Welcome to Cribl Curious!
|
|
1
|
145
|
April 19, 2022
|
Submit your Pack! Don't forget to Roll Your Own entry for the Cribl Packs contest by July 8th!
|
|
1
|
98
|
June 21, 2022
|
Regex to Grab Key:Value
|
|
2
|
71
|
June 21, 2022
|
How do I pull out a substring from my _raw, and put it at the **beginning** of the event?
|
|
1
|
54
|
April 25, 2022
|
How do I change the IP addresses of Stream workers?
|
|
1
|
68
|
April 25, 2022
|
What permissions are needed for Cribl Stream to pull an S3 bucket? I’m creating a role for it to use
|
|
2
|
70
|
April 25, 2022
|
Is it possible to POST to the API to trigger a collector?
|
|
1
|
66
|
April 25, 2022
|
How do I turn a string field value to an integer?
|
|
2
|
66
|
April 25, 2022
|
How many worker groups can a Cribl Stream leader support?
|
|
1
|
60
|
April 25, 2022
|
What's the best way to move a sample data capture into a pack?
|
|
1
|
49
|
April 25, 2022
|
How can I correctly break up giant JSON events?
|
|
1
|
53
|
April 24, 2022
|
How can I add Humio as an Elasticsearch destination?
|
|
1
|
58
|
April 24, 2022
|
Can I distribute a custom function in a pack?
|
|
1
|
58
|
April 24, 2022
|
Can a filter use a lookup table?
|
|
2
|
79
|
April 22, 2022
|
About the Announcement category
|
|
3
|
41
|
April 25, 2022
|
How can I assign limit to incoming events and drop the messages for a specific field, if it exceeds the limit?
|
|
1
|
88
|
April 19, 2022
|
Is there a Cribl expression that I can use to eval the size in bytes of _raw?
|
|
2
|
68
|
April 18, 2022
|
mtimeMs - Modify Time in Milliseconds
|
|
1
|
53
|
April 17, 2022
|
Is there a simple way to do if-elif-elif in an eval statement? Support 3 or 4 tests
|
|
1
|
66
|
April 17, 2022
|
How to increase the amount of memory available to each Worker Process?
|
|
1
|
58
|
April 17, 2022
|
How do I aggregate multiple logs into a single output?
|
|
1
|
67
|
April 17, 2022
|
How do I interpret this Stream error message? “Error: read ECONNRESET at TCP.onStreamRead (internal/stream_base_commons.js:209:20)”
|
|
1
|
83
|
April 17, 2022
|
Do you need to restart Stream after installing a pack?
|
|
1
|
60
|
April 17, 2022
|
PAN Packs Question: what purpose does the index index || ‘firewall’ serve?
|
|
1
|
62
|
April 17, 2022
|
How do I change the token for Stream workers?
|
|
1
|
50
|
April 17, 2022
|
Is it safe to remove Time from _raw?
|
|
1
|
65
|
April 17, 2022
|
How do I migrate current Stream Workers to a new leader?
|
|
1
|
56
|
April 17, 2022
|
Which Splunk HEC formats does Stream support?
|
|
1
|
67
|
April 17, 2022
|
Which port is used to distribute worker binaries?
|
|
1
|
44
|
April 17, 2022
|
How would I go about filtering out events where a field is equal to a certain value?
|
|
1
|
57
|
April 17, 2022
|