Cribl integration configuration fields

  • Release version: Australia
  • Updated March 12, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Cribl integration configuration fields

    This guide explains the configuration fields required to set up a Cribl integration with ServiceNow Health Log Analytics (HLA). It covers essential parameters for connecting your ServiceNow instance to Cribl for streaming and pulling log data efficiently and securely.

    Show full answer Show less

    Integration Details

    • Integration Name: Assign a unique name to identify your Cribl integration. This is a required field and influences the display name on the form.
    • Service Instance: Select the ServiceNow service instance that will be bound to the incoming log data. This is mandatory.
    • MID Server name: Specify the MID Server that will receive the Cribl logs. This must be an active MID Server and is required.
    • Port: Choose an available port between 6000 and 6200 on the MID Server for log streaming. Ensure this port is not blocked by your security policies and is free from conflicts.
    • Description: Optionally add notes to clarify the purpose or details of the integration.
    • Transport: Read-only field showing the protocol used for pushing logs (TCP).
    • Source: Read-only field indicating the log source (Cribl) for pull integrations.

    Connection Setup

    • Cribl URL: Enter the URL of your Cribl instance (on-premises, cloud, or sandbox). This URL enables HLA to connect and make API calls.
    • Authentication method: Choose between token-based authentication (required for Cribl Cloud and supported for self-hosted) or basic authentication (preferred for self-hosted). Both use the credential alias CriblCredentialAlias. It is important to maintain only one active credential record per type under this alias.
    • Worker Group: Select the Cribl Worker Group from which logs will be streamed. The list is dynamically populated based on the Cribl URL and authentication method.
    • Cribl route: Pick the route directing logs to a specific destination. This is a required field and lists all routes configured in Cribl.
    • Cribl destination: Auto-populated, read-only field showing the destination within Cribl where logs are sent. It includes a direct link to the destination on the Cribl server.

    Practical Benefits for ServiceNow Customers

    By correctly configuring these fields, customers can establish a secure and efficient log data pipeline from Cribl to ServiceNow HLA, enabling enhanced log analytics and monitoring. The configuration ensures proper binding to ServiceNow services, secure authentication, and precise routing of logs, which supports streamlined troubleshooting, compliance, and operational visibility.

    Description of the fields on the Cribl integration configuration forms for Health Log Analytics.

    For the Cribl integration setup procedure, see Set up a Cribl integration for Health Log Analytics.

    Table 1. Provide details
    Field Description
    Integration Name Unique name of this integration. For example: My Cribl integration. This field is required.
    Note:
    When you fill in this field, the generic name displayed on the form adjusts automatically to match the name you entered.
    Service Instance The service instance (formerly the application service) to which to bind the log data. This field is required.
    MID Server name The MID Server to which the Cribl logs are streamed. This field is required.
    Port The port on the MID Server. This field is required.

    Choose a port within the range 6000-6200 from the array. The port must not be occupied by another process. Make sure that your organization’s security team opens the selected port on the MID Server.

    Description Option to add a brief description of the integration to help identify it.
    Transport (for push integrations) The protocol used for streaming log messages to your ServiceNow instance: TCP. This field is read-only.
    Source (for pull integrations) The source of the log data that the integration pulls to your ServiceNow instance: Cribl. This field is read-only.
    Table 2. Set up connection
    Field Description
    Cribl URL The URL of the Cribl instance. This field is required.

    HLA uses this URL to establish the connection with the Cribl instance and make the necessary API calls.

    For example:
    • On-Prem: https://my-cribl.company.com:9000
    • Cloud: https://myorg-12345abcde.cribl.cloud
    • Sandbox: https://sandbox-xyz789.sandbox.cribl.io
    Authentication method The authentication method used by the Cribl integration. This field is required.
    The Cribl integration supports:
    • Token-based authentication: Required for Cribl Cloud and also supported for self-hosted (On-Prem) Cribl instances.
    • Basic authentication: Preferred for self-hosted (On-Prem) Cribl instances.
    Both of these authentication methods use the default credential alias: Cribl_Credential_Alias.
    For information about setting up credentials for the authentication method used by the Cribl integration, see Set up Cribl integration authentication credentials.
    Important:
    Verify that only one active credential record of each credentials type exists under the credential alias.
    Worker Group The Cribl Worker Group from which to stream log data to the instance. This field is required.

    The drop-down list displays Worker Groups based on the provided Cribl cloud instance URL and authentication method.

    For example:
    • default
    • dev-workers
    • prod-workers
    • staging-workers
    Cribl route The Cribl route that directs log data to a specific destination.

    This field is auto-populated with a drop-down list of all available routes, each configured with a default destination. Select the desired route from the list. This field is required.

    For example:
    • default
    • demo-route
    Cribl destination The Cribl destination to which the log data is directed. This field is auto-populated and read-only.

    When HLA populates this field, it provides a link to the destination on the Cribl server.

    For example: sn_hla_cribl_tcp_json_abcdef