Skip to main content

CollectorsCloud Collectors Administration Guide

Configure the Cribl Cloud Collector

Set up the Cribl Cloud Collector to continuously ingest events from your Cribl Stream pipeline.

  1. Log into the New-Scale Security Operations Platform as an administrator.

  2. Find the Collectors tab and click the Cloud Collectors tile.

  3. Click the Collectors tab.

    collectors-tab-cribl.png
  4. Click the Cribl tile. A configuration pane opens on the right.

  5. Enter a name for the new Cribl cloud collector as shown in the image below.

    cribl-config.png
  6. Click Install. A connection string is automatically generated and a confirmation message informs you that the new cloud collector is created. The connection string is displayed in a field on the success message and will need to be copied for use in Cribl Stream.

    cribl-success-dbox.png
  7. In the success message, click Copy (icon-copy.png) to copy the automatically generated connection string to your clipboard for use in the next step.

  8. In your Cribl Stream product (release 4.3.1 or later), create an Exabeam destination and navigate to Configure -> General Settings. Click Autofill with Exabeam Connection String to use the connection string you copied to your clipboard in Step 7. The configuration fields are auto-populated.

    cribl-settings.png
  9. When your Exabeam destination in Cribl Stream is fully configured, data collected via Cribl begins to flow into Exabeam Cribl Cloud Collector. To verify that data is being collected successfully, navigate to a downstream Exabeam service, like Search, and ensure that the collected data is available.

    Note

    If the data you search for is not available, you might need to perform some additional configuration in Cribl Stream. Certain types of Cribl logs require specific configuration to ensure they can be parsed effectively in Exabeam. To determine if you need to complete any special configurations, see Scenarios that Require Specific Configuration.