Security Incident Event Management (SIEM) licensing models can often be a challenge for companies seeking to manage visibility and costs effectively. This was the case for a global technology firm operating in the cloud, which faced limitations due to existing license caps that restricted data ingestion.
The company was eager to enhance its security by incorporating more data feeds into its SIEM but ran into prohibitive licensing costs that demanded an innovative solution.
Implementing Cribl for data optimisation
To address these challenges, the company enlisted the expertise of cybersecurity firm RiverSafe, considering Cribl’s data optimisation capabilities. Conducting a proof of concept, the security program manager explained, "We chose four data sources, deliberately selecting some of our most volumetric ones. Our goal was to send these through Cribl and assess the data reduction we could achieve."
The proof of concept revealed significant potential in reducing unnecessary data entry, particularly blank fields and null values, thus aligning with the company’s cost reduction targets.
Achieving significant data ingestion reduction
The security program manager noted the ease of configuring Cribl, which facilitated seamless data feed optimisation
Following a successful trial, the company adopted Cribl Stream, experiencing an impressive 40% drop in data ingestion from approximately 750GB to 450GB. The security program manager noted the ease of configuring Cribl, which facilitated seamless data feed optimisation.
"Introducing a layer like Cribl significantly aided our data reduction without compromising visibility or increasing risk," they stated.
Enhanced data streamlining and scalability
The implementation of Cribl Stream also streamlined data ingestion, allowing the company to selectively channel data into its SIEM system, thus enhancing onboarding efficiency.
This capability provided greater control over data selection and presented opportunities for scaling operations without exceeding SIEM licensing limitations. The company anticipates increased scalability and operational flexibility, benefits attributed to implementing Cribl.
Cost efficiency and operational benefits
The cloud-native company further optimised costs by redirecting data to more affordable storage options
By integrating Cribl and cutting data ingestion by 40%, the firm has circumvented the need for additional SIEM licensing capacity, which could have cost between £120,000 and £150,000 annually. "With Cribl, we can ingest more data feeds without buying extra licenses, which has already saved us money," noted the manager.
The cloud-native company further optimised costs by redirecting data to more affordable storage options while maintaining searchability for audits or incident investigations.
Optimised resource utilisation
Moreover, Cribl’s implementation has streamlined resource utilisation, reducing manual data management by enabling data to be ingested from various locations and directed as needed. Previously, setting up a data feed might take two days of full-time effort, but now, this can be achieved in half a day thanks to Cribl's capacity to handle data configuration and transformation.
The adoption of Cribl Stream not only mitigates SIEM-related expenses but also enhances data management efficiency, allowing the firm to focus its resources more strategically and efficiently. For cloud-based operations where processing costs are significant, these savings represent a meaningful boost to the firm's bottom line.
When it comes to balancing visibility and spending, Security Incident Event Managment (SIEM) licencing models can be somewhat restrictive—something a multinational, born in the cloud technology company was becoming painfully aware of.
The organisation wanted to improve its security posture by ingesting more data feeds into its SIEM. However, its cybersecurity team found itself hampered by licence limitations and prevented from feeding in more data by licence utilisation caps.
Faced with excessive additional licencing costs, the company needed an alternative solution that would optimise the ingestion of data, reduce licence usage, and boost visibility across its environment—without breaking the bank.
Enter Cribl
Looking for the best solution to achieve their data goals, the company reached out to cybersecurity company RiverSafe for advice. Given its ability to optimise, route and enrich data, Cribl was chosen as a possible fit, and RiverSafe began a proof of concept to investigate the potential impact the product could have on the company’s data streams.
“We chose four data sources, and deliberately chose some of our most volumetric data sources. We had a success criterion in mind, and that was to send all these data sources to our SIEM environment via Cribl and see what kind of reduction we could get from a percentage perspective,” the head of security programme management said.
“It’s seemed to be a very good product and much needed in the marketplace. There are many organisations like us who have the same kind of challenges and the same use case issues, whereby they don’t have the budget or inclination to spend more and more money on their SIEM.”
Instant data ingestion reduction
After a successful proof-of-concept, the company opted to implement Cribl Stream. “I know (Cribl Stream) and I knew its capability, so I had an inkling as to what the reduction rate could potentially be. What really surprised me was how easy it was to reduce the data feeds into the SIEM. I was really shocked at how seamless it was to introduce a layer like Cribl to assist with the data optimisation and reduction.”
After implementing Cribl Stream as an optimisation layer, the company reduced the amount of data being fed into its SIEM from around 750GB to 450GB.
“We were able to reduce our data ingest by about 40%, which matched our original success criteria around the percentage we hoped to reduce the data ingestion by. More importantly, what we were reducing were largely blank fields and null values, content that didn’t feed into our detection rules. We’re able to gain this headroom and cost savings without sacrificing visibility or increasing risk.”
Streamlining data ingestion
An additional benefit the company experienced post-implementation was streamlined data ingestion. By pointing data through Cribl, the company is able to cherry-pick the data that’s sent to its SIEM, simplifying the onboarding process for new data feeds.
“Once we’ve pointed the data to Cribl, we’re able to pick and choose what data we send into the SIEM and what data we don’t. That’s made it a lot more efficient in terms of the way we onboard data, and it’s enabled us to be a lot more granular with the data that we ingest into our SIEM.”
Greater scalability
With the reduction in data ingestion levels, the company is less likely to run into issues due to SIEM licencing limitations. By employing Cribl to help manage its data, the company hopes to benefit from greater scalability and agility in the future.
“Going forward, we’ll have scalability from a visibility and coverage perspective without being constrained by a SIEM licence.” This flexibility is just one of the wide-reaching benefits that the company has experienced since implementing Cribl, and one that’s made a major difference to its operations.
“Cribl gives you the flexibility to reduce data ingest, but also the flexibility to be agile and to move your data sources from one environment to another without much configuration. It’s given us the capability to be less rigid in our architecture; that’s been the biggest impact for us.”
Significant cost savings
Having cut data ingestion by 40% with Cribl Stream, the company is free to load more data feeds into its SIEM without the need to purchase additional licencing capacity. This has not only allowed the company to increase visibility across its digital environment, but also cut down on licencing costs.
“Now that we’ve got Cribl in our architecture, we have the ability to ingest more data feeds without having to buy additional licencing—that’s already saved us money. If we didn’t have Cribl, that additional cost would have been between £120,000 and £150,000 per year, on top of what we’re already paying today for our SIEM.”
As well as reducing spending on SIEM licencing, the company has been able to cut costs in other areas. “We’re completely in the cloud, so we’re charged for data that we retain for a longer period. Now that we have Cribl, we can send the data that we want to retain to a cheaper storage solution. And with Cribl Replay and Cribl Search, we still have the ability to easily search that data should we need it for audits or incident investigation. That gives us a cost benefit and more flexibility in the long run.”
Smarter resource utilisation
Cribl is also helping the company put its valuable resources to better use by cutting down on manual data management tasks.
Previously, its team had to configure multiple destinations when data was ingested. With Cribl, data from various locations can be ingested once and pointed to numerous locations around the business, eliminating the need for system and platform owners to configure multiple endpoints.
FTE effort to implement a data feed
“Normally, it would’ve taken us about two days of FTE effort to implement a data feed into Splunk or a similar destination. Since the introduction of Cribl, we’ve cut that down to half a day because now we only need to configure to send to Cribl and Cribl takes care of translating the data into the ideal format for other destinations.”
This reduction in time and labour adds up to additional cost savings too. Now, the company can send just the data that’s relevant to a particular end user, rather than shipping the entire data set. This has helped save money on licencing, infrastructure/compute, processing, and effort.
“Because we’re a cloud-native organisation, processing costs money—if we’re able to save on that, then we are definitely winning from a cost perspective.”