On This Page

Home / Search/ Manage/Workspaces

Workspaces ​

Use Workspaces to create isolated environments within your Cribl.Cloud Organization.


Workspaces offer a multi-tenancy capability, enabling you to create multiple isolated instances in your Cribl.Cloud Organization. This lets you strengthen your security, and fulfill compliance and isolation requirements.

Each Workspace offers a dedicated virtual private cloud (VPC) that acts as a separate environment within your Organization. Workspaces do not share product configurations, resources, or data flows, and each has a separate Leader Node. They do share a layer of access control (Organization-level Permissions and SSO configuration), as well as API credentials, licenses, and billing.

A centralized interface allows you to manage all your Workspaces and control access for Members and Teams to individual Workspaces.

Multiple Workspaces require a Cribl.Cloud Enterprise plan.

An example use case scenario for creating multiple Workspaces is setting up separate environments for different business units in an enterprise. Data management, security, development, and any other units can have their own federated Workspaces, with completely separate Members and Permissions lists. This way, they can work in isolation without risk of interference and with increased focus.

Limitations ​

The number of included Workspaces depends on your Cribl.Cloud plan:

PlanIncluded WorkspacesAdditional Workspaces you can add
Standard1 (the Main Workspace)N/A
Enterprise3Up to 2, at 250 credits each per month

On an Enterprise plan, Organization Owners and Admins can add Workspaces beyond the included allowance. When you have used the 3 included Workspaces, you can add up to two more on the Manage Workspaces page for 250 credits each per month.

When you select Add Workspace, Cribl.Cloud opens Accept additional cost? Select Accept to continue, or Cancel. The confirmation states that each Workspace you add costs an additional 250 credits per month, reflected in your next billing cycle.

Charges for additional Workspaces appear on your invoice under Infrastructure. See Understand Your Monthly Invoice.

In Cribl.Cloud, one credit equals one US dollar. An additional Workspace therefore costs $250 per month, prorated daily. See How Is Cost Calculated?.

Switch Workspaces ​

When you have access to multiple Workspaces in your Cribl.Cloud Organization, you can switch between them from the top bar in any Cribl product:

  1. On the top bar, select your current Workspace name.
  2. In the drop-down, select the Workspace you want to switch to.

The drop-down lists Manage Workspaces first. Select it to open the Workspace management modal, where you can add, edit, or delete Workspaces.

Below Manage Workspaces, the drop-down lists your Workspaces with the current Workspace first, followed by other Workspaces in alphabetical order.

If your Organization has only one Workspace, selecting the Workspace name on the top bar opens the Workspace management modal directly.

Manage Workspaces ​

To list the Workspaces in the Organization, in the sidebar, select Workspace or Organization and then Manage Workspaces. The list includes the name, ID, description, Cribl Insights retention status, tags, Cribl version number, and current state for each Workspace in the Organization.

Select a Workspace name or the ellipsis (...) in the Actions column to edit the Workspace name, description, and tags or delete the Workspace.

Release Channels ​

In Cribl.Cloud, Enterprise customers can assign each Workspace to the Regular or Slow release channel.

The Regular release channel (default) follows the standard monthly release cadence. The Slow release channel also updates on a monthly basis but is one version behind the Regular release channel. Cribl sends monthly notifications describing the versions published to each release channel.

Release channels give you self-service control over the upgrade cadence for each Workspace and allow you to validate new Cribl versions in pre-production Workspaces before deploying them to production environments. Release channel selection does not affect your support or product lifecycle.

Release channels determine when Cribl publishes feature and maintenance releases to Workspaces:

  • Regular release channel (default): Cribl publishes new feature and maintenance releases to the Regular release channel monthly.
  • Slow release channel: Cribl publishes new feature and maintenance releases to the Slow release channel one month after the corresponding Regular release enters production.

If Cribl publishes a hotfix to the Regular release channel within the previous two weeks, Cribl delays the Slow release channel update until the following month.

Cribl does not update the Slow release channel in November or December.

Cribl might deliver critical security and other emergency updates outside the normal release channel schedule. In these cases, to protect customer environments, Cribl might update Workspaces assigned to the Slow release channel to the same version as Workspaces assigned to the Regular release channel.

Change the Release Channel for an Existing Workspace ​

To change the release channel for an existing Workspace:

  1. On the top bar, select the current Workspace name, then select Manage Workspaces.
  2. Next to the Workspace that you want to update, select Settings in the Actions column.
  3. On the Details page, select the Release Channels tab.
  4. Select Regular or Slow.
  5. Select Save.

Cribl does not immediately change a Workspace’s version when you change its release channel. The Workspace stays on its current version until the next scheduled upgrade cycle.

Cribl does not downgrade a Workspace when you change it to the Slow release channel. Cribl does not support rolling back Workspaces to earlier versions.

If your Workspace includes customer-managed Worker Nodes or Edge Nodes, do not upgrade them to a version newer than the Leader Node version. For version compatibility requirements, see Supported Version Differences Between Leader and Workers and Supported Version Differences Between Leader and Edge Nodes.

View Workspace Details ​

Workspaces provide a set of information that you can use when configuring data flow through their Edge Nodes.

View Access Details ​

To view detailed access information of your Workspace, in the sidebar, select Workspace and then Access.

This page presents a summary of information about your Cribl.Cloud Organization, as well as the Cribl.Cloud URL for the current Workspace.

Cribl.Cloud URL ​

Cribl.Cloud URL is a static address associated with the load balancer that is in front of the Leader. Hybrid Stream Workers will connect to this address on port 4200, while the Leader UI is served from this address on port 443.

You can use this URL for certain API calls and certain Collection operations coordinated by the Leader.

Static External IPs for the Leader ​

The Leader NLB IPs field in Workspace > Access lists the IPs for the Leader Network Load Balancers associated with the Workspace.

Typically, only 2 of the 3 addresses will be active (returned by DNS) at any time, while the inactive address is swapped in during infrastructure maintenance events.

You can add all those IPs to your firewall allowlist to ensure that the load balancers are accessible across your hybrid deployment.

Get ARN ​

To get the ARN (Amazon Resource Name) for your Workspace, in the sidebar, select Workspace and then Trust.

You can copy and paste the Worker ARNs listed in the Trust page to attach a Trust Relationship to an AWS account’s IAM role. Use the Group drop-down to display the ARN for any Group of Cribl-managed Stream Worker Groups in Cribl.Cloud.

Attaching a Trust Relationship enables the AssumeRole action, providing cross-account access. For usage details, see the AWS Cross-Account Data Collection topic’s Account B Configuration section.

This option applies only to your Cribl-managed Stream Workers in Cribl.Cloud. You cannot use this technique to enable access to customer-managed hybrid Workers.

Set Up ACL ​

To set up Access Control List (ACL) Rules, in the sidebar, select Workspace and then Access Control List.

ACL Rules (IPv4 CIDR ranges) let you restrict data sent to your data sources. The Rules you define here are global to all Cribl-managed Worker Groups in Cribl.Cloud in the current Workspace. You can set up a maximum of 9 ACL Rules.

The default 0.0.0.0/0 rule (modifiable) imposes no limits. End a rule with /32 to specify a single IP address, or with /24 to enable a whole CIDR block from x.x.x.0 to x.x.x.255.

Select Save after adding, modifying, or removing rules. Each change takes up to 5 minutes to propagate. Cribl.Cloud will display a banner, notifying you that rules edits are temporarily disabled to prevent conflicts. A successful update proceeds silently - you will not see a confirmation message.

The ACL options apply only to Cribl-managed Stream Workers in Cribl.Cloud. You cannot use them to set access rules on customer-managed hybrid Workers.