Cribl adds AI observability and stream-native detections

Cribl has launched AI Observability and stream-native detection capabilities, letting enterprises govern AI usage and surface threats without duplicating telemetry

A brightly lit, modern network lab features a central server rack labeled "NETWORK SIMULATOR" connected by numerous colorful cables to two curved desks, each with three monitors displaying network data, a keyboard, mouse, and a measurement

Cribl has announced a set of AI-era security capabilities for its telemetry platform, targeting two urgent enterprise pain points: insufficient visibility into internal AI usage and the rising complexity of threat detection across fragmented tool stacks. The additions span a new AI Observability app, expanded detection engineering built on its recent CardinalOps acquisition, and stream-native detections running inline within Cribl Stream.

The company positions the release as a platform strategy milestone rather than a standalone product launch. Rather than requiring customers to ingest data into yet another closed system, the capabilities operate over telemetry already flowing through or retained alongside Cribl's existing infrastructure.

What is new

The AI Observability app gives security and IT teams a unified view of AI activity across models, applications, departments and environments. It surfaces token consumption, spend by workload, demand peaks and sensitive-data exposure within prompts and traces. Importantly, the company says it does not require customers to duplicate pipelines or pay to extract data from proprietary platforms to populate the view.

Detection engineering has been expanded using capabilities brought in through Cribl's acquisition of CardinalOps. The integrated tooling maps detection content to the MITRE ATT&CK framework, identifies coverage gaps, and flags broken or noisy rules before they degrade silently. AI-assisted workflows allow detection content to be maintained continuously rather than decaying between manual review cycles.

Stream-native detections, now available in Cribl Stream, allow teams to act on high-confidence, event-based conditions as telemetry moves through the pipeline. The design is intended for known-bad indicators, policy violations and canary events, routing or alerting on critical data in motion while reducing the volume pushed to more expensive downstream analysis tiers.

"Security teams are telling us they don't want to keep solving every new problem by sending the same data into more closed boxes," said Clint Sharp, co-founder and chief executive of Cribl. "They want visibility into enterprise AI usage and risk, stronger detections, and the flexibility to work across the tools and environments they already have."

Market context

Cribl competes in the broader security data pipeline and SIEM-adjacent market alongside vendors such as Splunk (now part of Cisco), Elastic, Exabeam and a growing number of specialist telemetry routing startups. The SIEM market has long been criticised for high data-ingestion costs and vendor lock-in, dynamics that have driven enterprise interest in open or vendor-agnostic data architectures.

The AI observability angle adds a newer competitive dimension. As large language model deployments move from pilot to production across enterprise functions, security and finance teams are increasingly looking for tooling that can track token spend, model adoption and data-leakage risk without standing up a dedicated platform for each problem. Chris DePuy, co-founder and analyst at 650 Group, noted in the release that Cribl's architecture positions the SIEM as one application among several rather than the centre of the data architecture, and that the AI Observability app alone is "substantial enough to be its own company."

Regulatory read-across

Enterprises deploying AI at scale face tightening obligations under the EU AI Act, which imposes logging and transparency requirements on certain classes of AI system, and under existing frameworks such as GDPR, which restricts the flow of personal data into model prompts. Cribl's emphasis on retaining data within existing infrastructure, rather than copying it into a vendor-controlled cloud, may carry practical compliance value for customers subject to data-residency rules. The company has not published formal compliance certifications specific to the new capabilities, and enterprise buyers will likely require independent validation before relying on the tooling for regulatory audit trails.