Cribl: The Stream Life

Cribl: The Stream Life

Download on the App Store

Cribl: The Stream Life episodes

  • Building a Distributed Security Team

    In this live stream, Cjapi's James Curtis joins Ed Bailey to discuss the challenges of building a distributed global security team. Talent is hard to find, and companies are hiring from all over the world to build the best teams possible, but this trend has a price. Traditional management processes don't always transfer over to remote management — everything from building a culture to the basics around assigning, tracking, and measuring work needs adjustment.

    28 min
  • The Top 4 Trends Defining Observability in 2023

    In this episode of The Stream Life Podcast, Nick Heudecker comes on the show to look at the major trends defining the observability market in 2023

    Resources
    • Learn more about CriblCon
    • Register for CriblCon
    • When Stream Meets Lake: Cribl's Integration With Amazon Security Lake Helps Customers Address Data Interoperability

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    22 min
  • The Evils of Data Debt

    Join Cribl's Ed Bailey and Jackie McGuire as they discuss the harmful effects of data debt on observability and security teams. Data debt is a pervasive problem that increases costs and produces poor results across observability and security. Simply put, garbage in equals garbage out. Ed and Jackie will delve into what data debt is and how to solve it in the long term. They will explore the complex nature of observability and security data, which is highly volatile and requires a different approach from typical analytics use cases. To get the best results, data standards must be established with high-level buy-in from leadership. Additionally, teams must have access to a high-quality observability pipeline that allows them to manipulate data in real-time. It's also important to build a strong relationship with your GRC team, so you can track issues with standards and gain the right visibility in the enterprise. With the right strategies, data debt can be overcome, and Ed and Jackie will help you get started on the road to success.

    29 min
  • CriblCon - Criblers: Assemble!

    In this episode of The Stream Life Podcast, I chat with Mike Dupuis about CriblCon! At Cribl, we understand there is power in getting together IN PERSON to share ideas, best practices, and swap battle stories with friends new and old. That's what CriblCon, on July 17th, at the Mirage in Las Vegas, is all about. We're bringing together a group of remarkable people–that's YOU!–to solve problems, talk architecture, figure out how to route, optimize, and enrich data to get more value from your SIEM, AI Ops, and analytics tools and do more with less.

    Resources
    • Learn more about CriblCon
    • Register for CriblCon

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    24 min
  • Industry Experts Discuss Cybersecurity Trends and a New Fund to Shape the Future

    In this live stream discussion, angel investor Ross Haleliuk joins Cribl's Ed Bailey to make a big announcement about his new fund to shape the future of the cybersecurity industry. Ross is a big believer in focusing on the security practitioner to provide practical solutions to common issues by making early investments in companies that will promote these values. Ed and Ross also discuss trends in the industry and common struggles that both Cribl and his new fund seek to address by adding value and giving security practitioners choice and control over how they run their security program.

    Read more about the discussion on Cribl's blog post.

    31 min
  • Giving the Goats A Day Off

    In this episode of The Stream Life Podcast, I chat with Lisa Nielsen, Cribl's SVP of People, about Cribl's recent Recharge Day. Listen to the show to learn more about our culture, open roles, and why we implemented a bi-annual recharge day.

    Resources
    • Cribl's Inaugural Recharge Day: Giving our Goats a 'Treat Yo' Self' Day
    • Cribl's open roles

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    14 min
  • It's Time to Assess the Potential Dangers of an Increasingly Connected World

    In this episode of The Stream Life Podcast, Bradley Chambers chats with Cribl's Jackie Maguire about the need for a stable infrastructure to protect against the crippling effects of cyber attacks. With the world becoming more interconnected, the stakes have never been higher. From power grids to financial systems, the consequences of a cyber attack can be devastating. The need for a secure infrastructure has become more critical than ever before. Join us as we delve into the importance of protecting critical infrastructures from cyber attacks and how we can create a more secure future.

    Resources
    • It's Time to Assess the Potential Dangers of an Increasingly Connected World

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    20 min
  • All About Cribl's Partner Program

    In this episode of The Stream Life Podcast, Bradley Chambers chats with Zac Kilpatrick and Ange Salerno about some exciting announcements to Cribl's partner program. Today, we've officially relaunched the program by adding an MSSP and Professional Services Specialization, deal and revenue protection, and marketing tools & resources. Additionally, we're launching a new partner portal that delivers self-service access to tools, enablement, and other selling resources needed to build their Cribl practice.

    Resources
    • Read the blog
    • Start your CCOE journey
    • Learn more about Cribl's partner program

    If you want to get every episode of the Stream Life podcast automatically, you can subscribe on your favorite podcast app.

    23 min
  • The Critical Role of Data in Cybersecurity: Why Incomplete Data Weakens Your Overall Program

    In this live stream, Cribl's Ed Bailey and CDW's Brenden Morgenthaler discuss a foundational issue with many security programs — having the right data to detect issues and make fast decisions. Data drives every facet of security, so bad or incomplete data weakens your overall program. Watch the video or continue reading below to learn about these issues and the strategies we use to solve security's data problem.

    As the amount of data, tools, systems, and clouds continue to increase, the threat to enterprises' security posture has risen as well. It simply doesn't matter what kind of SIEM you have anymore — even if it's as good as Splunk or its alternatives. If you don't have the right data, you'll run into problems.

    The Problem with Dropping Data Sources Due to Budget Constraints

    Budgets can no longer keep up with the amount of data that needs to be processed, so organizations are forced to get by without collecting and analyzing everything they should. As a result, security teams are forced to turn off data sources that could provide them valuable insights into credible threats. One client that Brenden and the team at CDW worked with got a firsthand look at the effects this has during a pen test they performed. They tested some common detections and were surprised to find that their red team engineer was able to completely compromise the domain and gain full control — simply because they had turned off all audit events on Kerberos. Situations like this are much too common and are just the tip of the iceberg —which is why it's so critical to have visibility into all areas of your network. You also need someone who knows all the different attack vectors so they can help you set up your infrastructure to avoid them.

    Poorly Formatted but Crucial Data Sources Eat Up Licensing Costs

    Data sources like Powershell, Sysmon, and Windows DNS debug logs are generally more difficult to work with. In the past, you'd have to rely on the heavy forwarder on the Splunk side or a ton of manual fine-tuning of things on the source side to handle the flood of data coming in from all these different systems and formats. This is where a tool like Cribl Stream can help — you can turn on a data source, send it to Stream, and then route to null by default. Then you can pull out specific streams and send them to your other tools as necessary. Other data won't need to be processed but will need to be kept for regulatory compliance issues, so you can keep it offline in raw, unmodified form in a data lake or send it to an object storage like an S3 bucket for as long as you need. Then if you need to recall it to investigate a data breach, you can use the replay feature in Stream to ingest it back through to whatever source you want without having to use your license or processing power. You can also use Cribl Stream to take advantage of EDR data. We see a lot of companies make enormous investments in EDR tools that also produce very accurate data, especially around assets — but then they don't take that data and put it into their SIEM because it's just too expensive. With Stream, you can take the majority of that EDR data and route it to a data lake, and then get value from the other 10-15% by routing it to your SIEM in the exact format you need it.

    Data Volume Management Strategies to Get the Best Results for Security

    To get the most value out of your data for security, you need to know what regulatory compliance you have to meet — what type of logs do you have to retain, and for how long? It also helps to have a good understanding of all the tools you have, what systems are in place, and what the limits are on your ingestion licenses. From there, securing your perimeter is the best place to start. You want your authentication sources, MFA sources, and VPN set up first, and then you can start bringing in all your security tools. The Mitre Attack framework is incredibly helpful to figure out what vertical you're in and see the common threat actors or attacks right you might encounter so you can decide which sources and services you'll need visibility from. Having had a long career in IT, I became used to constraints and compromise — which is why I was caught off guard when I first saw Cribl Stream back before I joined the company. Not having to make concessions on which data to pull in, where I could send it, what format it was in, or what my vendor would support was unexpected, to say the least. This choice and control is giving security teams the ability to have faster detections and even better responses to cyber threats. Be sure to watch the full conversation between Ed and Brenden, and connect with us in our Cribl Slack community if you have any questions or want to continue the discussion!

    41 min
  • Exploring Platform Engineering: Impacts on Observability and Security

    In this episode of The Stream Life Podcast, I chat with Luca Galante from Humanitec about platform engineering and its impact on observability and security. Platform engineering involves creating and developing toolchains and workflows that facilitate self-service functionalities for software engineering organizations in the era of cloud-native computing. The integrated product offered by platform engineers, commonly known as an "Internal Developer Platform," addresses the operational requirements throughout an application's lifecycle.

    Resources
    • What is platform engineering?
    • What is an internal developer platform?
    • What is Dynamic Configuration Management?
    • Platform Engineering community
    • PlatformCon 2023
    • Luca's LinkedIn and Twitter

    If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.

    33 min

About Cribl: The Stream Life

From the publisher's feed

Welcome to Cribl: The Stream Life, a podcast for IT pros trying to take control of their observability data with a no-compromise approach. With each episode, our hosts will cover the latest insights,…