Enrich and Automate
Use and customize Knowledge libraries to enrich your data, Macros to automate your searches, and Packs to share pre-built Cribl Search configurations.
You can access and manage Cribl Search Knowledge libraries and Macros by selecting Knowledge from the sidebar. You’ll now see upper tabs where you can configure the enrichment and automation resources listed below.
- Lookups are data tables that the
lookup
andip-lookup
operators use to enrich events with relevant geographic, identity, threat, or other details. - Parsers in Cribl Search are definitions for Datatypes and for the
extract
operator. - Regexes are definitions for Parsers.
- Grok patterns are definitions for Parsers.
- Macros are saved query snippets that you can reuse across different searches, providing consistency and a single point of maintenance.
Select Packs from the sidebar to import, modify, create, and export pre-built Cribl Search resources. Packs can include Dashboards, saved searches, Datatypes, Macros, and lookups – in any combination required to support a given data source or workflow.