Cribl has announced functions for AI observability, detection engineering and detections directly in the data stream. Existing telemetry data is intended to be turned into visibility, improved detection rates and faster incident response without requiring additional closed platforms.
Cribl, a provider of a platform for processing telemetry data, has introduced new security features designed for the use of artificial intelligence. The extensions include an AI Observability app, improved capabilities in detection engineering and so-called stream-native detections. The aim is to convert existing telemetry data into insights and actionable options without companies having to build further isolated systems or replicate data.
The rapid spread of AI applications presents many organizations with challenges in governance. Basic questions often remain unanswered: Which teams and applications use which models? How does token consumption relate to costs? When do demand peaks occur? Could smaller models handle certain tasks? Where do sensitive data enter prompts? At the same time, volumes of telemetry data and the speed at which threats emerge are increasing. The response of many providers so far has been to introduce additional tools and data copies.
Cribl positions its new functions as part of a platform strategy based on a shared telemetry infrastructure. Clint Sharp, co-founder and CEO of Cribl, said: “Security teams tell us they no longer want to solve every new problem by sending the same data into yet more closed boxes. They want transparent insights into enterprise-wide AI usage and existing risks, better detection rates and the flexibility to work with the tools and environments they already have.”
The new AI Observability app is intended to provide an overview of AI activities across models, applications, departments and environments. Based on existing telemetry data, teams can evaluate usage and spending by model, application, department or workload. They can see demand peaks, track token consumption and identify workloads for which smaller models might suffice. Sensitive data in prompts and traces can also be detected, and complete sessions examined over time. Pipelines do not need to be duplicated and data does not need to be exported from closed systems.
In the area of detection engineering, Cribl draws on functions stemming from the acquisition of CardinalOps. The platform maps detections against the MITRE ATT&CK framework, identifies coverage gaps as well as faulty or overly noisy rules, and supports the continuous maintenance of detection content through AI-assisted workflows. Security teams thereby gain an overview of coverage levels and priorities in an environment that extends beyond the capabilities of a single SIEM solution.
In addition, Cribl is introducing detection mechanisms directly in the data stream. Teams can identify event-dependent conditions and security-relevant events from normalized and enriched telemetry data as it passes through the pipeline. The mechanisms target known malicious indicators, policy violations, canary events and similar triggers. Suspicious data can be alerted, forwarded or prioritized while the volume of data for later deeper analysis is reduced. More complex analyses continue to rely on historical data for correlations, backtesting, threat hunting and forensic investigations.
Chris DePuy, co-founder and analyst at 650 Group, commented: “With Cribl’s platform model, AI Observability and SIEM solutions are no longer areas separated by walls. They are applications that can sit on different data stores and run on Cribl’s telemetry infrastructure. SIEM thereby becomes one application among several and is no longer the center of the architecture.”
Further information is available from the company at cribl.io. Cribl was founded in 2018, employs a predominantly remote workforce and maintains an office in San Francisco. According to the company, the platform is used by organizations including half of the Fortune 100.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de