NEW200+ connectorsnow onboarded — pipe any security source into OCSF effortlessly.Read the announcement
Consulting
About us
Book a demoStart now
Compare · Security pipelines

Derwent Labs vs Cribl Stream

Cribl Stream and Derwent Labs are both security data pipeline tools that sit between sources and destinations like SIEMs or data lakes. The core distinction: Derwent Labs is OCSF-native — every connector automatically normalises to a common schema, making detection rules portable across SIEMs. Cribl Stream is a broader, general-purpose pipeline used across security and IT observability use cases, with OCSF output configurable for specific destinations.

Book a demo View integrations
Side by side

At a glance

FeatureDerwent LabsCribl Stream
Normalisation approachOCSF-native — all 200+ connectors output OCSF 1.7 automaticallyManual mapping per source; OCSF output configurable for select destinations
Output schemaOCSF 1.7 (every source, always)Format-agnostic — passes source format through by default
Connector / source count200+ security sources80+ sources and destinations
SIEM migrationDual-write to old and new SIEM in parallel — built-inMulti-destination routing supported
Primary use caseSecurity normalisation and detection portabilityGeneral-purpose pipeline — security and IT observability
Deployment modelSaaSSaaS (Cribl Cloud) or self-hosted
Pricing modelContact for pricingPer-GB processed — from $50,000 / year (500 GB/day, Cloud)

Cribl pricing sourced from cribl.io/pricing/stream/ (July 2026). Derwent Labs connector count reflects current platform availability.

The tools

What each product does

Cribl Stream

Cribl Stream is a general-purpose data pipeline that collects, filters, routes, and transforms logs, metrics, and traces before they reach downstream storage or analysis platforms. It is used by security and IT teams to reduce data volumes, fan out to multiple destinations simultaneously, and apply field-level transformations at scale. Cribl Stream supports 80+ sources and destinations, including SIEMs, data lakes, and observability platforms such as Datadog and Grafana.

OCSF normalisation in Cribl is available for specific use cases — such as routing to Amazon Security Lake — and uses Cribl Copilot to suggest field mappings. Mapping is applied per source and requires pipeline configuration for each data type.

Derwent Labs

Derwent Labs is a security data pipeline purpose-built around OCSF. It connects to 200+ security sources — EDR, cloud, identity, network, and SIEM platforms — and normalises every event to OCSF 1.7 in the pipeline before it reaches any downstream tool. Normalisation is built into every connector: there is no mapping configuration required.

Because every source is in OCSF, detection rules written against the normalised data work on any SIEM or data lake without modification. Derwent Labs also supports dual-write SIEM migration — routing the same OCSF stream to an old and new SIEM simultaneously.

Common ground

Where Cribl and Derwent Labs overlap

Both tools sit in front of a SIEM or data lake and reduce the volume and cost of data ingestion. Both can filter, enrich, and route telemetry to multiple destinations simultaneously — useful for SIEM migrations where you need old and new platforms running in parallel. Both support connectors to major cloud platforms, endpoint, and identity providers. And both are designed to be deployed without modifying existing data sources.

The overlap is most direct for security teams whose primary goal is SIEM cost reduction: a well-configured Cribl pipeline achieves similar ingestion savings to Derwent Labs. The divergence comes in how schema normalisation is handled — and what you can do with consistently normalised data downstream.

Key differences

Where they diverge

OCSF: native vs configurable

Every Derwent Labs connector writes OCSF 1.7 output automatically — no pipeline configuration required. In Cribl Stream, OCSF output is available for specific destinations (such as Amazon Security Lake and AWS Security Hub) but requires building a mapping pipeline per source. Cribl Copilot can suggest field mappings, but each source still requires individual configuration.

Security-specific vs general-purpose

Derwent Labs is built exclusively for security telemetry: EDR, cloud, identity, network, and SIEM data. Cribl Stream covers a broader remit — security logs alongside IT observability data like application metrics, infrastructure logs, and traces routed to platforms such as Datadog or Grafana. If your pipeline spans both security and IT observability, that breadth matters.

Detection portability by default

Because Derwent Labs normalises to OCSF at ingest, every detection rule is written against a consistent schema — making rules portable across SIEMs without modification. In Cribl, detection portability depends on whether OCSF mapping has been applied; it is not automatic across all data paths.

Decision guide

When to choose each tool

Choose Cribl Stream when…
You need a single pipeline for both security logs and IT observability (metrics, traces, application logs).
You have existing Cribl Stream deployments and want to extend coverage rather than replace the pipeline layer.
You need self-hosted deployment with full control over processing infrastructure.
Your destinations include non-SIEM observability platforms like Datadog, Grafana, or Splunk Observability.
Choose Derwent Labs when…
Security normalisation is your primary goal and you want OCSF output across all sources without manual mapping work.
You are migrating between SIEMs and need dual-write support with consistent schema across both destinations.
You need detection rules to be portable across SIEMs — write once, run anywhere.
You want 200+ pre-built security source connectors with zero parser maintenance.
Pricing

How pricing compares

Cribl Stream uses a per-GB pricing model. Customers purchase an annual credit pool (1 credit = $1) that all Cribl products draw from. Published rates for Cribl Stream are $50,000 per year for up to 500 GB/day on Cloud Workers, and $84,000 per year for up to 1 TB/day. Hybrid Workers (self-hosted) are priced at approximately $0.26 credits per GB processed. Unused credits carry over up to a 20% cap. Source: cribl.io/pricing/stream.

Derwent Labs pricing is based on source count and data volume and is available on request. Contact us to get a quote matched to your environment.

Get a Derwent Labs quote
Derwent Labs

OCSF-native,
from the ground up.

Every Derwent Labs connector outputs OCSF 1.7 — not as a configurable option for specific destinations, but as the only output. Your SIEM, your data lake, and your detection engine all see the same schema from day one. No parser maintenance. No per-source mapping work.

200+ connectors, one output schema
Every source — CrowdStrike, Okta, AWS CloudTrail, Zscaler, and 196+ more — writes OCSF 1.7. Connect a source and get normalised data immediately.
Detection portability across SIEMs
Write a detection rule once against OCSF data. Run it on Splunk today, Chronicle tomorrow — the schema is the same on both sides.
SIEM migration without rewriting
Dual-write routes the same OCSF stream to your old and new SIEM simultaneously. Migrate at your own pace — nothing breaks in either direction.
Common questions

FAQ

Is Derwent Labs a Cribl alternative?
It depends on your use case. For security-specific normalisation and OCSF-native detection portability, Derwent Labs is a direct alternative. For general-purpose IT observability pipelines that also handle security data, Cribl Stream covers a broader scope. The two tools overlap on SIEM cost reduction and multi-destination routing but differ significantly in how they handle schema normalisation.
What’s the difference between Cribl and Derwent Labs?
Cribl Stream is a general-purpose data pipeline that routes and transforms logs, metrics, and traces across both security and IT observability use cases. Derwent Labs is purpose-built for security: every connector automatically normalises to OCSF 1.7, so detection rules, dashboards, and queries work consistently across any downstream tool without custom mapping work.
Does Derwent Labs support OCSF and Cribl doesn’t?
Both tools support OCSF output, but in different ways. Derwent Labs is OCSF-native — every connector automatically writes OCSF 1.7 with no configuration. Cribl Stream supports OCSF output for specific destinations (Amazon Security Lake, AWS Security Hub) and offers AI-assisted mapping recommendations via Cribl Copilot, but mapping is still applied per source and requires pipeline configuration.
Can I migrate from Cribl to Derwent Labs?
Yes. Derwent Labs can be deployed alongside or in place of an existing Cribl pipeline. If you are migrating, the dual-write capability means you can route data through Derwent Labs to both your current SIEM and your new destination simultaneously, with OCSF normalisation applied to both streams. Contact us to discuss a migration path.
How does Cribl pricing compare to Derwent Labs?
Cribl Stream uses a per-GB pricing model. Published Cloud rates start from $50,000 per year for up to 500 GB/day ($84,000 for 1 TB/day). Hybrid Workers (self-hosted) are priced at approximately $0.26 per GB. Derwent Labs pricing is available on request — contact us for a quote based on your source count and data volume.
Does Cribl support dual-write SIEM migration?
Yes. Cribl Stream supports multi-destination routing, which can be used to send data to two SIEMs simultaneously during a migration. Derwent Labs also supports dual-write migration natively, with the addition that both streams are normalised to OCSF before delivery, so detections work consistently across old and new SIEM from day one.
Which is better for security teams?
For security-specific normalisation and OCSF-native detection portability, Derwent Labs is purpose-built for that use case. Cribl Stream is a better fit when your team also manages IT observability pipelines or needs general-purpose routing across non-security destinations. Both tools reduce SIEM ingestion costs effectively.
The backbone for security telemetry

One schema.
Every tool.

Normalise every byte of your security telemetry to OCSF. Stop maintaining parsers. Stop rewriting detections. Start shipping signal.