Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

9 AWS reviews

External reviews

23 reviews
from

External reviews are not included in the AWS star rating for the product.


3-star reviews ( Show all reviews )

    Akhil Latchireddi

Centralized log streaming has improved cloud monitoring but still faces upgrade and scale issues

  • January 28, 2026
  • Review from a verified AWS customer

What is our primary use case?

My main use case for Cribl is to send and process logs from our AWS network and multiple other cloud networks to an S3 bucket to store the logs as well as to stream the logs to other service providers like Logz.io where we will set up a logging and alerting platform.

A quick specific example of how I'm using Cribl in this process is that we have been using different types of logs such as Python from ECS and EKS Kubernetes-based logs, and all those logs are in different formats. We add all the logs from different streams to Cribl and then from there we add specific formats and add certain tags to those logs so that it is easy to format and set alerts at the logging level.

Cribl is very useful because we have multiple clouds and it has been processing our logs from multiple different platforms into a single one, and it is processing to multiple other platforms as well. It is used as a bridge to stream and process the logs.

What is most valuable?

One of the best features Cribl offers is that it runs on Kubernetes clusters, which is easy to manage and comes with easier upgrades. It is very compatible with container-based environments and supports multiple different types of logs. It has many connectors and can send to many endpoints. The workflow features are also strong.

The compatibility with container-based environments has made my day-to-day work easier because it supports Kubernetes. In day-to-day work it is mostly useful for container-based logs because we mostly run on Kubernetes and ECS. We are a completely container-based organization, so most of our logs are container-based logs and application-based logs. All those logs are easily processed from Cribl.

Cribl has positively impacted my organization in terms of efficiency. We used to run on Lambda functions in AWS, which is an older process, and we used to drop many of our logs, which was problematic because those are necessary for future use cases. Now everything is working well.

This has impacted troubleshooting and compliance in my team because we are able to keep the logs indefinitely. There is no drop in the logs and no loss of the logs. This has impacted my team meaningfully because we have all the logs, we have very strict monitoring, and compatibility with all of our standards.

What needs improvement?

I think Cribl can be improved because I do not believe it is a mature product. It has gone down many times and when we are doing upgrades, many things break and we face a lot of issues, especially with scaling. If the logs are high volume, most of the time it is down or some connectors are down and it is not performing as well as we thought.

Moving from version 3 to version 4 became very difficult during the upgrade. The scalability issue is very problematic. We are running on Kubernetes and there are a lot of issues with respect to scaling. When we have more logs coming in, the connectors are failing.

I would like to see other improvements with Cribl beyond scaling and upgrades. The product should be more mature and the documentation can be improved.

For how long have I used the solution?

I have been using Cribl for four years.

What do I think about the stability of the solution?

Cribl is not really stable, although it may become stable. It is close.

What do I think about the scalability of the solution?

Cribl's scalability is not great.

How are customer service and support?

The customer support is also not great. They are connecting with us, but they are not able to figure out solutions very quickly. They may need more knowledge.

How would you rate customer service and support?

Which solution did I use previously and why did I switch?

I previously used a different solution, which was Lambda functions. It was highly costly and it used to drop many of our metrics and logs, which was problematic.

How was the initial setup?

I assess Cribl's ability to handle high volumes of diverse data types such as logs and metrics. I think it is feature-rich, but the scalability and reliability are major issues.

What about the implementation team?

I am using the new search in place technology feature of Cribl Search, and the search is good. However, we need to go into the particular workflow and then from there we need to do the search. It is not a global search, which is not a good sign.

What was our ROI?

I have seen a return on investment. With respect to money, the savings are not significant. With respect to time, there is a little bit of saving, but because things broke during the upgrade, we needed to go back to the older methods of using Lambda. In terms of employees, we did decrease the employee count, but I do not know if Cribl is really the reason for that.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing shows that I am not completely involved in the pricing part, but I did participate in the setup part. Cribl provided an image and we used that image. It is also publicly available and it is not difficult to set up in a Kubernetes cluster. I think it is easy.

Which other solutions did I evaluate?

Before choosing Cribl, I was not part of the team which explored Cribl. I was already part of the team implementing Cribl. We used to use Lambda functions and then we moved to Cribl. I am not sure which other options were explored.

What other advice do I have?

My advice to others looking into using Cribl is that if you are not a billion dollar company or if you are a startup that does not want to go into reinventing the wheel by writing all the code, Cribl is a great solution for streaming logs. I would rate this review a 6 out of 10.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)


    reviewer2748900

Real time validation of data transformation before pushing them into production

  • August 08, 2025
  • Review provided by PeerSpot

What is our primary use case?

We use Cribl Stream to collect logs from multiple sources, transform and enrich them, filter out unnecessary data before sending them to SIEM. We also use Cribl to route logging to data lake.

How has it helped my organization?

Since we started using Cribl, it’s made a huge difference for us. We spend a lot less time building and maintaining things, so the team can focus on the security work that really matters and brings value. Plus, by filtering out all the noisy data we don’t need, we’ve been able to cut costs and make our data a lot cleaner.

What is most valuable?

One of the biggest things I love about Cribl is that you can actually see the output in real time before you push anything to production. The UI makes it super easy to work with, and honestly, it saves a ton of time. Plus, it’s way easier to collaborate—everyone’s on the same page, and you’re not guessing what the data’s gonna look like once it’s live

What needs improvement?

So since we’re handling a ton of data, I think we could really benefit from a more integrated or connected way to manage it all. Like, if there is a way to better track data lineage, metadata, those can help with knowledge transfer.

For how long have I used the solution?

A couple of months

What do I think about the stability of the solution?

I haven’t ran into issue yet

What do I think about the scalability of the solution?

I can’t really speak to scalability yet. So far I don’t have any problem with it.

How are customer service and support?

The technical support is good. I'm happy with that.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have used something similar before, which was Logstash.

What was our ROI?

Not sure

What's my experience with pricing, setup cost, and licensing?

I think the pricing for Cribl is reasonable. For large usage, but I heard the calculation of those credits is a bit complicated.

Which other solutions did I evaluate?

We did, but Cribl just felt more mature and well-established. I think that’s the reason why we selected it.

What other advice do I have?

Cribl gives us way more control and flexibility than we ever had before. We deal with massive volumes of telemetry data, and honestly, a lot of it is just noise. Cribl allow us to easily filter, transform, and route that data exactly how we want. It’s made a big difference.


    Jai Chudasama

Provides data normalization and routes the same data to different destinations but lacks documentation

  • September 06, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use Cribl for data normalization, which involves standardizing data from various sources before sending it to a SIEM. This helps reduce costs associated with SIEM ingestion. Additionally, we use Cribl to sanitize data by removing or masking sensitive information from certain fields.

How has it helped my organization?

Cribl filters out unnecessary events and data, and we reduced the costs associated with SIEM ingestion.

What is most valuable?

You can use Cribl to route the same data to different destinations. For instance, if a company uses multiple SIEMs and needs data in each, Cribl makes it easy to direct that data to various destinations. Setting up API connections to get data into the platform is easy. Cribl offers a cloud version, allowing different workspaces to segregate various functions within a company or organization.

What needs improvement?

The documentation part could be better. Their documentation could be updated, as new features often outdated existing information. Additionally, there are inconsistencies between the documentation for Cribl Cloud and Cribl on-premises. This can be confusing, as features may differ, leading to potential misunderstandings if you use documentation intended for one version while working with another. Consolidating and improving the clarity of the Cribl Cloud documentation would be very helpful.

For how long have I used the solution?

I have been using Cribl for a year and a half.

What do I think about the scalability of the solution?

It is highly scalable. If you need more cloud worker groups, you're just a click or two away from doing that at extra cost.

How are customer service and support?

Depending on the license, we usually provide a Customer Success Manager to assist with any questions or issues when onboarding Cribl. They are very responsive, and their support is quite helpful.

How would you rate customer service and support?

Neutral

How was the initial setup?

We employed a hybrid strategy, setting up Cribl Cloud as the head node in their environment. For data processing, we used worker nodes within the client’s environment, which are closer to the data sources. This setup allowed us to process data locally before sending it to our destination. For cloud assets, such as SaaS applications like Salesforce, we used the cloud-hosted Cribl instance to handle that information. Meanwhile, the on-premises data was processed by the hybrid worker nodes.

We encountered delays due to third-party issues, extending the timeline to six to seven months. Without these issues, it likely would have taken around three months, depending on the speed of obtaining API keys, authorizations from networking teams, and other factors. Under ideal circumstances, a three-month timeframe would be more accurate.

You need to maintain the pipeline, which includes data processing, before it reaches its destination. When onboarding new data, managing and rotating API keys as needed is important. Maintaining these aspects ensures faster and more efficient deployments.

If you want to reduce log ingestion or route data to multiple destinations, consider using an on-premises or cloud solution. Your choice will depend on your organization’s network constraints. For example, if critical assets on your network need to connect to the internet, your network team might have restrictions. Weigh the benefits of cloud versus on-premises options to determine what best fits your needs.

What other advice do I have?

With less data coming into our system, we can now run queries faster since we're not processing as much data as before. The reduction has made our queries more efficient because we're working with more streamlined data.

The quick connects are great for testing and allow you to rapidly set up a proof of concept, which is very beneficial. They can also be useful in production environments. Another significant feature is the recent Sentinel integration. The provided pack simplifies the setup process, making it much easier than the previous method, where you had to manually handle tasks like finding API keys. This integration makes the setup much more efficient.

Overall, I rate the solution a seven out of ten.


    reviewer2540610

Offers efficient log management but has room for better documentation

  • September 04, 2024
  • Review provided by PeerSpot

What is our primary use case?

I use Cribl to ingest logs from different platforms. These logs could come from sources like Mimecast, Windows, or CrowdStrike logs. It acts as a pipeline to send data to our destinations and also helps in reducing the amount of logs sent by applying different functions on them.

How has it helped my organization?

Cribl has helped to save thousands of dollars for our clients. It provides cost-effective solutions, particularly when you know how to use it effectively. It does require some learning to cover all aspects of it because it's not entirely intuitive. However, once you overcome the learning curve and get hands-on with the platform, it significantly contributes to cost savings.

What is most valuable?

The capability to reduce logs in a user-friendly manner is a standout feature. Cribl allows us to view logs live as they are being processed, giving us quick feedback on the changes made.

Additionally, the data routing feature is beneficial because it gives us the option to send logs through data routes or QuickConnect, facilitating quick configurations of different sources and managing them more effectively. These functionalities offer logical and useful capabilities such as deciding where logs should be sent and specifying which fields should be included within the logs.

What needs improvement?

There is room for improvement in the documentation and knowledge base, particularly regarding configurations like sources where logs are being ingested. It would be helpful to have specific guidance on configuring different data sources, such as AWS S3 buckets. Additionally, the ability to understand what type of output a function will produce is missing in Cribl, which could be improved by indicating the output type.

For how long have I used the solution?

I have been using Cribl for more than one and a half years.

What do I think about the stability of the solution?

Cribl's stability has been well documented online, and we have not encountered any significant stability issues.

What do I think about the scalability of the solution?

We have tested Cribl and found it to be sufficiently scalable for our needs.

How are customer service and support?

At the time I was trying to do the course back then, I did escalate questions to tech support, but I haven't raised any recent issues.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have experience with Splunk and CrowdStrike. I am quite familiar with Splunk.

What was our ROI?

Cribl is indeed a cost-effective solution, saving thousands of dollars for our clients. It provides value through cost savings and time efficiency once users know how to effectively use the platform.

What other advice do I have?

It's important to know what source you will be using to ingest data into Cribl. Understanding how to configure the data source is key before using the platform. Once you have that figured out, Cribl becomes a powerful solution that can ingest almost anything with its Edge capability. However, having a clear understanding of the pathways you can take to ingest data is crucial before diving into it.


    Maciej Grabowski

Provides impressive architecture and easy setup but have administrative issues

  • September 02, 2024
  • Review provided by PeerSpot

How has it helped my organization?

We've encountered several challenges, but what's most promising and encouraging is Cribl's scalability. The architecture is impressive, and it distributes work across all worker nodes and communicates with the leader.

What needs improvement?

There have been several administrative issues. Another point is that the browsing functions aren't very intuitive.

The most challenging aspect is the versioning system. Everyone can see and potentially deploy each other's changes in a team of developers. Unlike traditional versioning systems, where you work in isolated feature branches and only merge changes after reviewing conflicts, Cribl's versioning system requires careful management because everyone works on the same repository.

I work with a team that includes both experienced and less experienced developers. Though new to this technology, the two senior developers have extensive experience with various other technologies and can get up to speed relatively quickly with the available training. The less experienced developers face significant challenges. They struggle to understand the system, suggesting it may not be intuitive.

For how long have I used the solution?

I have been using Cribl for two years.

What do I think about the stability of the solution?

I rate the solution’s stability a seven out of ten.

What do I think about the scalability of the solution?

10-15 people are using this solution.

How are customer service and support?

Everything works, but it required a lot of support. The setup wasn't easy, but the support team was very helpful and managed to get everything production-ready.

How was the initial setup?

Setting up Cribl for basic training is straightforward and effective. You can easily configure it on your laptop by downloading the binaries and using simple command-line instructions to set it up in different modes, like leader, edge node, or single deployment. Adding a worker node is also simple; just run a script generated in the UI, and it's up and running.

The enterprise setup process is more complex, and there are significant documentation challenges. Despite the system eventually being available, the process involved many support calls and workarounds. Getting everything set up for a production-ready enterprise deployment was long and challenging.

What other advice do I have?

In some of the projects I've been working on, we're still testing and exploring Cribl's capabilities. We haven't established specific business goals or fixed objectives yet. Currently, we're focused on ingesting data from various sources with minimal transformation to understand how Cribl handles different types of logs and data.

I encounter issues with the UI not accurately reflecting the current status. For example, the UI might show that a worker is still fetching the latest version of the code, but after refreshing the page, it usually updates to show that everything is up and running. Over time, I've learned to recognize when the UI is not displaying the correct information and use the refresh button to get the accurate status.

Overall, I rate the solution a six out of ten.


    Pawel Kwiatkowski

Provides a robust framework for managing data flows, but the debugging capabilities need improvement

  • August 07, 2024
  • Review provided by PeerSpot

What is our primary use case?

My primary use case for the platform was the internal management of events, parsing, and enriching events based on lookup files. It involved creating sources and destinations, managing data processing, and serializing data.

How has it helped my organization?

The solution has streamlined our data management and processing, making handling event data easier and forwarding it to the required destinations. It has provided a robust framework for managing data flows and event parsing, improving our overall efficiency in handling large volumes of data.

What is most valuable?

The product's most valuable features include the internal management of events, coding perspective, data processing, and serialization.

What needs improvement?

The product could be improved in terms of its logging and debugging capabilities. The sys logging could be enhanced to make it easier to identify errors, especially when dealing with multiple functions. Additionally, the user interface could be more flexible for advanced customizations.

For how long have I used the solution?

I have been using Cribl for over one year. In my previous position, I integrated it with Broadview and socket and SNMP for event management, forwarding events to BigPanda via webhook, and writing JavaScript code for event parsing and enrichment.

What do I think about the stability of the solution?

I rate the stability of this solution as six out of ten. While it is generally stable, issues have affected its reliability, especially with more advanced and customized uses.

What do I think about the scalability of the solution?

The solution is quite scalable. It allows for performance extension by distributing workloads among multiple workers via a load balancer. This architecture supports different customer needs for small-medium companies or larger enterprises.

How are customer service and support?

The support team is good and willing to resolve issues. However, they could improve their understanding of customer requirements.

How was the initial setup?

The initial setup can vary in complexity depending on the integration. It is straightforward for well-defined formats like JSON or XML. However, customized integrations may require significant development effort.

What other advice do I have?

The solution is well-suited for quick integrations and common data processing tasks. However, highly customized integrations might require additional development efforts.

I rate it a seven out of ten.


showing 1 - 6