Home /Cribl Search 4.10.1

Cribl Search 4.10.1 ​

PRODUCTDATERELEASEADDITIONAL RESOURCES
Search2025-02-26MaintenanceKnown Issues

With version 4.10.1, Cribl Search offers more consistent evaluation of empty objects, expanded Datatypes options, improved Dashboards management, a gzip download option for lookup files, and several other functional and UX fixes.

Important Changes ​

These changes to Cribl Search might require you to check or modify existing queries, or other configuration, especially on saved searches.

Deprecation Notice: Dataset Acceleration ​

Cribl is deprecating Dataset Acceleration (a Preview feature) in preparation for a different solution. This feature will be removed in a future release. Please continue to report issues through normal Cribl support channels, but assistance for this deprecated feature might be limited.

New Features ​

This release includes the following new features:

isempty and isnotempty Empty Object Evaluation ​

The isempty and isnotempty functions now evaluate an empty object ({}) as empty. This makes their behavior more consistent with integrated services.

Corrections ​

This release includes several fixes to various areas of Cribl Search, most notably:

ReferenceDescription
CRIBL-30329
After a session timeout, logging back into Cribl.Cloud now restores focus to the last-viewed product page.
SEARCH-9014Restored Datatypes link within Datasets.
SEARCH-8605The datetime Datatype now supports decimal values, as well as integers.
SEARCH-8542Determining the scalar value of a let query now works as expected.
SEARCH-8616Queries that include project *, field, some=expression now add to results, rather than replacing them. This new behavior is equivalent to extend some=expression.
SEARCH-8732Queries that include the find operator no longer return empty events.
SEARCH-8751Cribl Search now supports downloading lookup files in gzip (.gz) format.
SEARCH-7941Email Notifications now properly format embedded _time values, using UTC.
SEARCH-7991The Objects discovered, scanned, and skipped metrics now update as expected (below the query box) when a search completes.
SEARCH-9055Restored the ability to run ad hoc searches within the context of a Pack.
SEARCH-9074Adding a new Dashboard to a Pack no longer locks out the Add or Exit options.
SEARCH-8996Moving a Dashboard between Collections now preserves its ownership (Created by) metadata.
SEARCH-8381In Visualization details pop-overs, the Created by field now properly renders the owner’s display name, rather than an ID hash.
SEARCH-4307When configuring a new visualization, the Add to Dashboard modal’s default button is now Add & Go to Dashboard.
SEARCH-3326The Saved Searches page no longer displays a misleading Add Search button for users whose Permission does not allow them to create searches.
SEARCH-3328The Search Home page’s Actions menu no longer displays a misleading Save Search option to users whose Permission does not allow them to execute it.
SEARCH-2695Configuring a Google Workspace API Dataset Provider now exposes a modal with improved controls.