Docs
DocumentationQuery ReferenceAPI Reference
Open Console→→
DocumentationQuery ReferenceAPI Reference

Platform overview

What is Axiom?QuickstartArchitectureFeatures
Fundamentals
Datasets
Edge deployments
Limits
Performance
Optimize usage
Requirements
Semantic conventions
Glossary
Tour
SecurityRoadmap

Send data

Reference architecturesMethods

Understand data

Console
Query
Builder
Editor
Query results
Visualize
Traces
Metrics
Correlations
Save queries
Stream
Dashboard
Create
Elements
Create
Configure
Element types
Gauge
Heatmap
Log stream
Monitor list
Note
Pie chart
Scatter plot
Statistic
Table
Time series
Sections
Configure
Filter
Annotate
Monitor
Overview
View status
Configure
Examples
Monitor types
Anomaly
Match
Threshold
Alerting
Overview
Configure
Notifier types
Custom Webhook
Discord
Email
Microsoft Teams
Opsgenie
PagerDuty
Slack
Manage
Datasets
Overview
Views
Virtual fields
Access
RBAC
Tokens
CLI
Organization
Audit log
Settings
Usage and billing
Profile
Extend
Overview
AWS Lambda
AWS PrivateLink
Cloudflare Workers
Cloudflare Logpush
Convex
Grafana
Hex
Netlify
Supabase
Tailscale
Terraform
Vercel
Intelligence
Overview
Spotlight
AI agents
Overview
MCP Server
Query cost limits
Agent-created orgs
Skills
Overview
Axiom alerting
Build dashboards
Control costs
Query metrics
SRE
Translate SPL to APL
Splunk
Overview
Splunk app
Install and configure
Commands
Examples
Portal
How it works
Set up standard mode
Set up transparent mode
Observability Cloud
SPL command support
Examples
Monitor and troubleshoot

Use cases

ObservabilityProduct analytics
LLM observability
Overview
Use Axiom AI SDK
Manual instrumentation
GenAI attributes
Redaction policies

Miscellaneous

LLMs
Overview
List of docs pages
Full docs
Query reference
FAQs
Legal
Acceptable use policy
Cookies
Data processing
HIPAA
Partner agreement
Partner program guide
Privacy policy
SLA
Terms of service
Terms of use

Send data from Cribl to Axiom

Learn how to configure Cribl LogStream to forward logs to Axiom using both HTTP and Syslog destinations.

Cribl is a data processing framework often used with machine data. It allows you to parse, reduce, transform, and route data to and from various systems in your infrastructure.

You can send logs from Cribl LogStream to Axiom using HTTP or Syslog destination.

Prerequisites

  • Create an Axiom account.
  • Create a dataset in Axiom where you send your data.
  • Create an API token in Axiom with permissions to ingest data to the dataset you have created.

Set up log forwarding from Cribl to Axiom using the HTTP destination

Below are the steps to set up and send logs from Cribl to Axiom using the HTTP destination:

  1. Create a new HTTP destination in Cribl LogStream:

Open Cribl’s UI and navigate to Destinations > HTTP. Click on + Add New to create a new destination.

Cribl LogStream
└Cribl LogStream
  1. Configure the destination:
  • Name: Choose a name for the destination.

  • Endpoint URL: The URL of your Axiom log ingest endpoint https://AXIOM_DOMAIN/v1/ingest/DATASET_NAME.

    Info

    Replace AXIOM_DOMAIN with the base domain of your edge deployment. For more information, see Edge deployments.

    Replace DATASET_NAME with the name of the Axiom dataset where you send your data.

  • Method: Choose POST.

  • Event Breaker: Set this to One Event Per Request or CRLF (Carriage Return Line Feed), depending on how you want to separate events.

Cribl LogStream destination
└Cribl LogStream destination
  1. Headers:

You may need to add some headers. Here is a common example:

  • Content-Type: Set this to application/json.

  • Authorization: Set this to Bearer API_TOKEN.

    Info

    Replace API_TOKEN with the Axiom API token you have generated. For added security, store the API token in an environment variable.

Cribl LogStream destination headers
└Cribl LogStream destination headers
  1. Body:

In the Body Template, input {{_raw}}. This forwards the raw log event to Axiom.

  1. Save and enable the destination:

After you’ve finished configuring the destination, save your changes and make sure the destination is enabled.

Set up log forwarding from Cribl to Axiom using the Syslog destination

Create Syslog endpoint

  1. Click Settings > Endpoints.
  2. Click New endpoint.
  3. Click Syslog.
  4. Name the endpoint.
  5. Select the dataset where you want to send data.
  6. Copy the URL displayed for the newly created endpoint. This is the target URL where you send the data.

Configure destination in Cribl

  1. Create a new Syslog destination in Cribl LogStream:

Open Cribl’s UI and navigate to Destinations > Syslog. Click on + Add New to create a new destination.

  1. Configure the destination:
  • Name: Choose a name and output ID for the destination.

  • Protocol: Choose the protocol for the Syslog messages. Select the TCP protocol.

  • Destination Address: Input the address of the Axiom endpoint to which you want to send logs. This address is generated from your Syslog endpoint in Axiom and follows this format: tcp+tls://qsfgsfhjsfkbx9.syslog.axiom.co:6514.

  • Destination Port: Enter the port number on which the Axiom endpoint is listening for Syslog messages which is 6514

  • Format: Choose the Syslog message format. RFC3164 is a common format and is generally recommended.

  • Facility: Choose the facility code to use in the Syslog messages. The facility code represents the type of process that’s generating the Syslog messages.

  • Severity: Choose the severity level to use in the Syslog messages. The severity level represents the importance of the Syslog messages.

Cribl LogStream destination configuration
└Cribl LogStream destination configuration
  1. Configure the Message:
  • Timestamp Format: Choose the timestamp format to use in the Syslog messages.

  • Application Name Field: Enter the name of the field to use as the app name in the Syslog messages.

  • Message Field: Enter the name of the field to use as the message in the Syslog messages. Typically, this would be _raw.

  • Throttling: Enter the throttling value. Throttling is a mechanism to control the data flow rate from the source (Cribl) to the destination (in this case, an Axiom Syslog Endpoint).

Configure the Syslog message
└Configure the Syslog message
  1. Save and enable the destination

After you’ve finished configuring the destination, save your changes and make sure the destination is enabled.

Was this page helpful?
Suggest edits on GitHub
On this page
Set up log forwarding from Cribl to Axiom using the HTTP destinationSet up log forwarding from Cribl to Axiom using the Syslog destinationCreate Syslog endpointConfigure destination in Cribl