On This Page

Home / Search/ About/Cribl Search Basic Concepts

Cribl Search Basic Concepts ​

Get familiar with core Cribl Search terms.


Engines ​

Capacity units that power your queries.

Lakehouse engines store and search logs and metrics ingested from Cribl Search Sources. Data is structured and stays hot with no tiers to manage. You can add as many lakehouse engines as you need, and size each one for its ingest rate.

Federated engine runs search-in-place of data stored elsewhere, with no need for ingestion or pre-indexing. Each Cribl.Cloud Workspace has one federated engine.

Lakehouse engines and the federated engine
Lakehouse engines and the federated engine

Datasets ​

Containers for grouping related data.

Search Datasets store data ingested into a lakehouse engine. They’re either Log Datasets or Metrics Datasets, and are assigned through Log Dataset rules and Metric Dataset rules.

Federated Datasets point to specific paths in external storage, such as S3 or Azure Blob. Each federated Dataset uses a Dataset Provider, which holds the query endpoint and access credentials.

Datatypes ​

Sets of rules that parse logs into structured events.

You can use stock Datatypes or create custom ones.

Lakehouse engines can assign Datatypes automatically at ingestion time, and let you catch remaining uncategorized data with Datatype rules.

Dashboards ​

Collections of visualization panels that display search results and metrics.

Dashboards hold charts such as scatter plots, gauges or maps. Inputs let viewers filter a Dashboard without editing the underlying queries, and Interactions let them drill down into a data point.

Notebooks ​

Document-like workspaces that keep related searches, charts, and notes in one browser tab.

Notebooks are persistent records that you can share with others. Notebook templates are reusable layouts for repeatable processes or operational runbooks.

Investigations ​

AI-guided incident analysis that starts from a plain-language prompt.

Investigations analyze telemetry, find patterns, and document findings without you writing every query manually.

Monitors ​

Watches on metric queries that tell you when a metric moves outside its expected range.

Monitors raise alerts when their metrics cross thresholds or behave anomalously.

Notifications ​

Messages that deliver alerts to where your team works.

A Notification needs a Notification target, which sets the delivery method, such as email, Slack, or a webhook. Alerts come from scheduled searches and from Monitors, which you configure separately.

Organizations and Workspaces ​

Your Organization is your Cribl.Cloud account, covering your license and billing. Its AWS or Azure region is where your searches run.

Workspaces are isolated environments inside your Cribl.Cloud Organization, each with its own engines, Datasets, and limits.

Admins, Editors, Users ​

The three Cribl Search Permissions that set what someone can do in Cribl Search.

Search Admins manage engines and have unrestricted access. Search Editors add Datasets, rules, and Packs. Search Users only search and build, limited to the resources shared with them.

Limits and Usage Groups ​

Caps on how much resources a search or user can consume.

Usage Groups apply to users you select, with the built-in default group covering ad-hoc searches and system covering all searches. Limits apply to your whole Cribl.Cloud Workspace.