At a glance
| Feature | Derwent Labs | Cribl Stream |
|---|---|---|
| Normalisation approach | OCSF-native — all 200+ connectors output OCSF 1.7 automatically | Manual mapping per source; OCSF output configurable for select destinations |
| Output schema | OCSF 1.7 (every source, always) | Format-agnostic — passes source format through by default |
| Connector / source count | 200+ security sources | 80+ sources and destinations |
| SIEM migration | Dual-write to old and new SIEM in parallel — built-in | Multi-destination routing supported |
| Primary use case | Security normalisation and detection portability | General-purpose pipeline — security and IT observability |
| Deployment model | SaaS | SaaS (Cribl Cloud) or self-hosted |
| Pricing model | Contact for pricing | Per-GB processed — from $50,000 / year (500 GB/day, Cloud) |
Cribl pricing sourced from cribl.io/pricing/stream/ (July 2026). Derwent Labs connector count reflects current platform availability.
What each product does
Cribl Stream is a general-purpose data pipeline that collects, filters, routes, and transforms logs, metrics, and traces before they reach downstream storage or analysis platforms. It is used by security and IT teams to reduce data volumes, fan out to multiple destinations simultaneously, and apply field-level transformations at scale. Cribl Stream supports 80+ sources and destinations, including SIEMs, data lakes, and observability platforms such as Datadog and Grafana.
OCSF normalisation in Cribl is available for specific use cases — such as routing to Amazon Security Lake — and uses Cribl Copilot to suggest field mappings. Mapping is applied per source and requires pipeline configuration for each data type.
Derwent Labs is a security data pipeline purpose-built around OCSF. It connects to 200+ security sources — EDR, cloud, identity, network, and SIEM platforms — and normalises every event to OCSF 1.7 in the pipeline before it reaches any downstream tool. Normalisation is built into every connector: there is no mapping configuration required.
Because every source is in OCSF, detection rules written against the normalised data work on any SIEM or data lake without modification. Derwent Labs also supports dual-write SIEM migration — routing the same OCSF stream to an old and new SIEM simultaneously.
Where Cribl and Derwent Labs overlap
Both tools sit in front of a SIEM or data lake and reduce the volume and cost of data ingestion. Both can filter, enrich, and route telemetry to multiple destinations simultaneously — useful for SIEM migrations where you need old and new platforms running in parallel. Both support connectors to major cloud platforms, endpoint, and identity providers. And both are designed to be deployed without modifying existing data sources.
The overlap is most direct for security teams whose primary goal is SIEM cost reduction: a well-configured Cribl pipeline achieves similar ingestion savings to Derwent Labs. The divergence comes in how schema normalisation is handled — and what you can do with consistently normalised data downstream.
Where they diverge
OCSF: native vs configurable
Every Derwent Labs connector writes OCSF 1.7 output automatically — no pipeline configuration required. In Cribl Stream, OCSF output is available for specific destinations (such as Amazon Security Lake and AWS Security Hub) but requires building a mapping pipeline per source. Cribl Copilot can suggest field mappings, but each source still requires individual configuration.
Security-specific vs general-purpose
Derwent Labs is built exclusively for security telemetry: EDR, cloud, identity, network, and SIEM data. Cribl Stream covers a broader remit — security logs alongside IT observability data like application metrics, infrastructure logs, and traces routed to platforms such as Datadog or Grafana. If your pipeline spans both security and IT observability, that breadth matters.
Detection portability by default
Because Derwent Labs normalises to OCSF at ingest, every detection rule is written against a consistent schema — making rules portable across SIEMs without modification. In Cribl, detection portability depends on whether OCSF mapping has been applied; it is not automatic across all data paths.
When to choose each tool
How pricing compares
Cribl Stream uses a per-GB pricing model. Customers purchase an annual credit pool (1 credit = $1) that all Cribl products draw from. Published rates for Cribl Stream are $50,000 per year for up to 500 GB/day on Cloud Workers, and $84,000 per year for up to 1 TB/day. Hybrid Workers (self-hosted) are priced at approximately $0.26 credits per GB processed. Unused credits carry over up to a 20% cap. Source: cribl.io/pricing/stream.
Derwent Labs pricing is based on source count and data volume and is available on request. Contact us to get a quote matched to your environment.
FAQ
- Is Derwent Labs a Cribl alternative?
- It depends on your use case. For security-specific normalisation and OCSF-native detection portability, Derwent Labs is a direct alternative. For general-purpose IT observability pipelines that also handle security data, Cribl Stream covers a broader scope. The two tools overlap on SIEM cost reduction and multi-destination routing but differ significantly in how they handle schema normalisation.
- What’s the difference between Cribl and Derwent Labs?
- Cribl Stream is a general-purpose data pipeline that routes and transforms logs, metrics, and traces across both security and IT observability use cases. Derwent Labs is purpose-built for security: every connector automatically normalises to OCSF 1.7, so detection rules, dashboards, and queries work consistently across any downstream tool without custom mapping work.
- Does Derwent Labs support OCSF and Cribl doesn’t?
- Both tools support OCSF output, but in different ways. Derwent Labs is OCSF-native — every connector automatically writes OCSF 1.7 with no configuration. Cribl Stream supports OCSF output for specific destinations (Amazon Security Lake, AWS Security Hub) and offers AI-assisted mapping recommendations via Cribl Copilot, but mapping is still applied per source and requires pipeline configuration.
- Can I migrate from Cribl to Derwent Labs?
- Yes. Derwent Labs can be deployed alongside or in place of an existing Cribl pipeline. If you are migrating, the dual-write capability means you can route data through Derwent Labs to both your current SIEM and your new destination simultaneously, with OCSF normalisation applied to both streams. Contact us to discuss a migration path.
- How does Cribl pricing compare to Derwent Labs?
- Cribl Stream uses a per-GB pricing model. Published Cloud rates start from $50,000 per year for up to 500 GB/day ($84,000 for 1 TB/day). Hybrid Workers (self-hosted) are priced at approximately $0.26 per GB. Derwent Labs pricing is available on request — contact us for a quote based on your source count and data volume.
- Does Cribl support dual-write SIEM migration?
- Yes. Cribl Stream supports multi-destination routing, which can be used to send data to two SIEMs simultaneously during a migration. Derwent Labs also supports dual-write migration natively, with the addition that both streams are normalised to OCSF before delivery, so detections work consistently across old and new SIEM from day one.
- Which is better for security teams?
- For security-specific normalisation and OCSF-native detection portability, Derwent Labs is purpose-built for that use case. Cribl Stream is a better fit when your team also manages IT observability pipelines or needs general-purpose routing across non-security destinations. Both tools reduce SIEM ingestion costs effectively.