On This Page

Home / Search/Enrich and Automate

Enrich and Automate

Use and customize Knowledge libraries to enrich your data, and Macros to automate your searches.


You can access and manage Cribl Search Knowledge libraries and Macros by selecting Knowledge from the sidebar. You’ll now see upper tabs where you can configure the enrichment and autmation resources listed below.

  • Lookups are data tables that the lookup and ip-lookup operators use to enrich events with relevant geographic, identity, threat, or other details.
  • Parsers in Cribl Search are definitions for Datatypes and for the extract operator.
  • Regexes are definitions for Parsers.
  • Grok patterns are definitions for Parsers.
  • Macros are saved query snippets that you can reuse across different searches, providing consistency and a single point of maintenance.