Simulating a phased observability migration with Cribl Stream, Splunk, and Elastic

DEMO ENVIRONMENT · REFERENCE ARCHITECTURE
OPEN SOURCE | See the full project on github

A reproducible Podman lab showing how Cribl Stream can route, transform, protect, and validate telemetry during a Splunk-to-Elastic migration.

This demo environment deploys Splunk Enterprise, Elasticsearch, Kibana, Cribl Stream, and Nginx in a containerized demonstration environment that provides local DNS names and an reverse proxy for security and simplicity.

The scenario models a realistic phased migration: both platforms remain active while teams validate Elastic, reduce data volume, redact PII, enrich events, and prepare for cutover.

Why it matters

Observability migrations are rarely clean, immediate replacements. This lab turns those operational constraints into a live demonstration of dual routing, in-flight transformation, and side-by-side validation.

What you’ll learn

  • Single browser entry point

  • Only port 7770 is published

  • Hostname-based routing

  • Isolated services via podman networking

  • Preconfigured components support fast, repeatable demo deployment.

What this work demonstrates

A presenter-ready technical asset combining reproducible infrastructure, a realistic customer scenario, architecture documentation, operational guidance, and a structured demo flow.

Previous
Previous

Instructional Blog: DNS Failover for data stream uptime with Cribl Cloud

Next
Next

Agent: Indicator of Compromise reporting