On This Page

Home / Search/ Get Data In/ Sources/Ingest Windows Events into Cribl Search

Ingest Windows Events into Cribl Search ​

Collect Windows Event Forwarder logs from WEF servers to store them in Cribl Search for fast analysis.


Before You Begin ​

On the Cribl Search side, you’ll need:

On the WEF server side, you’ll need:

You don’t need Cribl Stream, Edge, or Lake. (Looking for the Windows Event Forwarder Source in Cribl Stream instead?)

1. Add a Lakehouse Engine ​

See Lakehouse Engines in Cribl Search.

2. Set Up Your Search Datasets ​

Create the Search Datasets you’ll route events into, and set their retention. See Create Search Datasets.

3. Add a Windows Event Forwarder Source in Cribl Search ​

On the Cribl.Cloud top bar, select Products > Search > Data > Add Source > Windows Event Forwarder.

Adding Sources in Cribl Search
Adding Sources in Cribl Search

Describe Your Source ​

Under General, configure:

SettingDescriptionExample
IDSource ID, unique across your Cribl.Cloud Workspace.

Use letters, numbers, underscores, hyphens.
wef_prod
DescriptionDescribe your Source so others know what it’s for.Ingests WEF from prod servers
AddressHostname (FQDN) that your WEF client connects to.search.main.foo-bar-abc123.cribl.cloud
PortNetwork port to listen on.

Keep the default unless it conflicts with another service.
5986 (default)

Set Up Authentication and Encryption ​

You can authenticate incoming connections to your Source using either client certificate or Kerberos authentication.

Client CertificateKerberos

4. Set Up Datatyping ​

Configure Datatype rules to parse, filter, and normalize your data into structured fields. We call this process Datatyping.

On the Cribl.Cloud top bar, select Products > Search > Data > Datatyping (auto). Here, you can:

See also:

5. Set Up Dataset Rules ​

Configure Dataset rules to route the parsed events into your Search Datasets.

On the Cribl.Cloud top bar, select Products > Search > Data > Datasets: Organize Your Data, and see Organize Data with Dataset Rules for details.

6. Set Up Your WEF Client ​

Configure your WEF client to forward events to your Cribl Search Source.

For details, see the Cribl Stream docs: Windows Event Forwarder Source in Cribl Stream.

7. Start Sending Data and Verify ​

Start sending events from your Windows Event Forwarder, and verify that they’re successfully flowing into Cribl Search.

On the Cribl.Cloud top bar, select Products > Search > Data > Live Data.

Here, check for your Windows Event Forwarder Source. For details, see Live Data.

Next Steps ​

Now that your data is in Cribl Search, you can start using it. For example: