This document is an introduction to how to configure, understand and leverage Cribl Stream or CrowdStream to provide data collection capabilities for the CrowdStrike Falcon® Next-Gen SIEM platform. It covers topics such as:
- Understanding the basic data collection methods for Next-Gen SIEM with Cribl
- Basic configuration of the platforms
- Explanation of the ingestion URLs available with Next-Gen SIEM
- Syntax considerations for HEC based ingestion URLs
- Common misconfigurations when ingesting data and ways to identify them