Cribl has announced an advancement in AI security with the debut of new features designed for enterprise telemetry. This initiative aims to leverage existing telemetry to enhance AI visibility, improve threat detection, and expedite security measures.
The company has introduced the AI Observability app to provide better management of token usage, expenses, model integration, and risks, amidst expanded detection features that highlight threats with high confidence, without the need to duplicate telemetry or modify existing infrastructure.
Challenges in AI Management
As AI technology rapidly transitions from experimentation to integral infrastructure, many organizations struggle to maintain oversight. Enterprises often lack crucial insights such as model utilization by teams and applications, token usage versus costs, peak demand times, and the ingress of sensitive data. Security teams, in particular, face challenges related to increasing telemetry and fragmented tools. Traditionally, the solution involves deploying more collectors, duplicating data, or resorting to closed platforms.
Strategic Platform Developments
Cribl has positioned its platform as a foundational element to support customer-facing applications that address critical enterprise security issues. “Security teams are telling us they don’t want to keep solving every new problem by sending the same data into more closed boxes,” stated Clint Sharp, co-founder and CEO of Cribl. He emphasized the need for visibility and improved detection capabilities across existing tools and environments, allowing organizations to avoid repetitive infrastructure rebuilding.
Comprehensive AI Oversight
Cribl's platform now includes capabilities to detect sensitive data exposure
The newly launched AI Observability app offers a consolidated view of AI activity across various organizational facets, utilizing existing telemetry data. This tool assists in comparing and analyzing usage, expenses, demand surges, and token consumption across models, applications, and departments. It also provides insights on workloads that could benefit from smaller, cost-effective models.
Cribl's platform now includes capabilities to detect sensitive data exposure and conduct thorough session analysis without data duplication or dependency on proprietary systems. Through the acquisition of CardinalOps, detection engineering capabilities have improved, incorporating AI-assisted workflows and the MITRE ATT&CK framework to identify and rectify gaps in security coverage, presenting a broader outlook than conventional SIEMs.
Stream-Native Detection
Cribl has integrated stream-native detections in Cribl Stream, enabling real-time identification of critical event-based conditions and a variety of security-relevant events. This feature is tailored for identifying known-bad indicators, policy breaches, and potential threats, allowing the immediate routing of critical data while minimizing data sent to premium analysis tiers. Advanced detections leverage historical data for detailed threat analytics and investigations, maintaining decision-making reliability.
According to Chris DePuy, co-founder and analyst at 650 Group, the Cribl platform allows for integration of AI Observability and SIEM solutions, treating them as applications on a diverse data infrastructure rather than isolated systems, illustrating the autonomy and significance of the AI Observability app.
Cribl, the AI Platform for Telemetry, announces new AI-era security capabilities that turn existing enterprise telemetry into AI visibility, stronger detections, and faster security action.
The new AI Observability app helps manage token usage, spend, model adoption, and risk across teams and applications. Expanded detection engineering improves coverage, while stream-native detections surface high-confidence threats earlier, without duplicating telemetry or rebuilding the infrastructure beneath every new tool.
More disconnected tools
AI adoption is moving from experimentation to infrastructure faster than enterprises can govern it. Many cannot answer basic questions about which teams and applications use which models, how token consumption maps to spend, when demand peaks, whether a smaller model could do the job, or where sensitive data is entering prompts. Security teams face a parallel problem: more telemetry, faster threats, and more disconnected tools. The market’s default answer remains another collector, another copy of the data, and another closed platform.
In contrast, Cribl’s new capabilities represent a pivotal expression of the company’s platform strategy, building on the AI Platform for Telemetry as a foundational infrastructure layer to offer real, customer-facing applications that solve urgent enterprise problems today.
Unified view of AI activity
“Security teams are telling us they don’t want to keep solving every new problem by sending the same data into more closed boxes,” said Clint Sharp, co-founder and CEO of Cribl. “They want visibility into enterprise AI usage and risk, stronger detections, and the flexibility to work across the tools and environments they already have. This is our new approach: keep the data open, run the security capabilities on top, and give teams a path forward without rebuilding the stack every time the market changes.”
Cribl’s new AI Observability app gives organizations a fast, unified view of AI activity across models, applications, departments, and environments. Using existing telemetry already flowing through Cribl or retained elsewhere, teams can compare usage and spend by model, app, department, or workload; see demand peaks; understand token consumption across applications; and identify workloads better served by a smaller, less expensive model.
Broader security environment
Teams can also detect sensitive data exposure in prompts and traces, analyze usage and cost, and investigate complete sessions over time. This is done without duplicating pipelines, paying to pull data back out of closed platforms, or locking themselves into another proprietary stack.
New detection engineering capabilities enable Cribl’s platform to more intelligently identify relevant events in telemetry data. Building on Cribl’s recent acquisition of CardinalOps, these capabilities map detections to the MITRE ATT&CK framework, expose coverage gaps, identify broken and noisy rules before they fail silently, and apply AI-assisted workflows so detection content can be maintained and improved over time instead of quietly drifting. That gives teams clearer visibility into what is covered, what is broken, and where to focus next across a broader security environment than any single SIEM can see on its own.
Security-relevant events
Cribl is bringing stream-native detections in Cribl Stream, enabling teams to identify high-confidence, event-based conditions and new classes of security-relevant events from normalised and enriched telemetry as it moves through the pipeline.
Designed for known-bad indicators, policy violations, canary events, and other atomic tripwires, these detections help teams alert, route, or fast-track critical data while reducing what is sent to premium analysis tiers. More complex detections continue to use full-fidelity history for stateful correlation, backtesting, threat hunting, and investigation. The result is speed where it matters, without sacrificing the context required for trustworthy decisions.
“With Cribl’s platform model, AI Observability and SIEM solutions are not separate walled gardens. They are applications that can sit on a variety of data stores running over Cribl’s telemetry infrastructure,” said Chris DePuy, co-founder and analyst at 650 Group. “The SIEM is one app among others rather than the centre of the architecture while the AI Observability app by itself is substantial enough to be its own company.”