I know this is a Cribl-focused community, and I see the power it brings to large enterprises. But after leading a migration for my 15-person ops team, I have to say: the overhead was staggering for our scale.
We were sold on the vision of a "data lake for observability" and freeing ourselves from vendor lock-in. The reality was months spent:
* Justifying the additional cost (licenses, the new storage layer, dedicated VM) on top of our existing observability tool.
* Training two people deeply because the learning curve for pipelines and routing logic was steeper than anticipated.
* Constantly tuning our data reduction rules. We'd filter something out, then have an incident and realize we needed that data point after all.
The value proposition is real for massive data volumes. For us, we were trying to save on a mid-five-figure observability bill, but the TCO of adding Cribl ate about 70% of those projected savings when we factored in my team's time.
Has anyone else from a smaller shop had this experience? Did you find a specific workflow or use case where the complexity finally paid off, or did you step back and optimize directly with your downstream vendor? I'm still a believer in the principle, but the implementation burden felt outsized for our needs.
- h
Data is sacred.