About Cribl Search
Cribl Search is a unified logs and metrics analytics platform that answers data questions with AI-assisted insights.
Search All Your Telemetry in One Place
Work with logs and metrics side by side
Pivot from a metric spike straight into the
logs behind it.
Combine fast ingest-based search with search-in-place
Ingest logs and metrics directly into Cribl
Search for high-speed access, while running federated queries on logs stored elsewhere.
Understand your logs before searching them
Explore your Log Datasets and see available fields
before writing a query.
Run AI-native investigations
Investigate incidents with AI guidance and capture your findings
in one workspace.
Collaborate in Notebooks
Combine queries, metrics, visualizations, and Markdown notes in shareable
Notebooks.
Visualize results
Build charts and Dashboards from your searches and
metrics queries, and share live views with others.
Get alerted
Schedule searches, watch for spikes or outliers, and
send Notifications to your existing tools. Monitors (Preview) raise alerts when a metric crosses a
threshold or behaves anomalously.
Scale with Packs
Install or build custom Packs of Dashboards, saved searches, Macros, and lookups.
Many Engines, One Interface
Lakehouse engines host and accelerate both your logs and your metrics. You can:
- Onboard data directly from existing pipelines, APIs, webhooks, agents.
- Shape, filter, and enrich events on ingest.
- Organize your data into Search Datasets and fine-tune their retention.
- Send Prometheus and OpenTelemetry metrics into a metrics Dataset on the same engine.
The federated engine connects to external data without indexing, so you can:
- Search data where you already store it: object stores, analytics services, APIs, and more.
- Query multiple systems at once without copying data around.
- Run queries natively on AWS and Azure.
A unified interface lets you:
- Run lakehouse queries and federated searches side by side without switching tools.
- Use the same query language and natural-language prompts for both types of searches.
- Investigate incidents across both backends with AI guidance and capture the full story in a single Notebook.
Read the Docs
Start your Cribl Search journey with the following resources.
Overview
- Concepts: Get a glossary-level overview of Cribl Search’s core building blocks.
- Quick Start: Create a Cribl.Cloud Organization to run your first log search.
- Cribl Search Tour: Find your way around the Cribl Search UI.
Setup
- Get Data In: Ingest logs and metrics into a lakehouse engine.
- Connect to External Data: Set up federated search for data stored elsewhere.
- Manage: Control engines, access, and system limits.
Search & Analysis
- Search Logs: Learn how to build efficient log queries.
- Explore Metrics: Ingest, filter, and visualize your metrics.
- Investigate: Answer data questions with Notebooks and AI-driven workflows.
- Visualize: Turn search results and metrics into charts and Dashboards.
- Alert: Schedule searches, create Monitors, and send Notifications.
Reference
- Cribl Search KQL Reference: Learn Kusto Query Language that powers your queries.
- API Code Examples: Run searches programmatically.
- API Reference: Full API reference for Cribl Search.