Cribl introduces AI Observability and expanded detection engineering
Cribl introduced new AI-era security capabilities tied to its AI Platform for Telemetry, focusing on visibility into AI usage and risk, stronger detections, and faster security action. The updates aim to use existing enterprise telemetry to produce security signals and operational insights without introducing another closed telemetry stack.
Cribl framed the change around enterprise needs for governance and clarity in AI adoption, including answers about which teams and applications use which models, how token consumption maps to spend, when demand peaks, and where sensitive data enters prompts. It also cited the need for security teams to handle more telemetry and faster threats while dealing with disconnected tools.
The company’s AI Observability app provides a unified view of AI activity across models, applications, departments, and environments. It uses existing telemetry already flowing through Cribl or retained elsewhere to compare usage and spend by model, app, department, or workload, view demand peaks, understand token consumption across applications, identify workloads for smaller models, detect sensitive data exposure in prompts and traces, analyze usage and cost, and investigate complete sessions over time.
Cribl also expanded detection engineering by mapping detections to the MITRE ATT&CK framework, exposing coverage gaps, identifying broken and noisy rules before failures, and applying AI-assisted workflows to maintain and improve detection content over time. In Cribl Stream, it introduced stream-native detections that create high-confidence, event-based conditions and new classes of security-relevant events from normalized and enriched telemetry, with more complex detections continuing to use full-fidelity history for stateful correlation, backtesting, threat hunting, and investigation. “Security teams are telling us they don’t want to keep solving every new problem by sending the same data into more closed boxes,” said Clint Sharp, co-founder and CEO of Cribl. “They want visibility into enterprise AI usage and risk, stronger detections, and the flexibility to work across the tools and environments they already have. This is our new approach: keep the data open, run the security capabilities on top, and give teams a path forward without rebuilding the stack every time the market changes.”
Provided by Globe Newswire on behalf of Cribl. Click to read original content. The original article was written by Decision Insights Editorial.