On This Page

Home / Search/Get Data Into Cribl Search

Get Data Into Cribl Search ​

Ingest logs and metrics into Cribl Search lakehouse engines for schema-aware searches and precisely scoped AI investigations.


Highlights ​
  • Send directly into Cribl Search, auto-parsing events as they arrive.
  • First, add a lakehouse engine and Search Datasets within it. Then, connect your Sources.
  • Parse with Auto-Datatyping or your own Datatype rules, then route events with Log Dataset rules.

About Getting Data In ​

Next to running federated queries on external storage, Cribl Search can also ingest your data into lakehouse engines.

Lakehouse engines keep your data hot for up to 10 years, with no storage tiering to manage. This allows for:

  • High-speed search for day-to-day investigations and incident response.
  • Deeper AI-powered analysis, with structured data that makes exploration faster and more precise.
  • Tight cost control through fixed-size engines and per-Dataset retention.

You don’t have to use Cribl Stream, Edge, or Lake. You can ingest directly into Cribl Search.

To get started, add your first lakehouse engine. This enables the Get Data In tab in the Cribl Search Data section:

Get Data In tab in Cribl Search
Get Data In tab in Cribl Search

Get Data In Permissions ​

You need the Editor or Admin Permission on Cribl Search to set up Sources, Datatyping, and Datasets, and the Admin Permission to add a lakehouse engine. See Cribl Search Permissions.

Data Onboarding Overview ​

The data onboarding workflow differs slightly between logs and metrics.

LogsMetrics

Source Tutorials ​

Set up your Source with step-by-step instructions:

Next Steps ​

Once your data is in Cribl Search, you can: