Cribl LogStream – Docs

Getting started with Cribl LogStream

Questions? We'd love to help you! Meet us in #cribl (sign up)
Download manual as PDF - v2.2.0

    Docs Home


Cribl LogStream can receive data from various sources, including Splunk, HTTP, Elastic Beats, Kinesis, Kafka, TCP JSON, and many others.

PUSH Sources

Supported data sources that send to Cribl LogStream:

Data from these sources is normally sent to a set of LogStream Workers through a loadbalancer. Some sources, such as Splunk forwarders, have native loadbalancing capabilities, and these should therefore be pointed directly at LogStream.

PULL Sources

Supported sources that Cribl LogsStream fetches data from:

Internal Sources

Sources that are internal to Cribl LogStream:

Configuring and Managing Sources

For each source type, you can create multiple definitions, depending on your requirements.
To configure sources, click on Sources, select the desired type from the left menu, then click Add New.

Updated about a month ago


Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.