We are using Cribl for log trimming with a vast majority of log sources that have different log patterns or log types. Some logs come in syslog format, some are in JSON, and some are in other HTML kinds of formats. We are using Cribl to streamline all the log formats and send the logs to Splunk, and we can also filter out the logs that are not required for us for security monitoring.
If logs from one device are sending us a lot of logs but we only need some events of interest for security monitoring, we can filter out the unnecessary logs and only forward those events of interest from Cribl to our SIEM solution.
Cribl has had a very positive impact on our organization. We are also using it for our cost cutting. The first benefit is cost cutting because we can filter out the unnecessary logs from the log sources, so we are only sending the events of interest to our SIEM solution for security monitoring. Most of the logs that are not necessary are filtered out within Cribl, which positively impacts the pricing of our SIEM solution.
The second benefit is that it has improved our security monitoring because Cribl is an augmented solution that can pull any log format, convert it, and send it to the SIEM solution. There is no requirement to have a specific log type to use Cribl. The third benefit is the filter option, which allows us to filter out the unnecessary logs.
In our organization, we are keeping the logging level of the firewall up to debug and forwarding all the logs from the firewall to our SIEM solution for security monitoring, so specifically for the firewall, we do not have any filtering in place in Cribl.
We can filter out the firewall logs if we keep the logging level up to informational, which would allow us to filter out all the debug logs through Cribl, which will definitely reduce the firewall traffic.
In our environment, we are handling around TBs of logs through Cribl, and it is handling everything perfectly fine. We have not observed any issues with traffic, log stoppage, system failures, or service failures related to Cribl, so everything is working fine.
The overall pipeline and the filtering option in Cribl are very good.
The complexity aspect is impressive; Cribl is already augmented and can receive any kind of logs with any format. It can handle almost all types of logs, which include Syslog, WMI, and all kinds of complex logs. It is particularly very good for complex logs where we have multi-line logs and large sources sending a significant quantity of logs; it is very helpful in that regard. Regarding the costing part, Cribl's charges are less than what we are saving in our SIEM solution, so ultimately, it is profitable for us.
Currently, Cribl is perfectly fine for us, and we have not observed any such issues. However, if we find anything later on, we will document it and share it with you.
Cribl could respond more quickly to email notifications to make the experience a nine or ten.
We have been working with Cribl for around eight months because we recently implemented it, so it has been six to eight months.
Cribl is a very stable product, and we have not observed any platform-related or internal service-related issues. It has been working fine since six to eight months, so we can say it is pretty stable.
We have not experienced any outages or crashes.
We can scale Cribl based on the log inputs we are providing. It is pretty much scalable, depending on when we want to scale it.
It has an option for scalability, so it is not an issue.
We often communicate with the technical support of Cribl.
They are very supportive and respond timely.
This is the first time we are using Cribl; previously we were directly sending logs to a SIEM solution. This is the first time we started using Cribl for that.
We were not personally involved in the implementation because there are multiple members on our team. One of our colleagues was involved along with Cribl resources to implement it. However, later on, once it was implemented, we got a chance to work on a few changes in Cribl.
In this particular area, we think Cribl is the only good solution partner, which is why we chose Cribl. There are no other applications that have that kind of capability like Cribl, as it is the industry-leading product as of now.
We went straight to Cribl and did not consider anything else.
We can share our feedback on Cribl.
We are a customer of Cribl.
Cribl is a pretty good solution. We did not face any challenges while working on Cribl.
Cribl is deployed on the cloud in our organization.
We are happy with the pricing that they offer.
Our review rating for Cribl is 9.