Send the downpipes audit trail to Cribl
Cribl takes the downpipes audit trail in either direction, so you pick the one that suits your pipeline. For a push, you create a Cribl HEC Source and point the console push at it. For a pull, a Cribl REST Collector polls the audit feed instead. Whichever you pick, Cribl then routes and reshapes each event for whatever sits downstream, which makes it a tidy way to fan the audit trail out to more than one destination.
This page leads with the push path, which is the simpler default: the engine dials out to the Cribl HEC Source on the scheduler tick, so a Cloudflare Access perimeter on your console hostname never blocks it, and there is no exemption to add.
What you need
- A Cribl Stream or Edge instance where you can add a Source, and a Splunk HEC Source with a token for the push path.
- Owner access to the downpipes console, and network reachability from your engine to the Cribl HEC URL.
Set it up
- In Cribl, create a Source of type Splunk HEC. Note the URL it exposes and a HEC token it will accept.
- In the downpipes console, open Integrations, and set up the SIEM audit push. Note where: the Cribl tile opens the pull credential, not the push config, because pulling is the direction Cribl is catalogued for. The audit push is a single destination for the estate and is edited from any push tile, so use Custom endpoint, or the Splunk tile, since a Cribl HEC Source speaks Splunk HEC. Either is owner-only and asks for a fresh step-up sign-in.
- On Custom endpoint, set Delivery to HTTP endpoint and Format to Splunk HEC. The Splunk tile fixes both to that same pair already, with no picker to set either. Paste the Cribl HEC URL into Endpoint URL.
- For the auth secret, paste
Splunk <token>: the literal wordSplunk, one space, then your token. The HEC Source treats thatSplunkprefix as part of the scheme, so the bare token does not authenticate. - Still on Custom endpoint (or Splunk, whichever you opened at step 2), leave Enabled ticked to start draining on the next tick after you save, or clear it to test before any real event leaves. Choose Configure to save. If a second owner must approve a save or an enable, nothing changes until they approve it.
- On the tile you opened at step 2, choose Test send. From console 0.2.7, a push saved from Custom endpoint stays on that tile. The engine posts one synthetic audit-shaped event and reports Cribl’s response. A test send works whether the destination is enabled or not, and never advances the delivery cursor. If you cleared it, choose Enable now, and from the next tick the engine forwards every audit event above the cursor.
The push is one destination: set it up from the Splunk tile and the console tags it splunk, so it shows there only. From console 0.2.7, set it up from Custom endpoint and the console tags it custom-endpoint, so it shows under Custom endpoint only. An earlier console wrote no tag from Custom endpoint, and the console matches such a push by the splunk-hec over http pair. That pair shows the push under the Splunk tile and the CrowdStrike Falcon Next-Gen SIEM tile, and not under Custom endpoint. Either way nothing is misrouted, the events go to the Cribl Source you pointed them at, and only the tile the console shows the configuration under can differ. Custom endpoint explains that tile-ownership rule in full.
To pull instead, which is the direction the Cribl tile does cover, add a Cribl REST Collector (or a Collector job) that polls https://<your-console-host>/support/audit-feed with an audit-feed credential as a Bearer token, paging by afterSeq. The mint, the Cloudflare Access exemption and the continuity checks are on Wiring the audit feed into your SIEM.
What lands in Cribl
On the push path each event arrives as an HEC event object, with time as epoch seconds, source set to downpipes, sourcetype set to downpipe:audit, and the audit event under event:
{"time":1750299248,"source":"downpipes","sourcetype":"downpipe:audit","event":{"seq":4097,"action":"restore-approve","outcome":"success","actorEmail":"ops@acme.example","...":"..."}}
Cribl parses the HEC object on arrival, so you can route, redact further or reshape from those fields before anything downstream sees them.
Good to know
- Delivery is at-least-once, not exactly-once. Every event carries a stable
seqand ahash; index or dedup on either and a re-sent event lands as a duplicate you can drop rather than a second incident. The feed carries operator identity (member emails, source IPs, roles and approver emails) and no backup data or secret values, so apply your Cribl data-handling rules to it as you would any access log. - The push needs no Access exemption; the pull needs one when Access fronts your hostname. For both the push mechanics and the pull feed, see Forwarding the audit log to your SIEM.
Last updated .