On This Page

Home / Search/ About/Cribl Search UI Tour

Cribl Search UI Tour

Find your way around the Cribl Search UI.


Search Home, with AI features enabled
Search Home, with AI features enabled
Sidebar (1-9)Query Box (10-14)Datasets and Searches (15-17)
AreaDescriptionMore Info
1Search Home is where you run your current search.
2History keeps previous searches so you can reuse them or check cached results.View Search History
3Saved Searches let you run queries on schedule and set up Notifications.Save Searches
4Dashboards visualize search results in a variety of ways.Dashboards
5Notebooks let you combine queries, visualizations, and notes on one tab.Notebooks
6Data is where Search Admins and Editors manage
Engines, Sources, Datasets, Dataset Providers, and Datatypes.
Get Data Into Cribl Search

Connect to External Data
7Knowledge contains your
lookups, Parsers, regexes, Grok patterns, and Macros.
Knowledge Libraries
8Packs let Search Admins and Editors import, export, and share knowledge objects.Packs
9Settings is where Search Admins set Notification targets, Usage Groups, and limits.Usage Settings
AreaDescriptionMore Info
10Query Box is where you build your searches in Kusto Query Language (KQL).

Select Build Query to use natural language instead.
11Select the gear button to change query box options or see the KQL reference.Language Reference
12Run Investigation starts an AI-powered investigation session.Run Investigation
13Sampling reduces the number of results for quick, exploratory searches.Sampling
14Time Range narrows down your search to a specific time period.Time Range
AreaDescriptionMore Info
15Available Datasets let you inspect your data before running a search.

Cribl-hosted Search Datasets are marked with the lakehouse icon Lakehouse
Inspect Your Datasets
16History tab shows a quick overview of recent searches.View Search History
17Sample Searches help you get started with running queries.Common Query Examples