icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.
Splunkbase will be undergoing a scheduled migration and will be unavailable on Saturday, Oct 1, 2022, from 11AM to 3PM PDT

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Push Data to Cribl
SHA256 checksum (push-data-to-cribl_108.tgz) c7fce516274fa0961cfe01ae47b9e2f82d92c6dd1f5c5dc6bbc37ef8cfb756c7 SHA256 checksum (push-data-to-cribl_107.tgz) 46f43dbba476f9c5c363316fbe3c9aa2209876791f041844cd323cab31f81eed SHA256 checksum (push-data-to-cribl_106.tgz) 072eedd308621da8488a988f64a6a569685c84400cb27a03e7eef441105100eb SHA256 checksum (push-data-to-cribl_105.tgz) a09c80e24620e5f95ead2dc0f0e599799c06579b2b85c16c0defe27837c8ab4f SHA256 checksum (push-data-to-cribl_104.tgz) c2efa374a30f9dddc227198269d5480ca172d7cc3ee62744511db90c2a44d689 SHA256 checksum (push-data-to-cribl_103.tgz) 087e83e1286517d5a162abfd54be7a57ae7a56ad55f7b6fdd7a29fb01e35a026 SHA256 checksum (push-data-to-cribl_102.tgz) 574a495855321858223deb70992e0548a5002b330e7118eac34ab7437b637a85 SHA256 checksum (push-data-to-cribl_101.tgz) 53e6bb029a9f41567301c3ead9f45d6af7a5cb840143eb413b087adbe2acc4a3 SHA256 checksum (push-data-to-cribl_100.tgz) 9e1af8a16b6b3d5a629e75f3c6f09cddd07d8e87102e3940bb9e73b26acdc577
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate


Push Data to Cribl

Splunk Cloud
This is a Splunk Modular Alert used to export Splunk search results to Cribl.

The search results are pushed to Cribl using the Cribl HTTPs Bulk API (https://docs.cribl.io/docs/sources-https)

The Python code in this App is dual 2.7/3 compatible.
This version of the App enforces Python 3 for execution of the modular alert script when running on Splunk 8+ in order to satisfy Splunkbase AppInspect requirements.
If running this App on Splunk versions prior to 8 , then Python 2.7 will get executed.

For details of the support we offer for our Apps , browse to : https://www.baboonbones.com/#support

Release Notes

Version 1.0.8
May 25, 2022

general updates to meet latest Cloud Vetting requirements

Version 1.0.7
Jan. 27, 2021

removed setup.xml because since Splunk 8.1 it does not seem to work (although it is permitted for Modular Alerts to have a setup.xml file), it just endlessly loops back on itself and writes no configuration settings, hence the App can't escape a "not yet configured" state. Replaced with a custom HTML setup form.

Version 1.0.6
Jan. 26, 2021

added urllib3 package for older versions of Splunk

Version 1.0.5
Nov. 13, 2020

updated logos

Version 1.0.4
Oct. 6, 2020

upgraded logging functionality

Version 1.0.3
Sept. 29, 2020

upgraded logging functionality

Version 1.0.2
Sept. 25, 2020

disabled some annoying log warning messages

Version 1.0.1
Sept. 19, 2020

chunking of HTTP POSTs.Default of 100 events sent per POST , but can be overridden
can declare a custom list of fields to POST to Cribl instead of the defaults

Version 1.0.0
Sept. 19, 2020

initial release

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.