Skip to content
Notifications
Clear all

Just saw a demo of Cribl's new ML features. Looks gimmicky. Anyone using it?

5 Posts
5 Users
0 Reactions
1 Views
(@jessicam)
Trusted Member
Joined: 1 week ago
Posts: 51
Topic starter   [#11990]

Just watched a vendor demo of Cribl's new machine learning stuff. They were showing "anomaly detection" and "log pattern clustering." It looked slick, but honestly, it felt like a feature they added just to check an AI/ML box.

Does anyone here actually use these features in production? I'm curious about real-world use. Like, are you getting actual actionable alerts from it, or is it just more noise? We're a Salesforce shop and use Splunk, so I'm trying to picture where this fits without adding complexity.



   
Quote
(@crm_hopper_2024)
Reputable Member
Joined: 4 months ago
Posts: 121
 

You're right to be skeptical. Saw a similar demo and kept asking "so what?" Anomaly detection is only useful if it's tuned to *your* normal, not some generic baseline. Otherwise it's just expensive noise.

If you're already in Splunk, you're probably paying for similar capabilities there. Adding another ML layer feels like stacking two toasters to make better toast.


CRM is a means, not an end.


   
ReplyQuote
(@devops_dad)
Estimable Member
Joined: 5 months ago
Posts: 131
 

Spot on about the "expensive noise." I remember setting up an early ML anomaly detector for our web app logs a few years ago, and the thing fired alerts for our scheduled cron jobs because they weren't "normal" traffic patterns. Tuned out one thing, it'd freak out about something else.

That said, the "stacking two toasters" analogy is perfect, but sometimes you need a waffle maker instead of more toast. If Cribl sits upstream and can tag or enrich data before it hits Splunk, you might reduce the volume of what you're even analyzing. But that's a pipe dream if it's not dialed in.


it worked on my machine


   
ReplyQuote
(@budget_minded_buyer)
Estimable Member
Joined: 3 months ago
Posts: 94
 

Check the licensing. Our sales rep slipped in that the "ML processing units" are billed separately from the standard data routing capacity.

So you're not just adding complexity, you're adding a whole new cost tier on top of your existing Splunk ingest. If the alerts are mostly noise, you're paying a premium to generate them.


always ask for a multi-year discount


   
ReplyQuote
(@aarons)
Estimable Member
Joined: 1 week ago
Posts: 80
 

That licensing split is exactly the model you need to watch for. It's not just a new cost tier, it's a variable one. If the feature runs on "ML processing units," your bill is tied directly to how much you experiment with it.

This makes tuning it prohibitively expensive. You can't afford the trial and error needed to reduce false positives, which is why you end up with "expensive noise."

You're then faced with a choice: pay for the noise or disable the feature, making the whole exercise a waste.


Your cloud bill is 30% too high


   
ReplyQuote