The feature I appreciate most about Cribl is the interface and how you're able to interact with the data, see the data both live on the ingest side as well as on the side where it goes out to the destination, which is a feature that was lacking in the previous solution I was using.
Cribl does a really great job of making sure that no matter how crazy the data set is, we're able to see that data and understand it, and then perform advanced functions against the data to make sure that it is in the ready state for whatever the end place is in which we wish to send it. It really helps us because we have thousands of different types of data which we have to run through Cribl and make sure that they get to the right place in the right amount of time.
Cribl is world-class at handling large volumes and types of of data, including metrics. Currently, for my organization, we push multiple terabytes worth of data through the solution every day. And we've been able to find out that it's easily scalable, and I feel that in the future, it's able to grow as our needs for data grow. We have been able to see reductions in firewall logs. For many organizations, firewall logs are one of the largest log sources, modernization included. And so with Cribl, we can use the aggregation functions to make sure that we're pulling out key information from those logs and sending those over to our SIEM solution.
In terms of the user interface of Cribl for managing log manipulation tasks, it is a world-class solution. It's one of the main reasons which drove us to contracting and purchasing Cribl. We were tired of using plain text files to manipulate data, especially at our large volume. It really helps us be able to see and click and have an easier interface, so administrators are able to do the same things that previously engineers weren't able to do, working with flat files.