Skip to content

Cribl Announces AI Observability at Black Hat

At Black Hat USA 2026, Cribl unwrapped a set of AI-era security capabilities for its existing platform. The headline is the AI Observability app, which puts token counts, spending, model uptake, and risk into a single view across teams and applications and flags sensitive data as it enters prompts and traces. Around it, detection engineering built on the company’s CardinalOps acquisition closes visibility gaps across a wider security environment, and stream-native detections in Cribl Stream surface high-confidence signals earlier without forcing teams to copy their telemetry. CEO Clint Sharp frames the thinking behind it: “Security teams are telling us they don’t want to keep solving every new problem by sending the same data into more closed boxes.” The company has been very busy: last week it announced the acquisition of CardinalOps, which marked its entrance to the SIEM market, and now at Black Hat, it announced AI Observability.

The most striking signal is the size of the opportunity: AI Observability alone is large enough to be its own standalone business, and yet Cribl is entering it as an extension of its current telemetry business rather than spinning it out. That is a deliberate architectural choice — one more application on data the company already collects, not a bet on another closed platform. And in that sense, this is Cribl adapting Traditional observability, which we have covered for years, to a different environment. AI is surging, and customers now ask questions they never asked before — which models are in use, how many tokens, at what cost, and with what risk — and AI Observability is the same pipeline it always was, pointed at those new, urgent questions.

Cribl App for AI Observability dashboard
Cribl App for AI Observability. Source: Cribl Blog

On an open telemetry foundation you can build numerous, valuable “apps,” and Cribl keeps shipping them: the AI Observability app today and the SIEM app it announced a week ago. 650 Group researches several of the technologies covered here, including Enterprise and Security and SASE.