Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
43 changes: 43 additions & 0 deletions packages/cribl/_dev/build/docs/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
# Cribl

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@alaudazzi would you mind reviewing this readme for a Cribl integration we're working on?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the late reply, I must have skipped the notification. Reviewing it now.


The Cribl integration offers users a way to ingest logs from either of Cribl's Elastic outputs into Elastic's Fleet integration data streams. This enables Cribl users to leverage the power of the Elastic Common Schema to unlock predefined dashboards, alerts and more.

## Instructions

1. Install the relevant integration assets in Kibana

In order to make the most of your data, install Fleet integration assets to load index templates, ingest pipelines, and dashboards into Kibana. In Kibana, navigate to **Management** > **Integrations** in the sidebar.

Find the relevant integration(s) by searching or browsing the catalog. For example, the Cisco ASA integration.

![Cisco ASA Integration](../img/catalog-cisco-asa.png)

Navigate to the **Settings** tab and click **Install Cisco ASA assets**. Confirm by clicking **Install Cisco ASA** in the popup.

![Install Cisco ASA assets](../img/install-assets.png)

2. Configuring the Cribl integration

1. Add informational field to Cribl Source

Configure the Cribl Source to specify the source of the data in the `_dataId` field.

![Configure Cribl Source fields](../img/cribl-source-fields.png)

See [Cribl Data Onboarding](https://docs.cribl.io/stream/data-onboarding/) for more information on configuring sources.

2. Configure the Cribl integration in Kibana

Note: The Cribl integration does not require Elastic Agent, but a policy must be configured when setting up the Cribl integration.

4. Configure an Elastic destination in Cribl

Cribl offers two options for sending data to Elastic, the Elastic Cloud output for cloud environments, and the Elasticsearch output for self-managed. Consult [Cribl Elastic Cloud documentation](https://docs.cribl.io/stream/destinations-elastic-cloud/) or [Cribl Elasticsearch documentation](https://docs.cribl.io/stream/destinations-elastic/) for more details on how to configure.

**Destination settings**

1. Set **Cloud Id** for the Cloud destination or **Bulk API URLs** for the Elasticsearch destination to point to your Elastic cluster.

2. Set **Index or Data Stream** to `logs-cribl-default`.

3. **API key** should be a Base64 encoded Elastic API key, which you can create in Kibana by following the instructions under **Management** > **Stack Management** > **Security** > **API Keys**. If you are using an API key with “Restrict privileges”, be sure to review the Indices privileges to provide at least "auto_configure" and "write" permissions for the logs-* index, which you will be using for these Fleet integration data streams.
5 changes: 5 additions & 0 deletions packages/cribl/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "0.2.0"
changes:
- description: Adds the second phase of the Cribl package
type: enhancement
link: https://github.com/elastic/integrations/pull/9097
- version: "0.1.2"
changes:
- description: Changed owners
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,12 +3,20 @@ description: Pipeline for rerouting log streams from Cribl.
processors:
- set:
field: ecs.version
value: 8.11.0
value: 8.13.0
- append:
field: tags
value:
- cribl
allow_duplicates: false
- rename:
field: _raw
target_field: message
ignore_missing: true
# The Cribl routing pipeline is managed by Kibana
# https://github.com/elastic/kibana/pull/176439
- pipeline:
Comment thread
kgeller marked this conversation as resolved.
name: 'cribl-routing-pipeline'
on_failure:
- set:
field: error.message
Expand Down
41 changes: 8 additions & 33 deletions packages/cribl/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,53 +16,28 @@ The Cribl integration offers users a way to ingest logs from either of Cribl's E

![Install Cisco ASA assets](../img/install-assets.png)

2. Update reroute rule logic
2. Configuring the Cribl integration

In order to specify the routing logic to be able to direct your events from Cribl to an Elastic integration datastream, setup a custom ingest pipeline for the Cribl integration.

1. Identify the name of the Elastic dataset

Review the relevant [integration documentation](https://docs.elastic.co/integrations) to determine the correct es_datastream_name value. The data stream components can be found in the example event for each integration.

![Cisco ASA sample event documentation](../img/sample-event-dataset-name.png)

2. Add informational field to Cribl Source
1. Add informational field to Cribl Source

Configure the Cribl Source to specify the source of the data in the `_dataId` field.

![Configure Cribl Source fields](../img/cribl-source-fields.png)

See [Cribl Data Onboarding](https://docs.cribl.io/stream/data-onboarding/) for more information on configuring sources.

3. Create custom pipeline

In Kibana, navigate to **Management** > **Stack Management** in the side bar. Under the **Ingest** header, select **Ingest Pipelines**. Click **Create pipeline** > **New pipeline**.

**Custom pipeline configuration**
1. The pipeline **Name** must be `logs-cribl@custom`.

2. **Add a processor**
2. Configure the Cribl integration in Kibana

1. Set the **Dataset** to the value identified in the step above (`cisco_asa.log` for our example).
Note: The Cribl integration does not require Elastic Agent, but a policy must be configured when setting up the Cribl integration.

2. Set the **Namespace** to `default`.
4. Configure an Elastic destination in Cribl

3. Fill in the conditional to specify the Cribl `_dataId` source field.

![Reroute processor](../img/custom-pipeline-reroute-processor.png)

3. Configure an Elastic destination in Cribl

Cribl offers two options for sending data to Elastic, the Elastic Cloud ouput for cloud environments, and the Elasticsearch output for self-managed. Consult the or the [Cribl Elastic Cloud documentation](https://docs.cribl.io/stream/destinations-elastic-cloud/) or [Cribl Elasticsearch documentation](https://docs.cribl.io/stream/destinations-elastic/) for more details on how to configure.
Cribl offers two options for sending data to Elastic, the Elastic Cloud output for cloud environments, and the Elasticsearch output for self-managed. Consult [Cribl Elastic Cloud documentation](https://docs.cribl.io/stream/destinations-elastic-cloud/) or [Cribl Elasticsearch documentation](https://docs.cribl.io/stream/destinations-elastic/) for more details on how to configure.

**Destination settings**

1. Set **Cloud Id** for the Cloud destination or **Bulk API URLs** for the Elasticaearch destination to point to your Elastic cluster.
1. Set **Cloud Id** for the Cloud destination or **Bulk API URLs** for the Elasticsearch destination to point to your Elastic cluster.

2. Set **Index or Data Stream** to `logs-cribl-default`.

3. **API key** should be a Base64 encoded Elastic API key, which can be created in Kibana by following the instructions under API Keys. If you are using an API key with “Restrict privileges”, be sure to review the Indices privileges to provide at least "auto_configure" & "write" permissions for the logs-* index, which you will be using for these Fleet integration data streams.




3. **API key** should be a Base64 encoded Elastic API key, which you can create in Kibana by following the instructions under **Management** > **Stack Management** > **Security** > **API Keys**. If you are using an API key with “Restrict privileges”, be sure to review the Indices privileges to provide at least "auto_configure" and "write" permissions for the logs-* index, which you will be using for these Fleet integration data streams.
Binary file not shown.
Binary file removed packages/cribl/img/sample-event-dataset-name.png
Binary file not shown.
11 changes: 9 additions & 2 deletions packages/cribl/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,19 +1,26 @@
format_version: 3.0.0
name: cribl
title: "Cribl"
version: 0.1.2
version: 0.2.0
description: Stream logs from Cribl into Elastic.
type: integration
categories:
- custom
conditions:
kibana:
version: "^8.8.0"
version: "^8.13.0"
icons:
- src: /img/logo.svg
title: Cribl logo
size: 32x32
type: image/svg+xml
vars:
- name: route_entries
type: textarea
title: Route mappings from Cribl sources to Elastic datastreams
multi: false
required: true
show_user: false
owner:
github: elastic/security-service-integrations
type: elastic