Try our new research platform with insights from 80,000+ expert users
Senior Splunk Admin at a consultancy with self employed
Real User
Top 20
Collects and sends the logs directly to the cloud and has free training
Pros and Cons
  • "Cribl offers other valuable features. For instance, you can replay data from an edge device, store your daily data in a stream, and replay specific event data into Splunk if a security incident occurs"
  • "Cribl doesn't have as many packs available"

What is our primary use case?

We use Cribl for multiple purposes. One key use is migration to Splunk Cloud. Traditionally, we used Splunk as an intermediate forwarder but switched to Cribl for this role. Cribl collects and sends the logs directly to the cloud, forwarding all data to Splunk Cloud. 

Another advantage is the ability to extract only the necessary data visually rather than handling it in Splunk's Props. You can see the changes you're making and directly onboard specific logs, avoiding the need to onboard all data.

Additionally, Cribl offers other valuable features. For instance, you can replay data from an edge device, store your daily data in a stream, and replay specific event data into Splunk if a security incident occurs. This targeted replay allows for analysis without onboarding all data into Splunk, providing a significant cost-saving benefit.

What is most valuable?

You deploy the pops and see it effectively on the page. There are functions that you can deploy in the pipeline, and you can sample that particular function. For instance, if I'm deploying a function like an A or JSON function, I can test it live before deploying it into production. This allows us to play with the data and verify if the outcome is as expected, ensuring that the processed data matches the anticipated raw data amount. 

Additionally, if you want to push an upgrade in the recent four-star version, you can update all other worker groups directly from the master rather than updating each part separately. You can instruct the master to push the update to all other workers, eliminating the need to push the update to individual nodes.

What needs improvement?

Cribl has a good community base, but unlike some vendors like Splunk, which has many TAs, Cribl doesn't have as many packs available. They need to focus on developing more custom packs for various vendors so that their solutions can be used more effectively. This will help users identify which logs are necessary and which are not. 

For how long have I used the solution?

I have been using Cribl for the past three years. We are using the V4.1.2 of the solution.

Buyer's Guide
Cribl
July 2025
Learn what your peers think about Cribl. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
864,155 professionals have used our research since 2012.

What do I think about the stability of the solution?

Cribl is a pretty stable product.

How are customer service and support?

Support is quite good. If you notice an issue and report a case, they respond promptly. If there is a problem, they raise it internally, develop a fix, and push it to production immediately. Their turnaround time is also critical.

How was the initial setup?

The initial setup is easy if it is planned.

What's my experience with pricing, setup cost, and licensing?

It's cheaper than Splunk.

What other advice do I have?

Cribl has had a positive impact on reducing the need for multiple support services. It simplifies collecting log data from various cloud vendors in a single place, which is much easier than configuring, managing, and maintaining a database for a Splunk add-on. Cribl has made it easier to handle log data.

It takes about two months to get fully up to speed. Cribl provides free training and offers sandboxes for practice, allowing you to gain the necessary knowledge. Once trained, you can start working right away.

Overall, I rate the solution a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2741781 - PeerSpot reviewer
Works at a tech vendor with 10,001+ employees
Real User
Enables us to gain control over data flow and optimizing log management across multiple destinations

What is our primary use case?

Entire logs from my organization go through Cribl and get routed to Splunk and various other destinations. I use it on a large scale in my organization. Cribl Stream is one of my favorite parts. I use Cribl to route the logs to various destinations. It helped us to completely remove the monopoly on Splunk. Not only firewall logs, but also cloud trail logs and many other logs were processed through Cribl.

What is most valuable?

It helped us to completely remove the monopoly on Splunk, as we previously couldn't have any control over logs and how to optimize them. When we had Cribl in place, it provided a vision and a platform for us to control what we send and how we send it in terms of data passing, data enrichment, and many more things, with massaging the data. It also helped us to open up to many tools where we could send the data to various destinations, as it is vendor-agnostic.

What needs improvement?

Cribl Stream is good, but I feel they could develop more products apart from Cribl Stream for my use case. I know Search is coming and Data Lake is there, but there can be more innovations in Cribl. They had one good product, which is Cribl Stream, which appears to be the primary revenue source for the company, but there may be many other use cases. They could explore OTel and how to connect with DynaTrace. They are looking specifically for logging, but expanding into metrics and APM would also help.

For how long have I used the solution?

I have been using Cribl for the past three to four years.

What do I think about the stability of the solution?

On-premises deployment is something which customers take care of themselves. Earlier versions had quite a few issues, but there are more stable versions now, so it is a good time to start using Cribl.

What do I think about the scalability of the solution?

They are very scalable and good.

How are customer service and support?

They are very good in terms of solving issues. Regarding availability over other time zones, since it is mostly focused on Europe and US, they are starting to build up in New Zealand and other places.

How would you rate customer service and support?

Which solution did I use previously and why did I switch?

I tried a few other alternatives as POCs, but none of them worked out as effectively as Cribl.

How was the initial setup?

We worked on it for six months. Our infrastructure is complex, so it took almost six months, a couple of quarters.

What about the implementation team?

If you have a good architect and a couple of Cribl staff members to assist, three persons can handle the implementation.

What was our ROI?

It is feasible and doable. Compared to Splunk, Cribl is cheaper.

What's my experience with pricing, setup cost, and licensing?

Pricing is feasible and doable. Compared to Splunk, Cribl is cheaper.

Which other solutions did I evaluate?

I tried a few other alternatives as POCs, but none of them worked out as effectively as Cribl.

What other advice do I have?

It has been able to perform to the best of its capabilities. They are able to handle everything with their non-shared architecture. On a scale of 1-10, I would rate Cribl a solid nine.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Cribl
July 2025
Learn what your peers think about Cribl. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
864,155 professionals have used our research since 2012.
Maciej Grabowski - PeerSpot reviewer
Architect at Sii Polska
Real User
Top 20
Provides impressive architecture and easy setup but have administrative issues
Pros and Cons
  • "The support team was very helpful and managed to get everything production-ready."
  • "There have been several administrative issues. Another point is that the browsing functions aren't very intuitive."

How has it helped my organization?

We've encountered several challenges, but what's most promising and encouraging is Cribl's scalability. The architecture is impressive, and it distributes work across all worker nodes and communicates with the leader.

What needs improvement?

There have been several administrative issues. Another point is that the browsing functions aren't very intuitive.

The most challenging aspect is the versioning system. Everyone can see and potentially deploy each other's changes in a team of developers. Unlike traditional versioning systems, where you work in isolated feature branches and only merge changes after reviewing conflicts, Cribl's versioning system requires careful management because everyone works on the same repository. 

I work with a team that includes both experienced and less experienced developers. Though new to this technology, the two senior developers have extensive experience with various other technologies and can get up to speed relatively quickly with the available training. The less experienced developers face significant challenges. They struggle to understand the system, suggesting it may not be intuitive.

For how long have I used the solution?

I have been using Cribl for two years.

What do I think about the stability of the solution?

I rate the solution’s stability a seven out of ten.

What do I think about the scalability of the solution?

10-15 people are using this solution.

How are customer service and support?

Everything works, but it required a lot of support. The setup wasn't easy, but the support team was very helpful and managed to get everything production-ready. 

How was the initial setup?

Setting up Cribl for basic training is straightforward and effective. You can easily configure it on your laptop by downloading the binaries and using simple command-line instructions to set it up in different modes, like leader, edge node, or single deployment. Adding a worker node is also simple; just run a script generated in the UI, and it's up and running.

The enterprise setup process is more complex, and there are significant documentation challenges. Despite the system eventually being available, the process involved many support calls and workarounds. Getting everything set up for a production-ready enterprise deployment was long and challenging.

What other advice do I have?

In some of the projects I've been working on, we're still testing and exploring Cribl's capabilities. We haven't established specific business goals or fixed objectives yet. Currently, we're focused on ingesting data from various sources with minimal transformation to understand how Cribl handles different types of logs and data.

I encounter issues with the UI not accurately reflecting the current status. For example, the UI might show that a worker is still fetching the latest version of the code, but after refreshing the page, it usually updates to show that everything is up and running. Over time, I've learned to recognize when the UI is not displaying the correct information and use the refresh button to get the accurate status.

Overall, I rate the solution a six out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2540610 - PeerSpot reviewer
Security Engineer at a tech services company with 51-200 employees
Real User
Top 20
Offers efficient log management but has room for better documentation
Pros and Cons
  • "The capability to reduce logs in a user-friendly manner is a standout feature. Cribl allows us to view logs live as they are being processed, giving us quick feedback on the changes made."
  • "There is room for improvement in the documentation and knowledge base, particularly regarding configurations like sources where logs are being ingested"

What is our primary use case?

I use Cribl to ingest logs from different platforms. These logs could come from sources like Mimecast, Windows, or CrowdStrike logs. It acts as a pipeline to send data to our destinations and also helps in reducing the amount of logs sent by applying different functions on them.

How has it helped my organization?

Cribl has helped to save thousands of dollars for our clients. It provides cost-effective solutions, particularly when you know how to use it effectively. It does require some learning to cover all aspects of it because it's not entirely intuitive. However, once you overcome the learning curve and get hands-on with the platform, it significantly contributes to cost savings.

What is most valuable?

The capability to reduce logs in a user-friendly manner is a standout feature. Cribl allows us to view logs live as they are being processed, giving us quick feedback on the changes made.

Additionally, the data routing feature is beneficial because it gives us the option to send logs through data routes or QuickConnect, facilitating quick configurations of different sources and managing them more effectively. These functionalities offer logical and useful capabilities such as deciding where logs should be sent and specifying which fields should be included within the logs.

What needs improvement?

There is room for improvement in the documentation and knowledge base, particularly regarding configurations like sources where logs are being ingested. It would be helpful to have specific guidance on configuring different data sources, such as AWS S3 buckets. Additionally, the ability to understand what type of output a function will produce is missing in Cribl, which could be improved by indicating the output type.

For how long have I used the solution?

I have been using Cribl for more than one and a half years.

What do I think about the stability of the solution?

Cribl's stability has been well documented online, and we have not encountered any significant stability issues.

What do I think about the scalability of the solution?

We have tested Cribl and found it to be sufficiently scalable for our needs.

How are customer service and support?

At the time I was trying to do the course back then, I did escalate questions to tech support, but I haven't raised any recent issues.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have experience with Splunk and CrowdStrike. I am quite familiar with Splunk.

What was our ROI?

Cribl is indeed a cost-effective solution, saving thousands of dollars for our clients. It provides value through cost savings and time efficiency once users know how to effectively use the platform.

What other advice do I have?

It's important to know what source you will be using to ingest data into Cribl. Understanding how to configure the data source is key before using the platform. Once you have that figured out, Cribl becomes a powerful solution that can ingest almost anything with its Edge capability. However, having a clear understanding of the pathways you can take to ingest data is crucial before diving into it.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user