Cribl has announced a suite of new AI-driven security features designed to enhance enterprise telemetry, providing improved visibility, superior threat detection, and expedited security actions.
Their newly introduced AI Observability app facilitates the management of token usage, expenditure, model adoption, and risk across different teams and applications. Enhanced detection engineering now enables better threat coverage through stream-native detections, highlighting significant threats more swiftly without the need for redundant telemetry or infrastructure modifications.
Addressing tool disconnection challenges
The rapid integration of AI into infrastructure has outpaced enterprises' governance capabilities, creating challenges in identifying model usage, understanding token consumption, and managing data inputs.
This rapid adoption mirrors the security sector's struggle with increased telemetry and more fragmented tools. Historically, the industry responded by adding more collectors and closed platforms, but Cribl's latest capabilities aim to simplify this landscape through their platform strategy, leveraging existing AI Platform for Telemetry as a foundational layer for addressing current enterprise challenges.
A unified AI activity overview
Clint Sharp, Cribl's co-founder and CEO, highlighted the need for better visibility in AI usage and risk management across the existing toolsets.
According to Sharp, "They want visibility into enterprise AI usage and risk, stronger detections, and the flexibility to work across the tools and environments they already have." Cribl's AI Observability app provides a cohesive view of AI activity encompassing models, applications, and departments. This tool enables organisations to efficiently compare model usage, analyse token consumption, detect demand spikes, and assess whether smaller models could be more cost-effective.
Enhancing security detection
The app also allows teams to detect sensitive data exposure in application prompts and sessions
The app also allows teams to detect sensitive data exposure in application prompts and sessions, offering insights without duplicating data pipelines or being constrained by proprietary systems. Building on the CardinalOps acquisition, Cribl has implemented new detection engineering capabilities that align more closely with the MITRE ATT&CK framework. This integration exposes coverage gaps and optimizes detection rules through AI-assisted workflows, ensuring sustained relevance and accuracy over time in an expanded security landscape.
Cribl's stream-native detections, now a part of Cribl Stream, help teams identify critical, event-based conditions from normalized telemetry. By targeting policy violations, canary events, and other indicators, these detections allow teams to prioritise essential data while limiting the load sent to premium analysis tiers.
More sophisticated detections leverage a full history for comprehensive threat analysis and investigations, maintaining both speed and contextual accuracy. As noted by Chris DePuy of 650 Group, "With Cribl's platform model, AI Observability and SIEM solutions are not separate walled gardens. They are applications that can sit on a variety of data stores running over Cribl’s telemetry infrastructure."
Cribl, the AI Platform for Telemetry, announces new AI-era security capabilities that turn existing enterprise telemetry into AI visibility, stronger detections, and faster security action.
The new AI Observability app helps manage token usage, spend, model adoption, and risk across teams and applications. Expanded detection engineering improves coverage, while stream-native detections surface high-confidence threats earlier, without duplicating telemetry or rebuilding the infrastructure beneath every new tool.
More disconnected tools
AI adoption is moving from experimentation to infrastructure faster than enterprises can govern it. Many cannot answer basic questions about which teams and applications use which models, how token consumption maps to spend, when demand peaks, whether a smaller model could do the job, or where sensitive data is entering prompts. Security teams face a parallel problem: more telemetry, faster threats, and more disconnected tools. The market’s default answer remains another collector, another copy of the data, and another closed platform.
In contrast, Cribl’s new capabilities represent a pivotal expression of the company’s platform strategy, building on the AI Platform for Telemetry as a foundational infrastructure layer to offer real, customer-facing applications that solve urgent enterprise problems today.
Unified view of AI activity
“Security teams are telling us they don’t want to keep solving every new problem by sending the same data into more closed boxes,” said Clint Sharp, co-founder and CEO of Cribl. “They want visibility into enterprise AI usage and risk, stronger detections, and the flexibility to work across the tools and environments they already have. This is our new approach: keep the data open, run the security capabilities on top, and give teams a path forward without rebuilding the stack every time the market changes.”
Cribl’s new AI Observability app gives organisations a fast, unified view of AI activity across models, applications, departments, and environments. Using existing telemetry already flowing through Cribl or retained elsewhere, teams can compare usage and spend by model, app, department, or workload; see demand peaks; understand token consumption across applications; and identify workloads better served by a smaller, less expensive model.
Broader security environment
Teams can also detect sensitive data exposure in prompts and traces, analyse usage and cost, and investigate complete sessions over time. This is done without duplicating pipelines, paying to pull data back out of closed platforms, or locking themselves into another proprietary stack.
New detection engineering capabilities enable Cribl’s platform to more intelligently identify relevant events in telemetry data. Building on Cribl’s recent acquisition of CardinalOps, these capabilities map detections to the MITRE ATT&CK framework, expose coverage gaps, identify broken and noisy rules before they fail silently, and apply AI-assisted workflows so detection content can be maintained and improved over time instead of quietly drifting. That gives teams clearer visibility into what is covered, what is broken, and where to focus next across a broader security environment than any single SIEM can see on its own.
Security-relevant events
Cribl is bringing stream-native detections in Cribl Stream, enabling teams to identify high-confidence, event-based conditions and new classes of security-relevant events from normalised and enriched telemetry as it moves through the pipeline.
Designed for known-bad indicators, policy violations, canary events, and other atomic tripwires, these detections help teams alert, route, or fast-track critical data while reducing what is sent to premium analysis tiers. More complex detections continue to use full-fidelity history for stateful correlation, backtesting, threat hunting, and investigation. The result is speed where it matters, without sacrificing the context required for trustworthy decisions.
“With Cribl’s platform model, AI Observability and SIEM solutions are not separate walled gardens. They are applications that can sit on a variety of data stores running over Cribl’s telemetry infrastructure,” said Chris DePuy, co-founder and analyst at 650 Group. “The SIEM is one app among others rather than the centre of the architecture while the AI Observability app by itself is substantial enough to be its own company.”