A new way to SIEM starts with a new foundation - og image

A new way to SIEM starts with a new foundation

Last edited: September 29, 2026

Today, we launched Cribl Detect. For me, this launch represents something I have believed for a long time: security teams do not need another version of the same SIEM architecture. They need a fundamentally better way to turn security telemetry into protection.

I have spent much of my career working with SOC teams and building security products, and the same challenge has appeared again and again. Security organizations have more data, more tools, and more detections than ever before, but that has not necessarily translated into greater confidence, faster investigations, or better security outcomes.

That realization was a big part of what drove us to build CardinalOps, and it is also a big part of why I am so excited about what we are launching at Cribl today.

The problem was always bigger than detection

When we founded CardinalOps, we focused on a problem that was hiding in plain sight. Security teams had invested heavily in SIEMs, EDR platforms, cloud security tools, identity systems, threat intelligence, and countless other technologies, yet they often struggled to answer some very basic questions: Are we detecting the threats that matter most? Where are our coverage gaps? Which detections are actually working? Which ones are broken or generating noise? Do we even have the telemetry required to detect a particular attack?

We developed Detection Posture Management to help answer those questions continuously. Instead of assuming that more rules meant better protection, we wanted organizations to understand whether their detections were actually effective.

But the deeper we went, the more obvious it became that the problem was broader than detection alone. Detection quality depends on the data underneath it. If the right telemetry is not available, even the best detection is useless. If data is too expensive to ingest, teams sacrifice visibility to stay in budget. If security data is spread across disconnected systems, investigations become slower and harder.

That experience gave us a deep understanding of the detection problem. Joining Cribl gave us the opportunity to address the much larger architecture around it.

Security teams are being forced into two bad choices

When I look at the SIEM market today, I see security teams caught between two very different models, neither of which fully solves the problem.

On one side is the traditional monolithic SIEM. These platforms bring a lot of capabilities together, but they typically do it by requiring customers to move more and more of their data into the vendor’s proprietary ecosystem. The vendor controls the analytics, storage, data model, and increasingly the workflows around it. Once years of data, detections, dashboards, and operational processes are tied to that platform, leaving becomes incredibly difficult.

The economics compound the problem. Security data continues to grow, yet much of the SIEM market still monetizes that growth through ingestion or per-GB pricing. Teams know that more telemetry can improve visibility and investigation, but every new source comes with another cost calculation. The result is often filtering data, shortening retention, or deciding that some telemetry is simply too expensive to keep.

On the other side is the increasingly popular “SIEM-less” approach. The idea is appealing: break apart the monolith and assemble a security architecture from specialized products for pipelines, storage, detection, search, investigation, automation, and response.

But in practice, that often transfers the integration problem to the customer. Now the security team is responsible for stitching together eight vendors, eight schemas, eight contracts, multiple query languages, and integrations they have to build and maintain themselves.

Security teams should not have to choose between a monolith that locks them in and an architecture they have to assemble themselves.

There is a third option: an integrated security platform that preserves choice and control without turning the customer into the systems integrator.

Cribl starts from a different place

Cribl was built around a simple idea: organizations should have control over their telemetry — what they collect, how they shape and route it, where they store it, how they access it, and how they manage the economics surrounding all of it.

That philosophy fundamentally changes how you can think about SIEM. Traditional SIEM architecture starts with the analytics platform and asks you to bring your data into it. Cribl starts with the data itself.

Because Cribl already sits in the telemetry path, security analytics can happen closer to the data and, in some cases, while that data is still in motion. Organizations can decide which telemetry needs high-performance analytics, which data should be retained economically, and where that data should live. You can throw out the assumption that every byte first has to be copied into one proprietary security data store.

The traditional model has forced you to centralize the data before you can secure it. Cribl brings security closer to the data and gives you control over what moves, what stays, and what gets stored.

That is one of the reasons the combination of Cribl and CardinalOps made so much sense. We are bringing together deep expertise in detection engineering and security outcomes with a telemetry platform built around openness, flexibility, and control.

Extending the AI Platform for Telemetry into a complete SIEM

Today, Cribl Detect extends Cribl’s AI Platform for Telemetry into a complete SIEM solution, bringing detection, coverage and posture management, investigation, response, and threat intelligence together on the same telemetry foundation.

High-fidelity detections

Cribl Detect can generate detection signals directly in the data pipeline, allowing security teams to identify threats in real time while also understanding the security value of telemetry before deciding where it should be stored. Correlation connects individual signals into broader chains of activity, helping analysts identify slow-burn or multi-stage attacks that would otherwise appear as isolated events.

Teams can start with a catalog of more than 8,000 detection rules covering a broad range of threat use cases, then use the Detection Lab to build, validate, and tune rules through an AI-assisted interface grounded in detection engineering expertise. And because security analytics have to work at enterprise scale, Cribl Detect is built to maintain detection and query performance even as telemetry and search volumes grow.

Coverage and posture management

Detection, however, is only part of the job. Cribl Detect helps teams understand whether they are actually prepared for the threats they care about. Teams can map coverage against MITRE ATT&CK, visualize rule health and coverage by tactic or threat group, and identify configuration or schema drift that can silently break detections.

Prioritized recommendations help focus detection engineering efforts on the gaps that matter most based on an organization’s threat model and priority adversaries. The goal is not simply to generate more detections, but to continuously improve the effectiveness of the detection program itself.

AI-guided investigation

Once a threat is identified, analysts need to move quickly from signal to understanding. AI-guided investigation helps analysts explore related evidence and determine next steps without requiring deep query language expertise.

Results from multiple systems can be brought together in a unified view across events, fields, tables, timelines, and charts. Collaborative notebooks give teams a shareable and auditable way to combine searches, findings, and analyst notes during an investigation, making it easier to preserve context and work together.

Integrated response

Cribl Detect carries that workflow from investigation into response. AI-driven triage helps separate genuine threats from noise, while related signals are aggregated into streamlined alerts so analysts can work from a coherent view rather than scattered raw events.

Existing SOAR investments can remain part of the workflow, and flexible notifications can route alerts into Slack, PagerDuty, or other operational channels.

Threat intelligence and enrichment

Throughout the workflow, threat intelligence and enrichment provide the context analysts need to make better decisions. External intelligence on APT activity, vulnerabilities, and evolving adversary behavior can be combined with internal context about users, endpoints, assets, and systems.

Rather than forcing analysts to pivot across multiple tools to assemble that picture, the context becomes part of the detection, investigation, and response experience itself.

This is what we mean by extending the AI Platform for Telemetry into security operations. Data management, detection, investigation, and response are no longer separate layers that customers have to assemble themselves. They become part of one integrated platform while customers retain control over the underlying telemetry.

Better data leads to better security outcomes

For a long time, data management and security analytics have been treated as separate problems. Security teams can’t afford to think that way anymore.

The quality of your security outcomes depends directly on the telemetry available to your SOC. If important data is discarded because it is too expensive to ingest, you create blind spots. If telemetry is locked into different proprietary systems, investigations become harder. If detection logic breaks because upstream data changes, teams can lose coverage without even realizing it.

Cribl has spent years helping enterprises solve telemetry challenges at scale. With Cribl Detect, that same foundation can now directly support the security outcomes the SOC is responsible for delivering.

One of the lessons we learned very clearly at CardinalOps is that having hundreds or thousands of rules does not necessarily mean an organization is well protected. What matters is whether those detections work, whether they cover the threats that matter, and whether the right telemetry is there to support them.

A modern SIEM should not be judged by how many rules it contains or how much data it can ingest. It should be judged by how effectively it helps protect the organization.

Open without being fragmented

Openness matters, but openness should not mean complexity.

Customers should have choices about where their data lives and how they use it. They should be able to work with open formats, integrate with the ecosystem they already have, and evolve their architecture over time. But they should not need eight products, eight schemas, eight contracts, and a team of engineers to make all of those pieces behave like a single security platform.

We think the right model combines an open architecture underneath with an integrated security experience on top. Customers maintain control over their data and architecture, while the SOC gets the detection, investigation, response, AI, and security workflows it expects from a modern SIEM.

We do not believe customers should have to surrender control of their data to get an integrated security platform. And we do not believe they should have to build the platform themselves to maintain that control.

A new way to SIEM

Cribl entering the SIEM market is a major milestone for the company. But the bigger story is what happens when security analytics becomes part of a broader telemetry platform.

Detection can happen while data is moving. Detection posture can be continuously measured and improved. Data can be stored and accessed based on its value rather than the constraints of a proprietary architecture. AI can help analysts move from an alert to understanding and action faster. And security teams can gain more control over both their security strategy and their budget.

That is what makes this launch so exciting to me personally. The work we began years ago around improving detection effectiveness now becomes part of something much bigger: a complete SIEM built on Cribl’s telemetry foundation.

We are not trying to recreate the traditional SIEM and compete feature by feature. And we are not asking customers to stitch together a collection of technologies and call the result a SIEM.

We are extending Cribl’s AI Platform for Telemetry into security operations with a SIEM built around security outcomes rather than rigid architecture — helping teams detect earlier, retain smarter, investigate faster, respond more effectively, and scale without forcing every byte of telemetry into the same analytics tier.

The SIEM still has an essential role to play. We just think there is a better way to do it.

Cribl Detect. A new way to SIEM.

Cribl, the AI Platform for Telemetry, empowers enterprises to manage and analyze telemetry for both humans and agents with no lock-in, no data loss, no compromises. Trusted by organizations worldwide, including half of the Fortune 100, Cribl gives customers the choice, control, and flexibility to build what’s next.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on Sandboxes for those interested in how companies globally leverage our products for their data challenges.

More from the blog

get started

Choose how to get started

See

Cribl

See demos by use case, by yourself or with one of our team.

Try

Cribl

Get hands-on with a Sandbox or guided Cloud Trial.

Free

Cribl

Process up to 1TB/day, no license required.