Internal Logs
Cribl Stream writes internal logs that record its own processes, API activity, configuration changes, and data handling. These logs provide valuable insights into system health, performance, and potential issues.
Distributed deployments write logs for the Leader, each Worker Node, and supporting services. Single-instance deployments write a smaller set of the same logs.
The sections on this page list where Cribl Stream writes an internal log. The following pages include an example event and field details for each log:
Several logs listed on this page are exposed only in customer-managed (on-prem) deployments. In Cribl.Cloud, Leaders support Cribl Stream Worker Node logs on hybrid Workers.
However, Members who have the Admin Permission on Cribl Search can use it to search the
cribl_internal_logsDataset for additional details about the Leader.
Leader Node Logs (Distributed)
The API/main process emits the following logs into the Leader Node’s $CRIBL_HOME/log/ directory.
| Logfile Name | Description | Equivalent on Logs page |
|---|---|---|
cribl.log | Principal log in Cribl Stream. Includes telemetry/license-validation logs. Corresponds to top-level cribl.log on Diag page. | Leader > API Process |
access.log | API calls, for example, GET /api/v1/version/info. | Leader > Access |
audit.log | Actions pertaining to files and settings, for example, create, update, commit, deploy, and delete. Also records AI Settings changes, which carry the type value ai-settings. | Leader > Audit |
notifications.log | Messages that appear in the Notification list in the UI. For each event, the time and _time fields record the start of the monitored interval (matching starttime), not when the Notification was written. | Leader > Notifications |
ui-access.log | Interactions with different UI components described as URLs, for example, /settings/apidocs, /dashboard/logs. | Leader > UI Access |
The API/main process emits the following service logs into the Leader Node’s $CRIBL_HOME/log/service/ directory. Each service includes a cribl.log file that logs the service’s internal telemetry and an access.log file that logs which API calls the service has handled.
| Service Name | Description | Equivalent on Logs page |
|---|---|---|
| Connections Service | Handles all Worker connections and communication, including heartbeats, bundle deploys, teleporting, restarting, and so on. Workers are assigned to connection processes using a round-robin algorithm. | Leader > Connections Service |
| Lease Renewal Service | Handles lease renewal for the primary Leader Node. | Leader > Lease Renewal Service |
| Metrics Service | Handles in-memory metrics, merging of incoming packets, metrics persistence and rehydration, and UI queries for metrics. | Leader > Metrics Service |
| Notifications Service | Triggers Notifications based on its configuration. | Leader > Notifications Service |
The Config Helper process for each Worker Group/Fleet emits the following log in $CRIBL_HOME/log/group/GROUPNAME.
| Logfile Name | Description | Equivalent on Logs page |
|---|---|---|
cribl.log | Messages about config maintenance, previews, and so on. | GROUPNAME > Config helper |
Worker Node Logs (Distributed)
The API Process emits the following log in $CRIBL_HOME/log/.
| Logfile Name | Description | Equivalent on Logs page |
|---|---|---|
cribl.log | Messages about the Worker/Edge Node communicating with the Leader Node (that is, with its API Process) and other API requests, for example, sending metrics, reaping job artifacts. | GROUPNAME > Worker:HOSTNAME > API Process |
Each Worker Process emits the following logs in $CRIBL_HOME/log/worker/N/, where N is the Worker/Edge Node Process ID.
| Logfile Name | Description | Equivalent on Logs page |
|---|---|---|
cribl.log | Messages about the Worker/Edge Node processing data. | GROUPNAME > Worker:HOSTNAME > Worker Process N |
metrics.log | Messages about the Worker/Edge Node’s I/O metrics for Sources, Destinations, and persistent queues. | GROUPNAME > Worker:HOSTNAME > Worker Process N |
For convenience, the UI aggregates the Worker/Edge Node Process logs as follows.
| Logfile Name | Description | Equivalent on Logs page |
|---|---|---|
| N/A | Aggregation of all the Worker Process N logs and the API Process log. | GROUPNAME > WORKER_NAME |
In Cribl Stream, the logs listed above are currently available only on customer-managed hybrid Workers. The single-instance logs listed below are not relevant to Cribl.Cloud.
TCP load balancing
If TCP load balancing is enabled in at least one supported Source (such as Syslog, TCP JSON, or Cribl TCP), the Worker also emits the following log to $CRIBL_HOME/log/worker/LB/.
| Logfile Name | Description | Equivalent on Logs page |
|---|---|---|
cribl.log | Internal telemetry of the load balancing process. | GROUPNAME > Worker:HOSTNAME > Load Balancer |
Events in the load balancer copy use different channel values than the Worker Process cribl.log for the same Source. On the load balancer log, search with channel == "<source-id>_lb". On the Worker Process log, use channel == "input:<source-id>". For the built-in in_tcp_json Source, use channel == "in_tcp_json_lb" and channel == "input:in_tcp_json", respectively.
Single-Instance Logs
The API/main process emits the same logs as it does for a Distributed deployment, in $CRIBL_HOME/log/:
Each Worker/Edge Node Process emits the following logs in $CRIBL_HOME/log/worker/N/, where N is the Worker/Edge Node Process ID.
| Logfile Name | Description | Equivalent on Logs page |
|---|---|---|
cribl.log | Messages about the Worker/Edge Node processing data. | GROUPNAME > Worker:HOSTNAME > Worker Process N |
metrics.log | Messages about the Worker/Edge Node’s I/O metrics for Sources, Destinations, and persistent queues. | GROUPNAME > Worker:HOSTNAME > Worker Process N |
Outpost Logs
The Outpost service emits the following logs into the $CRIBL_HOME/log/service/outpost/N/ directory,
where N is the Outpost Node Process ID:
| Logfile Name | Description | Equivalent on the Logs tab in Outpost info drawer |
|---|---|---|
cribl.log | Internal telemetry logs. | Outpost Service N |
metrics.log | Outpost Node metrics. | Outpost Service N - Metrics |
cribl_stderr and Per-Process Stderr Logs
In rare cases, the Node.js backend can encounter a fatal error, such as an out-of-memory condition, that prevents normal logging. To help with troubleshooting, Cribl Stream writes details about these failures to stderr log files, including:
cribl_stderr.logat the Worker Node level.- Per-process stderr log files, for example
cribl_stderr_<PID>.log, for specific API or service processes.
Key points:
- These stderr logs are intended for Cribl Support and are not exposed in the UI.
- They follow the same size-based rotation policy as other internal logs. See Log Rotation and Retention.
- Some stderr logs include prepended UTC timestamps to make it easier to correlate failures with other system activity, such as events in
cribl.log.
Log Rotation and Retention
Cribl Stream writes multiple internal log files for Leaders, Worker Nodes, and supporting services. To prevent any single log file from consuming excessive disk space, Cribl Stream automatically rotates these files based on size rather than time.
By default, Cribl Stream:
- Rotates each log file when it reaches 5 MB.
- Keeps the five most recent rotated files per log.
This rotation policy applies to all internal log files, including:
- Leader and Worker Node API logs in
$CRIBL_HOME/log/, such as:cribl.logaccess.logaudit.lognotifications.logui-access.log
- Service logs in
$CRIBL_HOME/log/service/.... - Worker Group logs in
$CRIBL_HOME/log/group/<GROUPNAME>/. - Worker Node logs in
$CRIBL_HOME/log/worker/<N>/..., such asmetrics.log. - Stderr-based logs, such as
cribl_stderr.log.
Verbose logging levels (for example, debug or silly) and high system activity can cause logs to reach the 5 MB threshold more quickly.
For guidance on forwarding internal logs and metrics to external observability platforms, see Forward Logs and Metrics Externally.
Use Logs and Datasets for Troubleshooting
Troubleshooting health, API, or data-handling problems often requires searching across internal log files. In Cribl Search, you can search built-in Datasets that include multiple logs instead of opening each file separately in the Cribl UI. See Map Log Files to Built-in Datasets to match common symptoms to a log file and built-in Dataset.
To display and export internal logs for a single Leader or Worker Node in the product UI, see Search Internal Logs. You can also forward logs externally.
Built-in Datasets do not include Collector job artifacts (
job.log,task.log, and related files understate/jobs/). For those logs, see Collector Job Logs.
Map Log Files to Built-in Datasets
The following table identifies the internal logs to investigate for common issues and the built-in Datasets that include the log file. The table references these built-in Datasets:
cribl_internal_logs: A federated search Dataset that includes internal.logfiles under$CRIBL_LOG_DIRon the Leader. Thecribl_leaderDataset Provider reads these Leader-local files. It does not search log directories on remote nodes.cribl_logs: A Lake Dataset that includes audit and access logs from your Cribl.Cloud Leader. Query from Cribl Search.cribl_metrics: A Lake Dataset that includes internal metrics from your Cribl.Cloud Leader. Query from Cribl Search.
| Issue | Log to Investigate | Dataset Coverage |
|---|---|---|
| Leader or API Process activity needs review | Leader cribl.log | cribl_internal_logs |
| A Worker Node cannot communicate with the Leader | Worker Node API Process cribl.log | None |
| API request fails or returns an unexpected status | access.log | cribl_internal_logscribl_logs |
| A setting, commit, deploy, or file action needs an audit trail | audit.log | cribl_internal_logscribl_logs |
| UI navigation needs to be correlated with API activity | ui-access.log | cribl_internal_logs |
| A Notification did not appear or contains unexpected timing | notifications.log | cribl_internal_logs |
| A supporting service is unhealthy or mishandles API calls | Service cribl.log and access.log | cribl_internal_logs |
| Config maintenance or preview fails or behaves unexpectedly for a Worker Group | Worker Group cribl.log (Config Helper) | cribl_internal_logs |
| Events are dropped, delayed, or transformed unexpectedly | Worker Process cribl.log | cribl_internal_logs (Leader-local only) |
| TCP Load Balancing misroutes or errors on a supported Source | Load balancer cribl.log | cribl_internal_logs (Leader-local only) |
| An HTTP-based Destination shows request or backpressure trouble | Worker Process metrics.log | cribl_internal_logs (Leader-local only) |
| Outpost service fails or behaves unexpectedly | Outpost cribl.log | None |
| Outpost metrics need review | Outpost metrics.log | None |
| A process exits unexpectedly | cribl_stderr.log or cribl_stderr_<PID>.log | cribl_internal_logs (Leader-local only) |
| Cloud Leader internal metrics need review | Metrics Service internal metrics | cribl_metrics |
Query Internal Logs in Built-in Datasets
To find events from an internal log, search the built-in Dataset that includes it in Cribl Search.
Members must have the Admin Permission on Cribl Search to query cribl_internal_logs. To query cribl_logs or cribl_metrics, Members need the Read Only Permission on Cribl Lake Datasets in addition to the Admin Permission on Cribl Search.
The following search examples target internal log paths and event fields that are useful for troubleshooting. Adjust paths and filters for the log you are investigating. For log query syntax details, see Build a Log Search.
Find API requests that returned an error status:
dataset="cribl_internal_logs" source="*access.log" status>=400Show Config Helper events for all Worker Groups:
dataset="cribl_internal_logs" source="*group/*/cribl.log"Find commits and deploys:
dataset="cribl_internal_logs" source="*audit.log"
| where action in ("commit", "deploy")Find events for one Notification rule:
dataset="cribl_internal_logs" source="*notifications.log"
| where channel == "<rule-id>"Find API errors handled by a Leader service:
dataset="cribl_internal_logs" source="*service/*/access.log" status>=400Find Cribl.Cloud Leader API requests that returned an error status:
dataset="cribl_logs" data_source="*access.log" status>=400