Cribl.Cloud vs. Self-Hosted (and Cloud-Connected Environments)

A straight comparison of the managed workspace and self-hosted deployments, plus the hybrid connected-environment option.

The decision in one table

A Cribl.Cloud deployment differs in several ways from a customer-managed (on-prem) deployment of Cribl Suite software on your own infrastructure, and the differences show up in the product's UI, in-app help, and documentation. The Cribl.Cloud vs. Self-Hosted page lists them; this table condenses that page's comparison points, with every cell traced to it.

Comparison pointSelf-hosted (on-prem)Cribl.Cloud
Cloud-only products Not available: Cribl Search, Cribl Lake, and Workspaces are cloud-only Cribl Search, Cribl Lake, and Workspaces are available
Distributed setup Configured by you Preconfigured as a Distributed deployment; Free or Standard plans allow only a single Worker Group
Git configuration You configure and secure the Git repository (Git Settings present) Local git client preconfigured; Cribl.Cloud does not support Git remote repos
Restarts You control restarts (Settings > Controls present) Cribl handles Leader and Worker Group restarts automatically, without an Enterprise plan
Authentication Customer configures authentication methods Local and SAML/OIDC IDP with Enterprise plans; Cribl.Cloud does not currently support LDAP
Data at rest Customer responsible for encryption and key management Encrypted at rest by using industry standard encryption (e.g., AES-256)
Data in motion Customer configures encryption (TLS) for data in transit Preconfigured TLS for some Sources; can be further configured
Patch management Customer responsible for applying security patches to Cribl Stream and underlying infrastructure Cribl manages patching of Cribl.Cloud (Cribl-managed) infrastructure
Threat detection & response Customer responsibility; Cribl Stream security features (limited) and external tools Cribl uses internal security teams and an external MSSP for threat detection, workload scanning, and vulnerability management
Compliance Customer responsible for adhering to compliance standards SOC 2 Type II compliant and GDPR-compliant (Cribl.Cloud)
Scripts Settings > Global > Scripts available (if enabled) Cribl.Cloud does not support configuring or running shell scripts
On-disk collectors Script Collector, File System Collector, Filesystem Destination, and File-based Destination staging directories available These features are available only on customer-managed hybrid Workers
Persistent queues Queue size limit freely defined, based on the disk space you provision Requires an Enterprise plan; on Cribl-managed Worker Groups each Source or Destination queue gets a maximum of 1 GB disk space per Worker Process
Ingress ports Your infrastructure defines them Sources and ports already enabled, plus 11 additional TCP ports (20000-20010); external port 443 maps internally to port 10443

Plan gating also shapes this table. Free and Standard Cribl.Cloud plans leave out the Git Settings and Controls links; an Enterprise plan adds at least two Workers that scale up as needed, hybrid Workers and Worker Groups, Key Management Service (KMS), and Local and Google SSO authentication. The docs point to the Cribl pricing page for the Free, Standard, and Enterprise feature comparison. The documentation lists no dollar prices, SLAs, or contract terms, so treat any such guidance from anyone (including us) as commercial territory to confirm with Cribl directly.

What a Cribl.Cloud deployment looks like

In a Cribl.Cloud deployment, Cribl assumes responsibility for hosting and managing your Cribl Stream infrastructure, per the About Cribl.Cloud page. Cribl.Cloud comes in both free and paid versions. A free Cribl.Cloud account allows up to 1 TB/day of data throughput (data ingress + egress), but does not have the option to have multiple Worker Groups.

Upgrading to a Cribl.Cloud Enterprise plan is what unlocks a hybrid deployment of any complexity. In hybrid deployments, the Leader resides in Cribl.Cloud, and manages Stream Workers and Edge Nodes regardless of their location. Your data processing configuration can consist of any combination of Workers and Edge Nodes: Cribl-managed, in private cloud instances that you manage, or in your data centers.

The page describes usage-based pricing: you pay only for what you use, the data you send to Cribl Stream and the data sent to external destinations, with data sent to your AWS S3 storage always free. From your Cribl.Cloud Organization, select Go Enterprise to submit an inquiry about upgrading your free account. Cribl.Cloud always runs in Distributed mode, as the table above reflected. For what an Enterprise plan adds, the docs point back to the Cribl pricing page.

What connected environments are

If you have one or more on-prem Cribl Stream environments and Cribl.Cloud Organization(s), you can configure Connected Environments, per the Learn About Connected Environments page:

The setup, per that page, starts by creating a connection between the on-prem Leader and the Cribl.Cloud Leader. You then use the Connections page in your Cribl.Cloud account to manage credit consumption for all of your on-prem environments from one interface. This feature is called Universal Subscription. Credits serve as the virtual transaction currency in the Cribl product suite; each Cribl product has a predefined usage rate, and as you use the products, credits are deducted from your initial pool.

One constraint: Connected Environments does not support proxied connections, so the connection between your on-prem Leader and Cribl.Cloud must not pass through a proxy. Alternatively, eligible Enterprise Organizations can reach the Cribl.Cloud Leader over AWS PrivateLink, keeping the connection on your cloud provider's private network. Leader Private Link is AWS only, and the connecting environment must be able to create an AWS VPC interface endpoint.

Before you connect, confirm these requirements from the page:

The connected-environment setup

The How to Connect On-Prem Leaders to Cribl.Cloud page is the full runbook. You can start the connection from the Cribl.Cloud account in Connections > Connected Environments, or from the on-prem Leader in Distributed Settings > Cloud Connection. If you run multiple environments, such as staging and production environments when using GitOps, you must connect each environment individually.

From the Cribl.Cloud side: select Products, then Cribl, then Workspace and Connections in the sidebar, and select Configure New Environment. You set an environment name, see the read-only workspace hostname, use port 4200, and get a workspace token. The page offers two script formats for the Leader you are connecting; the environment-variable form (token redacted):

CRIBL_DEPLOYMENT="On-prem Stream"
CRIBL_CLOUD_WORKSPACE_URL="tls://<your-token>@main-random-goat-a12bcdef.cribl.cloud:4200"

Set those variables when, or before, you run cribl start. How you set the variable depends on your deployment: for a container, set it in the run call or configuration; for your own server, set environment variables for the cribl user, or declare the variable along with the start command.

From the on-prem Leader side, select Settings, then the Global tab and Distributed Settings, select Cloud Connection, toggle Join Cribl.Cloud Workspace on, and fill in the Connection URL (from Workspace > Access in Cribl.Cloud), the Connection port (default 4200), and the Connection auth token copied from the Workspace token field on the Cribl.Cloud Connections page. Select Save, accept the Cribl Subscription Services Agreement in the modal, and select Yes to save changes and restart.

Two caveats the page carries. Once you connect an on-prem Leader to a Cribl.Cloud Organization, the license type changes to a Cribl.Cloud billing account and the Licensing page will not be accessible. To return, toggle Join Cribl.Cloud Workspace off and restart. And for a High Availability Leader, set the same variables on the primary Leader (via the Cribl.Cloud UI, the CLI, or directly in your environment); if the primary Leader runs as a systemd service, set them as Environment= entries in the [Service] section of the unit file. The failover Leader inherits the configuration from the filesystem changes made by the primary Leader.

How we usually help teams choose

Here is our own guidance, not Cribl's: teams that want Cribl Search or Cribl Lake and would rather not operate infrastructure tend toward Cribl.Cloud, especially when the workload fits a single Worker Group at first. Teams with data that must not leave their VPC, shell-script requirements, or multi-Worker-Group scale tend toward self-hosted. Connected Environments is the path we most often land on, because it keeps the Leader on-prem while adding cloud infrastructure management, credit-based billing, and access to Lake and Search. Where the docs are silent on pricing and plan limits beyond the 1 TB/day free tier, we run the plan economics with the team's actual ingest numbers, using Cribl's pricing page as the source of truth.

Frequently asked questions

Which Cribl products and features are available only on Cribl.Cloud?

Cribl Search, Cribl Lake, and Workspaces are the Cribl products and features the documentation lists as available only on Cribl.Cloud. The comparison table in this post lists the other differences between self-hosted and Cribl.Cloud deployments, such as Git, restarts, patching, and authentication.

What does the Cribl.Cloud free tier cover?

The free Cribl.Cloud account allows up to 1 TB/day of data throughput, counting both data ingress and egress together. It allows only a single Worker Group, and Cribl Stream always runs in Distributed mode in Cribl.Cloud.

Can I use Cribl.Cloud with an on-prem Cribl Stream deployment?

Yes, through Connected Environments, which connects an on-prem Leader to a Cribl.Cloud Leader so you keep infrastructure management, credit-based billing, Cribl Lake, and Cribl Search while your Leader stays on-prem. The connection is required to use TLS on port 4200, without a proxy, and an Enterprise Cribl.Cloud plan is required.

What are the requirements for connecting an on-prem Cribl Stream Leader to Cribl.Cloud?

Your Cribl.Cloud account must be on an Enterprise plan, the on-prem deployment must run Cribl Stream 4.8.2 or newer in Distributed mode (single-instance deployments are not supported), port 4200 must be open on the Leader over TCP, the connection must use TLS, and it cannot pass through a proxy.

Verified against Cribl Stream 4.20 documentation on October 3, 2026.

Ready to Reduce Your SIEM Costs?

Get a personalized demo and see how Cribl can save you 50-80% on data costs.

Schedule Free Demo