Home /Cribl Search 4.20.0

Cribl Search 4.20.0

PRODUCTDATERELEASEADDITIONAL RESOURCES
Search2026-09-16FeatureKnown Issues, Cribl Lake Release Notes

Summary

Cribl Search 4.20.0 adds a new, integrated AI experience, multi-engine lakehouse queries, a CrowdStrike NG-SIEM Dataset Provider, and Splunk SmartStore and DDSS support in federated search v2. Apps are now generally available.

Important Changes

This release introduces notices that require action if you use the affected features:

Review the full list of important changes for additional critical updates.

New Features

Apps General Availability

Apps are now generally available and no longer in Preview.

Apps let you build and run custom applications in Cribl. An App is a packaged user-interface experience that can call Cribl and third-party APIs, enabling tailored workflows and front-end experiences beyond the built-in product surfaces.

This release adds:

  • Backend functions: An App can expose HTTP endpoints and run work on a schedule, so it can automate tasks instead of doing everything in the browser.
  • External API Access: Administrators can authorize which third-party hosts each App may call, including Organization-specific domains that were not packaged with the App.
  • Permissions review: Before you install an App, you can see the in-product permissions and external API access it declares.
  • App limits: Administrators can control how much compute and related capacity each App can use.
  • Scaffolding and upgrades: App builders get a clearer path from Create App through packaging, versioning, and upgrading an installed App.

Integrated AI Experience in Cribl Search (Preview)

A single Cribl AI assistant now persists throughout Cribl Search. Open it from the AI icon on the top bar, and it keeps your conversation and page context as you move across Search. Cribl AI can explain your results, run searches, and create or update Dashboards, Notebooks, and saved searches, asking you to confirm each change first.

This Preview is available only in Cribl.Cloud and doesn’t cover the Metrics and Monitors pages.

MCP Server Role-Based Access Control (RBAC)

The Cribl MCP server now supports role-based access control, enabling non-admin users to connect to the MCP server and use tools scoped to their product-level permissions. Previously, MCP server access was restricted to admin users only.

Cribl AI in Cribl.Cloud Government (BYOM)

Cribl.Cloud Government now supports Cribl AI via a Bring Your Own Model (BYOM) setup. Activating your custom AI provider routes supported features, including Copilot chat, Stream editing, and Search assistance, through your managed provider using simplified controls while maintaining FedRAMP compliance boundaries.

New Gemini Models in BYOM

The Google Gemini custom AI provider now supports the Gemini 3.6 Flash and Gemini 3.5 Flash-Lite models. Based on evaluation results, the suggested tier defaults for Gemini have changed: the Small tier now defaults to gemini-3.5-flash-lite, the Frontier tier now defaults to gemini-3.6-flash, and the Reasoning tier remains gemini-3.1-pro-preview. To restore these suggested defaults for every tier, select Reset to Defaults in AI Settings.

Multi-Engine Lakehouse Queries

You can now query Datasets across multiple lakehouse engines in a single search, including wildcards and aggregations.

CrowdStrike NG-SIEM Dataset Provider

Cribl Search now has a dedicated CrowdStrike NG-SIEM Dataset Provider. It queries NG-SIEM asynchronously, so investigation-scale searches run to completion instead of timing out. For setup details, see Connect Cribl Search to CrowdStrike NG-SIEM.

Splunk SmartStore and DDSS Support in Federated Search v2

v2 federated Datasets on Amazon S3 and Azure Blob Storage now support the Splunk DDSS and Splunk SmartStore partitioning schemes. You can point a v2 Dataset at Splunk-managed storage in your own bucket. Selecting the Splunk Journal Datatype discovers journal files automatically, so you no longer have to configure glob patterns, file extensions, or compression settings by hand.

Dataset Type v2 for DDSS Cribl Lake Datasets

Cribl Lake Datasets that use the DDSS storage format now support Dataset Type v2, expanding beyond previous v1 limits. Pair them with the stock splunk_journal Datatype to reduce the volume of data read and speed up queries, by skipping bucket directories outside your search time range.

Metrics Permissions (Preview)

Cribl Search Permissions now govern access to Metrics:

Grafana Dashboard Migration (Preview)

You can now import your Grafana Dashboards directly into Cribl Search. After you connect to Grafana or upload a JSON export, Cribl Search evaluates your configuration for compatibility. Review the assessment, then proceed with the migration.

OpenTelemetry Metrics Storage (Preview)

The OpenTelemetry Source can now store metrics in a Dataset, which lets you run PromQL queries in Metrics Explorer. Set Store this source data as to Metrics or Both Logs and Metrics. Cribl Search supports gauges, counters, and histograms, and maps OTLP metrics to Prometheus-compatible names automatically.

Metrics Ingest from Cribl Stream and Cribl Edge (Preview)

You can now send metrics from Cribl Stream and Cribl Edge into Cribl Search two ways:

  • Cribl Search Destination: Send native metric events over the same connection that carries your logs. On the Cribl HTTP Source, set Store this source data as to Metrics or Both Logs and Metrics. On the Cribl Search Destination in Stream or Edge, set Send as to Metrics or Logs and Metrics.
  • Prometheus Destination: Point the Prometheus Destination in Stream or Edge at the Prometheus Remote Write Source in Cribl Search, using the address, port, and remote write endpoint of that Source.

Either way, Cribl Search normalizes the metrics and stores them in a metrics Dataset instead of storing them as logs, so you can query them in Metrics Explorer.

Experience Improvements

Search Home Is Now Logs

The main Search Home page is now Logs, which distinguishes log search from Metrics features more clearly.

TLS by Default

New lakehouse engine Sources that support TLS now enable it by default. Existing Sources remain unchanged.

Quick Access to Recent Work

Use My Recents to reopen your recently visited Dashboards, Notebooks, saved searches, or Packs.

Shared Time Range for Dashboard Panels

New Dashboards include a default Time Range Input, and every visualization panel you add links to it automatically. All panels share one time range that Dashboard viewers can change in one place, instead of setting it panel by panel. On a chart panel whose horizontal axis is time, viewers can also drag across the range they want to inspect.

Notebook Status and Tags

You can now assign a status (None, Active, or Closed) and custom tags to each Notebook. Use them to track a Notebook’s workflow state and to filter the Notebooks listing page. Notebook templates also support tags.

Table of Contents in Notebooks

Notebooks now include a Table of Contents panel that Cribl Search generates from your Markdown headings and query cells. Use this collapsible sidebar to navigate long investigation Notebooks without scrolling, and to reorder cells by dragging and dropping.

Persistent Metrics Query Box in Notebook Cells

The Metrics query box now stays visible inside Notebook cells after you run a query, which keeps the Visual and Code tabs accessible and matches the logs cell workflow. If you have Maintainer access, select the query box to edit and refine your query directly in the cell.

Calendar Quick Actions in Timepickers

You can now filter your data by full calendar periods, using new quick actions such as Today, Yesterday, This week, and Previous month. These options snap your time range to the exact start and end of a calendar period, based on your selected time zone. The quick actions are available in the Search timepicker, and in the Alert Monitor and Active Alerts timepickers under Insights > Alerts.

Simpler Search Limit Settings

Settings > Search > Limits now shows simplified controls. You can still turn dynamic concurrency on or off with Enable dynamic concurrency. Contact Cribl Support if you need help tuning Search for a specific workload.

Quick Access to Engine Insights

You can now open billing and lakehouse engine insights straight from Cribl Search, and view queue time, time to first byte, pre-processing load, backpressure, and engine volume. In the sidebar, under Search, select Search Insights. This entry appears only when your Workspace has Cribl Insights enabled and you hold the System Insights Read Permission. See System Insights.

Clearer Dataset Retention Settings

When you set Dataset retention, Cribl Search now blocks values that don’t equal a whole number of days. You see the conversion before you save, so a value such as 1.01 days is no longer rounded silently.

Last Modified Column on Lookups

The Lookups page now includes a Last Modified column. Hover over the relative time in this column to see the full timestamp. The value reflects when the lookup file content last changed, not edits to tags or description.

Important Changes

New Location for Login and SSO/SLO Callback Rate Limits

The Login rate limit and SSO/SLO callback rate limit settings moved to Settings > Global > General Settings > Limits > API for the Leader and to Worker Group/Fleet Settings > Limits > API for Worker Groups and Edge Fleets. Cribl stores the values in api-limits.yml. Existing rate limits defined in cribl.yml continue to work and do not need to be migrated. To set the limits using the Cribl API, use the PATCH /system/api-limits endpoint.

Notice: Cribl as Code TypeScript and Go SDK Discontinuation

Cribl is stopping active development of the Cribl as Code Go and TypeScript SDKs, which were previously in preview. To give existing users a clear path forward, we are moving the SDKs from the criblio GitHub Organization to the Cribl Community GitHub Organization. We are also open sourcing them as community resources. Customers and community members can continue using and building on the SDKs while Cribl steps back from active development and long-term support.

The SDKs will continue to be available through their new home in the Cribl Community GitHub Organization. You can continue using, forking, and extending them based on your needs. To use a supported integration, consider migrating to the Python SDK, Terraform Provider, or direct Cribl API access. During the transition period, Cribl support will be limited to critical issues, such as security vulnerabilities or P0 blockers. On October 1, 2026, the SDK repositories will be archived and marked read-only.

Notice: Future Removal of CBC and RSA TLS Cipher Suites

In an upcoming release, Cribl.Cloud will remove support for CBC and RSA-based TLS cipher suites to strengthen the security and confidentiality of customer environments.

Why we’re making this change:

  • CBC ciphers are susceptible to well-documented side-channel and padding oracle attacks.
  • RSA key exchange does not provide forward secrecy. If a server’s private key were ever compromised, previously recorded sessions could be retroactively decrypted.

What could be affected:

This change applies to the TLS endpoints your workspaces expose and connect to for data movement, meaning the connections your own systems make into Cribl Stream, and the outbound connections Stream makes to your Destinations. Customers most likely to be affected are those with:

  • Legacy or embedded data senders (older syslog forwarders, appliances, IoT/OT devices, or custom agents) pushing data into Stream sources.
  • Third-party or on-prem systems whose TLS libraries have not been updated in several years and can only negotiate CBC or RSA-keyed cipher suites.
  • Custom integrations built on outdated TLS stacks (older OpenSSL, legacy Java runtimes, end-of-life OS builds) that connect to Stream HTTP, TCP-TLS, or Kafka sources, or that Stream pushes to as a destination.

Corrections

IDDescription
SEARCH-14994
Fixed an issue where valid lakehouse engine size changes were blocked.
SEARCH-14888Federated search v2 now reports the correct number of bytes scanned in Cribl Lake Datasets.
SEARCH-13436Searches that fan out to hundreds of Windows Edge Nodes no longer fail with heartbeat errors.
SEARCH-11826{{searchResultsUrl}} links in Notifications no longer return HTTP 404 after Search prunes the job.
SEARCH-6216You can no longer delete a Datatype that’s in use. Cribl Search lists the linked Datasets so you can reassign them first.

SDK Changelogs

The Cribl SDKs help you integrate with Cribl and reduce the need for repetitive tasks. We maintain changelogs for each version of the Cribl Python SDKs in their GitHub repositories: