A multinational technology company, established in the cloud, was seeking ways to enhance its security posture without incurring prohibitive costs associated with Security Incident Event Management (SIEM) licensing.
The firm's intent to expand its data feeds into the SIEM was met with challenges due to existing licensing restrictions and utilization limits, prompting a search for a cost-effective solution.
Adopting Cribl for Data Optimization
RiverSafe recommended Cribl due to its capability to optimize, route, and enrich data
The company partnered with cybersecurity expert RiverSafe to navigate this issue. RiverSafe recommended Cribl due to its capability to optimize, route, and enrich data. A proof of concept was conducted, focusing on some of the organization's most substantial data sources to determine the reduction in data ingestion.
“We chose four data sources, and deliberately chose some of our most volumetric data sources. We had a success criterion in mind, and that was to send all these data sources to our SIEM environment via Cribl and see what kind of reduction we could get from a percentage perspective,” the head of security program management said.
Following a successful trial, which indicated a potential reduction, the company decided to implement Cribl Stream for data optimization.
Reduction in Data Ingestion
Implementing Cribl Stream led to a significant decrease in data being injected into the SIEM, dropping from 750GB to 450GB. This roughly 40% reduction aligned with the company's initial targets, primarily by filtering out redundant fields and null values, ensuring that crucial data did not miss detection rules.
“What really surprised me was how easy it was to reduce the data feeds into the SIEM. I was really shocked at how seamless it was to introduce a layer like Cribl to assist with the data optimization and reduction,” a company representative noted.
Improved Data Ingestion and Scalability
Further benefits were realized post-implementation, including streamlined data ingestion
Further benefits were realized post-implementation, including streamlined data ingestion. By directing data through Cribl, the company could selectively send targeted data into the SIEM, enhancing onboarding efficiency for new feeds.
This approach mitigates licensing issues, offering increased scalability and adaptability. As the company expands, it can scale visibility without additional SIEM licensing burdens.
“Going forward, we’ll have scalability from a visibility and coverage perspective without being constrained by a SIEM license,” the company stated.
Significant Cost Savings
Beyond operational efficiency, Cribl Stream has enabled the company to introduce additional data feeds into its SIEM while circumventing the need for costly licensing expansions, estimated to save between £120,000 to £150,000 annually.
“Now that we’ve got Cribl in our architecture, we have the ability to ingest more data feeds without having to buy additional licensing—that’s already saved us money,” a representative commented.
Additional cost benefits emerged from reduced storage costs in the cloud, as Cribl allows for archival data to be stored more affordably with maintained searchability for audits and investigations.
Enhanced Resource Utilization
Cribl's implementation also streamlined resource use by cutting down on manual data management tasks. The tool allows for data to be routed efficiently to various endpoints without extensive configuration, significantly reducing setup time from days to mere hours.
“Since the introduction of Cribl, we’ve cut that down to half a day because now we only need to configure to send to Cribl and Cribl takes care of translating the data into the ideal format for other destinations,” stated the organization's representative.
This decreased time and labor contribute to further cost reductions, optimizing resources for the cloud-native company.
When it comes to balancing visibility and spending, Security Incident Event Managment (SIEM) licensing models can be somewhat restrictive—something a multinational, born in the cloud technology company was becoming painfully aware of.
The organization wanted to improve its security posture by ingesting more data feeds into its SIEM. However, its cybersecurity team found itself hampered by license limitations and prevented from feeding in more data by license utilization caps.
Faced with excessive additional licensing costs, the company needed an alternative solution that would optimize the ingestion of data, reduce license usage, and boost visibility across its environment—without breaking the bank.
Enter Cribl
Looking for the best solution to achieve their data goals, the company reached out to cybersecurity company RiverSafe for advice. Given its ability to optimize, route and enrich data, Cribl was chosen as a possible fit, and RiverSafe began a proof of concept to investigate the potential impact the product could have on the company’s data streams.
“We chose four data sources, and deliberately chose some of our most volumetric data sources. We had a success criterion in mind, and that was to send all these data sources to our SIEM environment via Cribl and see what kind of reduction we could get from a percentage perspective,” the head of security program management said.
“It’s seemed to be a very good product and much needed in the marketplace. There are many organizations like us who have the same kind of challenges and the same use case issues, whereby they don’t have the budget or inclination to spend more and more money on their SIEM.”
Instant data ingestion reduction
After a successful proof-of-concept, the company opted to implement Cribl Stream. “I know (Cribl Stream) and I knew its capability, so I had an inkling as to what the reduction rate could potentially be. What really surprised me was how easy it was to reduce the data feeds into the SIEM. I was really shocked at how seamless it was to introduce a layer like Cribl to assist with the data optimization and reduction.”
After implementing Cribl Stream as an optimization layer, the company reduced the amount of data being fed into its SIEM from around 750GB to 450GB.
“We were able to reduce our data ingest by about 40%, which matched our original success criteria around the percentage we hoped to reduce the data ingestion by. More importantly, what we were reducing were largely blank fields and null values, content that didn’t feed into our detection rules. We’re able to gain this headroom and cost savings without sacrificing visibility or increasing risk.”
Streamlining data ingestion
An additional benefit the company experienced post-implementation was streamlined data ingestion. By pointing data through Cribl, the company is able to cherry-pick the data that’s sent to its SIEM, simplifying the onboarding process for new data feeds.
“Once we’ve pointed the data to Cribl, we’re able to pick and choose what data we send into the SIEM and what data we don’t. That’s made it a lot more efficient in terms of the way we onboard data, and it’s enabled us to be a lot more granular with the data that we ingest into our SIEM.”
Greater scalability
With the reduction in data ingestion levels, the company is less likely to run into issues due to SIEM licensing limitations. By employing Cribl to help manage its data, the company hopes to benefit from greater scalability and agility in the future.
“Going forward, we’ll have scalability from a visibility and coverage perspective without being constrained by a SIEM license.” This flexibility is just one of the wide-reaching benefits that the company has experienced since implementing Cribl, and one that’s made a major difference to its operations.
“Cribl gives you the flexibility to reduce data ingest, but also the flexibility to be agile and to move your data sources from one environment to another without much configuration. It’s given us the capability to be less rigid in our architecture; that’s been the biggest impact for us.”
Significant cost savings
Having cut data ingestion by 40% with Cribl Stream, the company is free to load more data feeds into its SIEM without the need to purchase additional licensing capacity. This has not only allowed the company to increase visibility across its digital environment, but also cut down on licensing costs.
“Now that we’ve got Cribl in our architecture, we have the ability to ingest more data feeds without having to buy additional licensing—that’s already saved us money. If we didn’t have Cribl, that additional cost would have been between £120,000 and £150,000 per year, on top of what we’re already paying today for our SIEM.”
As well as reducing spending on SIEM licensing, the company has been able to cut costs in other areas. “We’re completely in the cloud, so we’re charged for data that we retain for a longer period. Now that we have Cribl, we can send the data that we want to retain to a cheaper storage solution. And with Cribl Replay and Cribl Search, we still have the ability to easily search that data should we need it for audits or incident investigation. That gives us a cost benefit and more flexibility in the long run.”
Smarter resource utilization
Cribl is also helping the company put its valuable resources to better use by cutting down on manual data management tasks.
Previously, its team had to configure multiple destinations when data was ingested. With Cribl, data from various locations can be ingested once and pointed to numerous locations around the business, eliminating the need for system and platform owners to configure multiple endpoints.
FTE effort to implement a data feed
“Normally, it would’ve taken us about two days of FTE effort to implement a data feed into Splunk or a similar destination. Since the introduction of Cribl, we’ve cut that down to half a day because now we only need to configure to send to Cribl and Cribl takes care of translating the data into the ideal format for other destinations.”
This reduction in time and labor adds up to additional cost savings too. Now, the company can send just the data that’s relevant to a particular end user, rather than shipping the entire data set. This has helped save money on licensing, infrastructure/compute, processing, and effort.
“Because we’re a cloud-native organization, processing costs money—if we’re able to save on that, then we are definitely winning from a cost perspective.”