parquet…
Collect and Send S3 logs via Cribl to Splunk
Hello All, I'm new to Cribl and basically a Splunk Admin & developer. Been working on Cribl migration project for a while. My requirement is to collect data from a S3 bucket Via Cribl and apply some cool stuffs than send it to Splunk for indexing.Now, I have established the connection with my S3 bucket from Cribl stream.…
would it be possible to use the same encryption key in an Edge fleet and in a Stream worker group ?
Hi there,Question about encryption keys: would it be possible to use the same encryption key in an Edge fleet and in a Stream worker group ?I have a use case where we need to encrypt data at the source (Edge) and send it to a S3 compatible storage. Then I should be able to retrieve data from the S3 bucket using a collector…
Is there any info on Search costs when searching AWS S3 buckets?
Is there any info on Search costs when searching AWS S3 buckets? Specifically on how data transfer works. For example, does Search hit S3 from US East and is $.01 per GB against my AWS account? Is Search caching at all? Original post was from
Cribl Search to query S3 bucket - "Error initializing task queue"
Hi guys, we are trying to configure Cribl Search to query S3 bucket but have been facing error that says "Error initializing task queue" .... "Access Denied"We are seeing the Cribl Stream worker AssumeRole into our AWS account for the existing S3 Source Collector that we have configured previously but, we’re not seeing any…
Cannot get AWS S3 data destination to work on Stream - self-hosted
I can't get any of the data destinations to work. I have tried this with ElasticSearch, AWS S3 and Splunk. The message I get when I try a Test payload is "Error: 400-Bad Request Output … does not exist!" The logs don't have any information either. I'm running stream in a docker container. I got the same results on Cribl…
Can Cribl Stream read AWS S3 tags?
Can Cribl Stream read AWS S3 tags? I know there are multiple places where you can add tags to parts of the stream, such as in the Source or in a Pipeline, but I want my stream to be able to read the tags that are assigned via S3 in order to filter them. If that's not possible, would I be able to call a Lambda function and…
How do I create a Trust between my AWS Account and a Cribl Cloud instance?
This post will help you setup a trust between your Cribl Cloud instance and your AWS account. It follows the steps documented on the docs page for Cross-Account data collection. This Rapid Adoption CloudFormation template can help automate the trust between your Cribl Cloud stack and your AWS Account. In order to keep the…