Changelog: Cribl.Cloud Government
This page summarizes new and expanded capabilities added to Cribl.Cloud Government by release. For a full comparison of Cribl.Cloud Government and commercial Cribl.Cloud capabilities, see What’s Different in Cribl.Cloud Government.
Cribl.Cloud Government 4.20.0
Cribl AI Through a Custom AI Provider
Cribl.Cloud Government now supports Cribl AI through a Custom AI Provider that you configure and control. Every large language model (LLM) request goes to your provider endpoint, so no prompts or event context reach the Cribl AI backend. Cribl-managed models are not offered, and web search is unavailable. For the full set of differences, see AI in Cribl.Cloud Government.
Cribl Guard Background Detection
Cribl Guard background detection is now available in Cribl.Cloud Government. Detection runs locally on the Worker Node using regex rules and an in-house named-entity-recognition (NER) model, so it sends no event data to your AI provider and requires no Custom AI Provider. One approved detection model is available.
Search Insights: Lakehouse Engine and Usage Visualizations
Cribl.Cloud Government now includes lakehouse engine and usage visualizations in System Insights for Cribl Search, so you can see backpressure, queueing, and consumption without inferring them from query behavior:
- A new tab for lakehouse engines, with expandable Infrastructure and Volume sections. Infrastructure adds Pre-processing Load, a single series averaged across the compute that pre-processes events, and Backpressure, which plots one series per engine. Volume collects the existing volume panels and adds Inbound Data Volume, which you can scope to one engine with the Engine filter.
- A new Usage tab that holds the existing CPU*Hours panel.
- Avg Queue Time, Avg Time to First Byte, and Avg Search Duration panels on the Overview tab, each broken out by compute type, so you can separate the time a search waits from the time it runs.
Authentication Token Management
Cribl.Cloud Government now supports the authentication token mechanism for provisioning Worker Nodes and Edge Nodes. You can create multiple tokens, then rotate and revoke them to control which Nodes can connect to the Leader.
On upgrade to 4.20.0, existing deployments automatically receive one legacy type token set to the value of the existing auth token. No immediate action is required. Cribl recommends rotating the legacy token to a new provisioning token at your earliest convenience. As in commercial Cribl.Cloud, you can’t revoke the legacy token.
Cribl.Cloud Government 4.18.0
Lakehouse Engines with Search Datasets in Cribl.Cloud Government
Cribl.Cloud Government now supports the same lakehouse engines and Search Datasets as commercial Cribl Search. The new lakehouse engines use FedRAMP-approved, FIPS-compliant cryptography and stay fully inside the Cribl.Cloud Government boundary. The Lakehouses in Cribl Lake are being deprecated.
Federated Search v2 Datasets on the Federated Engine
Cribl.Cloud Government now supports federated search v2 Datasets with Search federated engines, bringing faster queries and clearer Datatype mapping to federated searches.
Insights
Cribl Insights is now enabled by default in Cribl.Cloud Government, at parity with commercial Cribl.Cloud.