Cribl Embeds New AI Observability Capabilities in AI Platform to Enhance Security
Cribl, the AI Platform for Telemetry, is offering new AI-era security capabilities that turn existing enterprise telemetry into AI visibility, stronger detections, and faster security action.
The new AI Observability app helps manage token usage, spend, model adoption, and risk across teams and applications. Expanded detection engineering improves coverage, while stream-native detections surface high-confidence threats earlier, without duplicating telemetry or rebuilding the infrastructure beneath every new tool, according to Cribl.
Cribl’s new capabilities represent a pivotal expression of the company’s platform strategy, building on the AI Platform for Telemetry as a foundational infrastructure layer to offer real, customer-facing applications that solve urgent enterprise problems today.
“Security teams are telling us they don’t want to keep solving every new problem by sending the same data into more closed boxes,” said Clint Sharp, co-founder and CEO of Cribl. “They want visibility into enterprise AI usage and risk, stronger detections, and the flexibility to work across the tools and environments they already have. This is our new approach: keep the data open, run the security capabilities on top, and give teams a path forward without rebuilding the stack every time the market changes.”
Cribl’s new AI Observability app gives organizations a fast, unified view of AI activity across models, applications, departments, and environments, said Cribl.
Using existing telemetry already flowing through Cribl or retained elsewhere, teams can compare usage and spend by model, app, department, or workload; see demand peaks; understand token consumption across applications; and identify workloads better served by a smaller, less expensive model.
Teams can also detect sensitive data exposure in prompts and traces, analyze usage and cost, and investigate complete sessions over time, the company said.
New detection engineering capabilities enable Cribl’s platform to more intelligently identify relevant events in telemetry data. Building on Cribl’s recent acquisition of CardinalOps, these capabilities map detections to the MITRE ATT&CK framework, expose coverage gaps, identify broken and noisy rules before they fail silently, and apply AI-assisted workflows so detection content can be maintained and improved over time instead of quietly drifting.
Additionally, Cribl is bringing stream-native detections in Cribl Stream, enabling teams to identify high-confidence, event-based conditions and new classes of security-relevant events from normalized and enriched telemetry as it moves through the pipeline.
Designed for known-bad indicators, policy violations, canary events, and other atomic tripwires, these detections help teams alert, route, or fast-track critical data while reducing what is sent to premium analysis tiers. More complex detections continue to use full-fidelity history for stateful correlation, backtesting, threat hunting, and investigation. The result is speed where it matters, without sacrificing the context required for trustworthy decisions, said the company.
For more information about this news, visit https://cribl.io.