Cribl Expands AI Observability and Security Operations

0
Cribl has announced new AI-focused security capabilities that transform existing enterprise telemetry into actionable AI visibility, stronger threat detection, and faster security response. The release introduces an AI Observability app that helps organizations monitor AI token usage, spending, model adoption, and risk across teams and applications. Expanded detection engineering and stream-native detections further improve threat coverage while enabling earlier identification of high-confidence threats without duplicating telemetry or rearchitecting existing infrastructure.

AI adoption is moving from experimentation to infrastructure faster than enterprises can govern it. Many cannot answer basic questions about which teams and applications use which models, how token consumption maps to spend, when demand peaks, whether a smaller model could do the job, or where sensitive data is entering prompts. Security teams face a parallel problem: more telemetry, faster threats, and more disconnected tools. The market’s default answer remains another collector, another copy of the data, and another closed platform.

In contrast, Cribl’s new capabilities represent a pivotal expression of the company’s platform strategy, building on the AI Platform for Telemetry as a foundational infrastructure layer to offer real, customer-facing applications that solve urgent enterprise problems today.

“Security teams are telling us they don’t want to keep solving every new problem by sending  the same data into more closed boxes,” said Clint Sharp, co-founder and CEO of Cribl. “They want visibility into enterprise AI usage and risk, stronger detections, and the flexibility to work across the tools and environments they already have. This is our new approach: keep the data open, run the security capabilities on top, and give teams a path forward without rebuilding the stack every time the market changes.”

Understand AI usage, cost, and risk across the enterprise

Cribl’s new AI Observability app gives organizations a fast, unified view of AI activity across models, applications, departments, and environments. Using existing telemetry already flowing through Cribl or retained elsewhere, teams can compare usage and spend by model, app, department, or workload; see demand peaks; understand token consumption across applications; and identify workloads better served by a smaller, less expensive model. Teams can also detect sensitive data exposure in prompts and traces, analyze usage and cost, and investigate complete sessions over time. This is done without duplicating pipelines, paying to pull data back out of closed platforms, or locking themselves into another proprietary stack.

Continuously improve detection engineering across environments 

New detection engineering capabilities enable Cribl’s platform to more intelligently identify relevant events in telemetry data. Building on Cribl’s recent acquisition of CardinalOps, these capabilities map detections to the MITRE ATT&CK framework, expose coverage gaps, identify broken and noisy rules before they fail silently, and apply AI-assisted workflows so detection content can be maintained and improved over time instead of quietly drifting. That gives teams clearer visibility into what is covered, what is broken, and where to focus next across a broader security environment than any single SIEM can see on its own.

Generate high-confidence security signals in motion

Cribl is bringing stream-native detections in Cribl Stream, enabling teams to identify high-confidence, event-based conditions and new classes of security-relevant events from normalized and enriched telemetry as it moves through the pipeline. Designed for known-bad indicators, policy violations, canary events, and other atomic tripwires, these detections help teams alert, route, or fast-track critical data while reducing what is sent to premium analysis tiers. More complex detections continue to use full-fidelity history for stateful correlation, backtesting, threat hunting, and investigation. The result is speed where it matters, without sacrificing the context required for trustworthy decisions.

“With Cribl’s platform model, AI Observability and SIEM solutions are not separate walled gardens. They are applications that can sit on a variety of data stores running over Cribl’s telemetry infrastructure,” said Chris DePuy, co-founder and analyst at 650 Group. “The SIEM is one app among others rather than the center of the architecture while the AI Observability app by itself is substantial enough to be its own company.”

To learn more, visit cribl.io

Related News:

Revenium Launches Guardrails for Real-Time AI Governance

Zero Networks Launches Least Agency Enforcement

Share.

About Author

Leigh Porter's first love is to love people. Beginning her career as a neonatal RN was an obvious choice until life threw the curve ball to embark on a new IT endeavor. Pursuing this fresh career was a piece of cake with her resilient and steadfast character. Outside of the office, Leigh also diligently gives much of her time faithfully as a nationally awarded volunteer leader to a very dear to her heart organization.