Skip to content
Logmetry

You already have the control layer

Cribl Stream is the control layer itself: worker nodes receive from every source, run each event through pipelines and routes, and send each destination only what it is for, with the whole configuration held by a leader and backed by git. It is not a SIEM, it holds no detections, and it is licensed by the GB it processes in credits. An estate that already runs it has the hard part in place, and the work is what stands on it: tuning per source, the Lake partitioned for retrieval, and the phases beyond.

How a Cribl estate looks today

An estate already running Cribl owns the control layer, and the usual gaps are the system around it: reduction stalled after the easy sources, a lake that is a parked bucket, and pipelines living in a UI instead of a repository.

How an estate already running Cribl looks todayThe estate already feeds Cribl Stream, the strongest general-purpose control layer in the market, and that was the right call. But reduction stalled after the first easy sources, so the SIEM still bills on too much. Everything lands in an S3 bucket nobody can read back, because it is parked rather than partitioned. And the pipelines live in a UI, so changes are clicks rather than reviewed commits.YOUR ESTATEServers, VMs, containersEVERY KIND OF SOURCEForwarders, syslog, HEC, cloudNetwork gear and appliancesAll of itCRIBL STREAMYou already ownthe control layerConfigured by hand, in the UISTILL PER GBYOUR SIEMReduction stalled afterthe first easy sourcesEverything, unreadAN S3 BUCKETParked. Nobody reads it backNO REPOSITORYPipelines live in the UI.Changes are clicks,not commitsWHAT IS MISSINGStream cut the easy sources.The rest never got tuned.The Lake is a bucket. Everyquestion is an export job.Config lives in a UI, so noreview, no history, no test.
An estate that already runs Cribl owns the hard part. The gaps are the system around it: reduction stalled after the easy sources, a lake that is a parked bucket, and pipelines that live in a UI instead of a repository.

What Cribl does best

Cribl Stream is the strongest general-purpose control layer in the market: collect once, route to many destinations, parse, trim, and enrich in flight, at enterprise scale. In most environments a well-run Stream deployment cuts ingest to the expensive destinations 40-70% with zero detection loss. If you already run it, you made the right call.

The gap we usually find is between having Cribl and having it as a governed system: pipelines that live in a UI instead of a repository, reduction that stalled after the first easy sources, and a lake that is an S3 bucket rather than a partitioned, enriched asset the next tool can read.

What we do to a Cribl estate

Keep it and govern what flows in, shrink its footprint, cut what it costs, extend it with an agent, and replace only where replacement is honest.

The Logmetry Blueprint applied to an estate already running CriblThe same Stream, made into a governed system. Pipelines move to your repository where every change is a reviewed, tested pull request deployed by API. Reduction is worked source by source, measured before and after, so the SIEM receives only what earns its place. The bucket becomes a partitioned, enriched lake, and the agent phases stand on it, investigating each alert against the history Stream has been landing all along. Pins: keep on Stream, shrink on the sources, cut on the meter, extend on the agent, replace on nothing.YOUR ESTATEServers, VMs, containersEVERY KIND OF SOURCEForwarders, syslog, HEC, cloudNetwork gear and appliancesSAll of itYOUR GROUNDCRIBL STREAMTuned source by source,measured before and afterAs code, in your reposKRYOUR REPOSITORYEvery change a pull request,reviewed, tested, deployedby APIEverything, enrichedTHE LAKE, PARTITIONEDPER GB, PER DAYOnly what earns its placeCYOUR SIEMReceiving a governed feedTHE INDEXThe alertYOUR AGENTTriage and root cause, onwhat Stream landedEIt queries your historyWHAT CHANGEDThe engine you own nowproduces everything it can.The bucket becomes apartitioned, readable asset.Changes are pull requests,tested before they ship.
The Logmetry Blueprint applied. The engine you already own becomes a governed system: pipelines as code, reduction measured per source, the bucket partitioned into an asset, and the agent phases standing on it. The pins mark where each of the five verbs acts.
KKeep

Stream as your log control layer. It is the engine we reach for in exactly this seat, and your investment in it compounds from here, because every later phase stands on the routing it already does.

SShrink

The sources nobody tuned yet. Reduction is worked source by source against your top talkers, measured before and after, so the number the SIEM bills is one you can show rather than estimate.

CCut

The destinations keep receiving only what earns its place, and the config moves into your repository where changes are reviewed and testable.

EExtend

The Lake becomes partitioned and enriched rather than parked, and the agent phases stand on it: triage and root cause reading history Cribl landed.

RReplace

Nothing. This estate already owns the hard part. The work is making it produce everything it can.

The letters mark where each verb acts in the drawing above

From a pipeline to a foundation

The difference between running Cribl and owning a foundation is code, partitioning, and the phases that stand on top.

Pipelines and configuration move to repository-backed management, so every change is reviewed, testable, and reproducible. The Lake gets the treatment that makes it an asset: enrichment in flight, partitioning that matches how investigations move, and a compliance archive that answers auditors with a query.

From there the Blueprint's later phases open up: footprint reduction against the per-node monitors, and agents that investigate alerts reading the history your control layer has been landing all along.

The per-source structure

The first source goes end to end against criteria agreed in writing before the rollout continues, so trust never has to run ahead of proof.

Cribl work is the one engagement we price per source, because the unit of work is genuinely the source. The foundation is one fixed-price project: Stream deployed or brought under management, the pipeline and its configuration as code, the repository and the API-driven deploy. Then the estate moves source by source, typically one to two weeks each, each with its reduction measured and its acceptance criteria agreed in writing before it starts.

The first source is the proof. It goes end to end, against written criteria, before the rollout continues, so you are never asked to trust the method further than it has already demonstrated. An estate that already runs Cribl is tuned the same way, per source, starting with your most expensive one.

Asked about Cribl estates

We already run Cribl. What is left to buy?

The system around it: pipelines as code in your repositories, per-source reduction worked against your top talkers with results measured, a Lake that is partitioned and enriched rather than parked, and the agent phases that stand on that foundation. The engine you have is the prerequisite, not the finish line.

How is Cribl work priced?

A fixed-price foundation project, then per source, typically one to two weeks each, with acceptance criteria agreed in writing before each source starts. The first source proves the method end to end before the rollout continues. Real quotes follow the review and discovery.

Does Logmetry sell Cribl licences?

Licensing is a conversation with its own options, and where the licence transacts is settled in the engagement paperwork, not on a webpage. What we sell is the engineering: the design, the build, the reduction, and the code you own after.

Start with the review

You share your diagrams, we review them with you, and you leave with your version of the Logmetry Blueprint drawn on your Cribl estate. No system access, no obligation.