How Cribl Detect Pipelines Can Mask Log Identifiers with LogTotal Sanitizer

Cribl Detect, a SIEM built on Cribl's data platform, was released on September 29, 2026. Because its stored and searchable data flows through Cribl Stream Routes and Pipelines, adding sanitization there controls what analysts, AI-assisted triage, alerts, and retained datasets can see. The LogTotal Sanitizer Pack is presented as a way to pseudonymize log data in that pipeline.
Cribl Detect became available on September 29, 2026, and operates as a SIEM on Cribl’s data platform. Because its stored and searchable records pass through Cribl Stream Routes and Pipelines, sanitization placed there shapes what downstream users and systems can view.
The LogTotal Sanitizer Pack is an open-source Cribl Pack, unaffiliated with Cribl or SOC Prime, that uses SOC Prime’s LogTotal sanitization engine. It recognizes eleven sensitive-value categories and substitutes keyed HMAC tokens with type labels. Deterministic tokens preserve correlation across events while removing credentials, payment data, health data, and personal identifiers before storage.
If adopted, organizations running Cribl Detect may reduce exposure of sensitive log content to analysts, AI triage, alerts, and retained datasets. This could lower breach impact and compliance scope, while deterministic tokens may help defenders keep correlating activity. However, pseudonymization may also affect incident response, audit, or legal review if original values are needed. Privacy benefits and operational tradeoffs may vary by sector and jurisdiction.