On This Page

Home / Search/ Investigate/Deep Investigations (Preview)

Deep Investigations (Preview)

Preview Feature

Cribl is still developing this Preview feature. We don’t recommend using it in a production environment, because the feature might not be fully tested or optimized for performance, and related documentation could be incomplete.

Please continue to submit feedback through normal Cribl support channels, but assistance might be limited while the feature remains in Preview.

Deep Investigation Mode is an investigation experience that structures your analysis around hypotheses. Instead of an open-ended conversation, Cribl Search proposes a set of hypotheses, you select the ones you want to pursue, and the AI validates each one sequentially - running queries, gathering evidence, and building toward a structured conclusion.

You decide when to run a deep investigation. To use Deep Investigation Mode, turn on the Deep Investigation Mode toggle in the Investigations toolbar, or start an investigation from a Notebook.

Before You Begin

  • AI must be configured correctly in your organization.
  • The Search Investigations setting must be active in Global Settings > AI Settings.
  • A paid, active Cribl Search subscription or billing plan is required.

Turn On Deep Investigation Mode

There are two ways to run a deep investigation:

  • Turn on the toggle: In the Investigations toolbar, turn on the Deep Investigation Mode toggle before you start. You must turn it on at the start - Cribl Search sets the mode when the investigation begins and keeps it for the rest of the session. Your toggle choice persists across page reloads.
  • Start from a Notebook: A deep investigation also runs when you start one from a Notebook. For details, see Start an Investigation from a Notebook.

Deep Investigation Mode is a Preview feature that is still improving and can occasionally fail. If it returns an error, turn off the Deep Investigation Mode toggle and run your investigation again in standard investigation mode, so that Deep Mode issues don’t block you from continuing.


How the Workflow Differs from Standard Investigations

Standard investigations use a free-form conversation model. Deep Investigations use a structured state machine that progresses through the following phases:

  1. Establish a goal: Describe a scenario, select a recent incident, or browse external context. Cribl Search infers and records the investigation goal.
  2. Identify data sources: Cribl Search selects up to five relevant Datasets and examines their schema and field statistics. If Dataset Intelligence is enabled on a Dataset, that context is used automatically.
  3. Select hypotheses: Cribl Search proposes a list of hypotheses for you to review. Select the ones you want to investigate. You can also add your own.
  4. Validate hypotheses: Cribl Search validates each selected hypothesis strictly one at a time, in the order selected. During this phase, the chat thread stays quiet while Cribl Search runs queries and updates progress in the background.
  5. Review the summary: When all hypotheses have a terminal status, Cribl Search presents a structured investigation summary with findings, a conclusion, and terminal action buttons.

View the Investigation Graph

The Investigation Graph is a visual map of the investigation that updates as Cribl Search progresses.

To open it, select Map in the Investigations toolbar.

The graph displays the following nodes:

  • System Alert: Shown when the investigation was started from an alert.
  • Investigation Goal: The goal statement inferred from your input.
  • Context Discovery: With a sub-node for each data source identified as relevant.
  • Hypotheses: With a sub-node for each hypothesis selected.
  • Conclusion: The overall outcome after all hypotheses reach a terminal status.

Select any hypothesis node to open the Hypothesis Drawer, which shows the hypothesis details, evidence gathered, and the Disregard option.


Hypothesis Statuses

Each hypothesis moves through a set of statuses during the investigation:

StatusMeaning
EnqueuedSelected and waiting to be investigated
InvestigatingCurrently being validated
ConfirmedEvidence strongly supports the hypothesis
InconclusiveEvidence is partial or ambiguous
UnlikelyEvidence contradicts the hypothesis
FailedInvestigation could not gather sufficient evidence
DisregardedDismissed by you before or during investigation

All statuses except Enqueued and Investigating are terminal – the investigation does not revisit a hypothesis once it reaches a terminal status.


Disregard a Hypothesis

You can dismiss a hypothesis at any time during the investigation.

  1. In the investigation toolbar, select Map to open the Investigation Graph.
  2. Select the hypothesis node you want to dismiss.
  3. In the Hypothesis Drawer, select Disregard.

A disregarded hypothesis is marked terminal immediately. Cribl Search will not run further queries for it. It is still noted in the investigation summary so your findings remain accurate.


Finish the Investigation

When every hypothesis has a terminal status, Cribl Search presents the investigation summary. From the summary, you can:

  • Save to Notebook: Builds a Notebook containing the AI-generated summary, the queries run, key results, and recommendations. See Notebooks for details.
  • Dig deeper into findings: Returns to the investigation to continue exploring.
  • End investigation: Closes the investigation session.

Your session is saved automatically throughout. To return to this investigation later, select Recent investigations in the Investigations toolbar. See Saved Sessions for details.