Repository navigation
Cribl phase2 #9097
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Cribl phase2 #9097
Changes from all commits
Commits
Show all changes
11 commits
Select commit
Hold shift + click to select a range
6b0bd1f
Updates for cribl phase 2
kgeller 0461031
conflict resolution
kgeller 6a19438
changelog pr#
kgeller a544900
Update packages/cribl/_dev/build/docs/README.md
kgeller 91e1a56
Update packages/cribl/_dev/build/docs/README.md
kgeller 0766b2f
fixing typo and regenating
kgeller ed44e59
Update packages/cribl/_dev/build/docs/README.md
kgeller e45735a
regenerated docs and added note in pipeline
kgeller 4703427
Update packages/cribl/_dev/build/docs/README.md
kgeller 38b7237
Update packages/cribl/_dev/build/docs/README.md
kgeller 5aad4ee
regenerate
kgeller File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,43 @@ | ||
| # Cribl | ||
|
|
||
| The Cribl integration offers users a way to ingest logs from either of Cribl's Elastic outputs into Elastic's Fleet integration data streams. This enables Cribl users to leverage the power of the Elastic Common Schema to unlock predefined dashboards, alerts and more. | ||
|
|
||
| ## Instructions | ||
|
|
||
| 1. Install the relevant integration assets in Kibana | ||
|
|
||
| In order to make the most of your data, install Fleet integration assets to load index templates, ingest pipelines, and dashboards into Kibana. In Kibana, navigate to **Management** > **Integrations** in the sidebar. | ||
|
|
||
| Find the relevant integration(s) by searching or browsing the catalog. For example, the Cisco ASA integration. | ||
|
|
||
|  | ||
|
|
||
| Navigate to the **Settings** tab and click **Install Cisco ASA assets**. Confirm by clicking **Install Cisco ASA** in the popup. | ||
|
|
||
|  | ||
|
|
||
| 2. Configuring the Cribl integration | ||
|
|
||
| 1. Add informational field to Cribl Source | ||
|
|
||
| Configure the Cribl Source to specify the source of the data in the `_dataId` field. | ||
|
|
||
|  | ||
|
|
||
| See [Cribl Data Onboarding](https://docs.cribl.io/stream/data-onboarding/) for more information on configuring sources. | ||
|
|
||
| 2. Configure the Cribl integration in Kibana | ||
|
|
||
| Note: The Cribl integration does not require Elastic Agent, but a policy must be configured when setting up the Cribl integration. | ||
|
|
||
| 4. Configure an Elastic destination in Cribl | ||
|
|
||
| Cribl offers two options for sending data to Elastic, the Elastic Cloud output for cloud environments, and the Elasticsearch output for self-managed. Consult [Cribl Elastic Cloud documentation](https://docs.cribl.io/stream/destinations-elastic-cloud/) or [Cribl Elasticsearch documentation](https://docs.cribl.io/stream/destinations-elastic/) for more details on how to configure. | ||
|
|
||
| **Destination settings** | ||
|
|
||
| 1. Set **Cloud Id** for the Cloud destination or **Bulk API URLs** for the Elasticsearch destination to point to your Elastic cluster. | ||
|
|
||
| 2. Set **Index or Data Stream** to `logs-cribl-default`. | ||
|
|
||
| 3. **API key** should be a Base64 encoded Elastic API key, which you can create in Kibana by following the instructions under **Management** > **Stack Management** > **Security** > **API Keys**. If you are using an API key with “Restrict privileges”, be sure to review the Indices privileges to provide at least "auto_configure" and "write" permissions for the logs-* index, which you will be using for these Fleet integration data streams. | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Binary file not shown.
Binary file not shown.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,19 +1,26 @@ | ||
| format_version: 3.0.0 | ||
| name: cribl | ||
| title: "Cribl" | ||
| version: 0.1.2 | ||
| version: 0.2.0 | ||
| description: Stream logs from Cribl into Elastic. | ||
| type: integration | ||
| categories: | ||
| - custom | ||
| conditions: | ||
| kibana: | ||
| version: "^8.8.0" | ||
| version: "^8.13.0" | ||
| icons: | ||
| - src: /img/logo.svg | ||
| title: Cribl logo | ||
| size: 32x32 | ||
| type: image/svg+xml | ||
| vars: | ||
| - name: route_entries | ||
| type: textarea | ||
| title: Route mappings from Cribl sources to Elastic datastreams | ||
| multi: false | ||
| required: true | ||
| show_user: false | ||
| owner: | ||
| github: elastic/security-service-integrations | ||
| type: elastic |
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@alaudazzi would you mind reviewing this readme for a Cribl integration we're working on?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sorry for the late reply, I must have skipped the notification. Reviewing it now.