On This Page

Home / Search/ Get Data In/ Sources/Ingest Windows Events into Cribl Search

Ingest Windows Events into Cribl Search

Collect Windows Event Forwarder logs from WEF servers to store them in Cribl Search for fast analysis.


Before You Begin

On the Cribl Search side, you’ll need:

On the WEF server side, you’ll need:

You don’t need Cribl Stream, Edge, or Lake. (Looking for the Windows Event Forwarder Source in Cribl Stream instead?)

1. Add a Lakehouse Engine

See Lakehouse Engines in Cribl Search.

2. Set Up Your Search Datasets

Create the Search Datasets you’ll route events into, and set their retention. See Create Search Datasets.

3. Add a Windows Event Forwarder Source in Cribl Search

On the Cribl.Cloud top bar, select Products > Search > Data > Add Source > Windows Event Forwarder.

Adding Sources in Cribl Search
Adding Sources in Cribl Search

Describe Your Source

Under General, configure:

SettingDescriptionExample
IDSource ID, unique across your Cribl.Cloud Workspace.

Use letters, numbers, underscores, hyphens.
wef_prod
DescriptionDescribe your Source so others know what it’s for.Ingests WEF from prod servers
AddressHostname (FQDN) that your WEF client connects to.search.main.foo-bar-abc123.cribl.cloud
PortNetwork port to listen on.

Keep the default unless it conflicts with another service.
5986 (default)

Set Up Authentication and Encryption

You can authenticate incoming connections to your Source using either client certificate or Kerberos authentication.

Client CertificateKerberos

4. Set Up Datatyping

Configure Datatype rules to parse, filter, and normalize your data into structured fields. We call this process Datatyping.

On the Cribl.Cloud top bar, select Products > Search > Data > Datatyping (auto). Here, you can:

See also:

5. Set Up Dataset Rules

Configure Dataset rules to route the parsed events into your Search Datasets.

On the Cribl.Cloud top bar, select Products > Search > Data > Datasets: Organize Your Data, and see Organize Data with Dataset Rules for details.

6. Set Up Your WEF Client

Configure your WEF client to forward events to your Cribl Search Source.

For details, see the Cribl Stream docs: Windows Event Forwarder Source in Cribl Stream.

7. Start Sending Data

Start sending events from your Windows Event Forwarder, and verify that they’re successfully flowing into Cribl Search.

On the Cribl.Cloud top bar, select Products > Search > Data > Live Data.

Here, check for your Windows Event Forwarder Source. For details, see See Live Data Flow.

Next Steps

Now that your data is in Cribl Search, you can start using it. For example: