What is Observability - Feature

The Strategic Importance of Observability: Discovery to Data Control

cribl-blogmark

September 22, 2023

Observability lets IT and Security teams understand applications and infrastructure from the data those systems produce. Here is the thesis of this paper, stated plainly: observability is the ability to discover what you did not know to look for. You cannot discover anything in data you cannot afford to collect, cannot route where it is needed, or cannot query where it lives. Observability is therefore primarily a data control problem.

Modern distributed systems and ephemeral application architectures have exposed the limits of legacy monitoring. Legacy monitoring focuses on collecting and reporting known errors. That works when failure modes are predictable, and it fails in environments where services spin up and vanish in minutes. Observability takes the opposite approach, letting you interrogate system behavior without the constraints imposed by older methods and products. Coping with the volume, variety, and cost of observability data requires a new approach to managing it.

Many SREs, SecOps, and ITOps teams still wrestle with the difference between monitoring and observability. So let's be direct. Observability is not about alerts and dashboards, which are the things you already know. Observability is about discovering the things you don't.

Why does observability matter if you already have monitoring?

You need both observability and monitoring for full insight into your environment. That is the short answer. The surge in interest in observability has created confusion in the monitoring space, and customers ask the same questions: does observability replace monitoring, how do the two work together, and what new tools do I need?

Think of it as the OODA Loop. OODA stands for Observe, Orient, Decide, and Act, and it has been used for decades in domains from military strategy to IT operations. It maps closely to how observability and monitoring divide the work.

What is Observability - Figure 1

Figure 01: The OODA Loop.

Figure 01: The OODA Loop.

On the right side of Figure 1 sit Observe and Orient. This is observability territory. It is where you discover new or unexpected signals in your environment, the things you are not monitoring for yet because you do not even know they exist. Observability gives you the ability to understand the behavior of applications and infrastructure from the data they emit. Observability is about discovery.

The left side, Decide and Act, is monitoring territory. Monitoring is about doing. Once the data indicates a performance problem or a potential breach, you configure your monitoring systems to watch for it and automate the most appropriate response. Discovery feeds action, and action refines what you look for next. The loop continues.

The two concepts are closely related, but there is a difference between them. The biggest difference starts with data.


What makes observability data different from monitoring data?

Observability data is inclusive by design, while monitoring data is exclusive by design. Traditional monitoring platforms take a narrow view of the data they use, and that narrowness limits their view of the environment. They rely primarily on dedicated software agents deployed across applications and infrastructure, and each agent sends data to exactly one place, the monitoring platform it belongs to.

Most enterprises run a sprawl of monitoring tools, each with its own agents, which produces disconnected silos of information. Every silo has a partial picture. None of them has the whole one. The volume makes this worse. In cloud-native environments, most organizations now generate more than 5 to 10 TB of telemetry daily, according to Gartner (2024), and much of it is log data that never gets a second look.

Observability flips the model. With an inclusive approach to every source of data, observability tools provide more discovery value. Today the focus is on four data types: metrics, events, logs, and traces, commonly shortened to MELT.

That list will expand. In the near future, observability platforms will consume a wider array of sources, including configuration management data, dependency maps, and data pulled from data marts, lakes, and warehouses. Those diverse sources will need to reach a changing set of destinations.

Connecting sources to destinations intelligently is the first real observability challenge. This is where the observability pipeline comes in.


Why should an observability pipeline sit between sources and destinations?

An observability pipeline is a control layer positioned between your data sources, such as networks, servers, applications, and agents, and the many destinations in today's IT and SecOps environments. Instead of relying on siloed point-to-point connections, an observability pipeline centralizes your observability data processing and gives your team control over every aspect of your data. Gartner (2024) now explicitly recommends telemetry pipelines as the way to control ingestion and storage costs while routing data to multiple destinations.

From a data management perspective, a pipeline such as Cribl Stream lets you:

  • Filter out redundant data to improve performance and lower the cost of ingest-priced destination platforms.

  • Enrich data with additional context, like GeoIP, for sharper downstream analysis and compliance with data privacy laws.

  • Redact sensitive fields in flight to satisfy data governance requirements.

  • Route data from one source to many destinations, so onboarding a new tool no longer means deploying a new agent.

  • Send full-fidelity data to low-cost storage, and replay it whenever you need it.

The benefits of abstracting sources from destinations compound quickly. You get a single point for governing data and applying consistent rules for redaction, access control, and sharing. You reduce the redundant data flowing into downstream systems like log analytics, SIEM, and SOAR platforms. You also accelerate onboarding of new tools, because one source can feed multiple destinations without touching the endpoints. Extend that processing to the source itself with Cribl Edge, and you can filter and shape data before it leaves the host.

But as the appetite for more data grows, a second challenge surfaces. Not all data is worth the same amount, and its value changes over time. That calls for dynamic data tiering.


Why does observability data need value-based tiering?

Most of the data you collect is never analyzed, and you are paying premium prices to store it anyway. Telemetry data is growing at an average of 29% a year, roughly doubling costs every 18 months, according to Cribl (2025). Much of that data lands in high-cost destinations, then just sits there. It is kept just in case an application goes down or a breach surfaces. Until that day arrives, its value is essentially zero, but you are storing it in your most expensive tier.

The budget math is getting ugly. By 2027, 35% of enterprises will see observability costs consume more than 15% of their overall IT operations budget, according to Cribl's 2026 Trends and Predictions Report (2025). On the security side, 42% of SOCs dump all incoming data into a SIEM with no retrieval or management plan, according to the SANS 2025 SOC Survey (2025). That is not a retention strategy. That is a reflex.

The fix is a data philosophy that aligns where data is stored with its value and usage. Performance-optimized data goes to the analytics, monitoring, and cybersecurity tools that need it, in the shape that is most useful to each platform. Full-fidelity data goes to cost-optimized object storage, where it remains available for exploratory work, investigations, and compliance. A purpose-built telemetry lake like Cribl Lake stores that full-fidelity copy in open formats, so it stays yours and stays replayable.

This tiering strategy places data where it best serves its intended outcome, at a cost that matches its value. Once data is spread across value-based tiers, though, a new question arises: how do you govern, share, and access it across teams and across companies?


How do you access and govern data wherever it lives?

You unify data at the query tier instead of the storage tier. Value-based tiering frees you from forcing everything into the most expensive location. The next step is a way to reach data wherever it resides, whether on an endpoint, in a relational database, behind an API, or in low-cost object storage. What you need is a consistent, immutable view of your data assets, delivered through schema-on-need rather than the schema-on-write or schema-on-read approaches of legacy platforms.

Schema-on-need combines the benefits of schema-on-read and schema-on-write. It eliminates the need to predefine a rigid schema while still providing the performance, quality, and governance benefits of working with one. Unlike schema-on-write, where all data is structured and typed before storage, schema-on-need defers the schema until the moment it is needed. The data engine examines how data is accessed and used, then applies the optimal schema based on those access patterns. The effort and complexity of defining schemas for every data type upfront goes away.

The query experience matters just as much. Cribl Search meets users where they are with an open, familiar pipe-delimited language that applies to any queried source, so analysts no longer need to learn a different language for every tool. And because search is one part of the same data engine, results can be forwarded to any destination through the pipeline. Query in place, find the needle, and send only what matters downstream.


What does a modern observability data management strategy look like?

It is composable, not monolithic. Whether you sit on the IT side or the security side, observability and the data required to achieve it are a challenge. What is needed is a data management strategy that fits the business, regulatory, and financial realities you face today and can adapt to the ones you'll face next year. Strategies that cannot adapt to unpredictable futures will be replaced.

IT and Security teams need a unified, composable, and flexible data management infrastructure as the basis for collecting, processing, storing, and accessing data at scale.

What is Observability - Figure 2

Figure 02: Cribl suite.

Observability gives you the opportunity to discover and understand your dynamic environments in near real time.

A sound observability data strategy removes the compromises baked into both incumbent and newer solutions. It does so by offering capabilities that can be composed into architectures optimized for your environment and your use cases. The core capabilities of a modern data infrastructure are:

  • Endpoint monitoring and management with rich data collection and processing, complete with data access, control, and the ability to search distributed data sets.

  • Pipeline features to route, enrich, govern, and control data at scale.

  • Distributed data sharing and access with strong governance.

  • An opinionated but flexible, automated approach to storage, tiering, and metadata management, built on open data formats.

When composed, these capabilities create a data engine that powers the needs of both IT and Security teams. Adopting a composable observability data infrastructure designed for the diverse and unique needs of today's teams lets organizations navigate data challenges efficiently instead of reactively. The answer is not another platform that wants all your data. The answer is a data engine for IT and Security that gives you a unified, composable data management foundation for today and for whatever comes next.


Own the data before you try to observe it

Every argument in this paper points to the same conclusion: discovery depends on control. You cannot ask new questions of data you dropped to save on ingest. You cannot correlate signals trapped in a dozen agent silos. You cannot investigate a breach with logs that aged out of your SIEM six months ago. Cribl provides tools to give IT and Security teams that control, with no lock-in, no data loss, and no compromises.

Cribl's platform is built on the Data Engine for IT and Security, and it maps directly to the four capabilities above. Cribl Edge collects and processes telemetry at the source, across tens of thousands of nodes, without adding another proprietary agent. Cribl Stream is the vendor-agnostic pipeline that collects, reduces, enriches, redacts, and routes data from any source to any destination, and replays full-fidelity copies when an investigation demands them. Cribl Lake stores that telemetry in open formats at object-storage economics, with unified retention and access policies. Cribl Search queries data in place across the lake, object stores, APIs, and existing tools, so both human analysts and AI agents work from the same governed view of reality.

The result is telemetry that is organized around your teams instead of the other way around. You decide what to collect, how to shape it, where it lives, and who can see it. You onboard new tools or migrate SIEMs without re-instrumenting endpoints. You keep years of full-fidelity history without a budget conversation every quarter. Trusted by organizations worldwide, Cribl gives you the choice, control, and flexibility to build what comes next.

Ready to put discovery on top of data you actually control? Start with free training and certifications at Cribl University, process up to 1TB a day on the free tier of Cribl.Cloud, get hands-on in a Cribl Sandbox, or bring your questions to Cribl engineers, partners, and customers in the Cribl community Slack.


The Strategic Importance of Observability

Q.

What is the difference between observability and monitoring?

A.

Monitoring is about doing: you already know which signals matter, so you build dashboards, set alerts, and automate responses. Observability is about discovery: it lets you interrogate the behavior of applications and infrastructure from the data they emit and find signals you were not looking for. In the OODA Loop, observability covers Observe and Orient, while monitoring covers Decide and Act. Both are necessary.

Q.

Does observability replace my existing monitoring tools?

A.

No. Observability complements monitoring rather than replacing it. Once observability surfaces a new performance or security signal, you configure your monitoring tools to watch for it going forward. The practical challenge is that most monitoring tools use dedicated agents that only send data to one place, which is why an observability pipeline that shares data across destinations becomes essential.

Q.

What is an observability pipeline and why do I need one?

A.

An observability pipeline is a control layer that sits between your data sources (servers, networks, applications, agents) and your destinations (SIEM, log analytics, object storage, data lakes). It lets you filter, enrich, redact, and route telemetry in flight, and send full-fidelity copies to low-cost storage for replay. Cribl Stream provides a single point of governance instead of many brittle point-to-point connections.

Q.

What is value-based data tiering?

A.

Value-based data tiering means storing data where its current value and usage justify the cost. Performance-optimized subsets go to your analytics, monitoring, and security tools. Full-fidelity data goes to cost-optimized object storage for compliance, investigations, and exploratory use. Telemetry is growing roughly 29% a year according to Cribl (2025), so keeping everything in your most expensive tier is not sustainable.

Q.

What is schema-on-need?

A.

Schema-on-need defers applying a schema until the moment you actually need one. Unlike schema-on-write, which structures and types everything before storage, or schema-on-read, which leaves all the work for query time, schema-on-need examines how data is accessed and applies the optimal schema based on those patterns. It removes the upfront effort of defining schemas for every data type while preserving the performance and governance benefits of working with structure.

Q.

How does Cribl support an observability data management strategy?

A.

Cribl's Data Engine for IT and Security has four components: Cribl Edge for collection at the endpoint, Cribl Stream for pipeline routing and governance, Cribl Lake for tiered storage in open formats, and Cribl Search for federated search across data wherever it resides. Together they reduce telemetry volume, lower costs, and keep data portable without vendor lock-in.

Cribl, the AI Platform for Telemetry, empowers enterprises to manage and analyze telemetry for both humans and agents with no lock-in, no data loss, no compromises. Trusted by organizations worldwide, including half of the Fortune 100, Cribl gives customers the choice, control, and flexibility to build what’s next.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on Sandboxes for those interested in how companies globally leverage our products for their data challenges.

get started

Choose how to get started

See

Cribl

See demos by use case, by yourself or with one of our team.

Try

Cribl

Get hands-on with a Sandbox or guided Cloud Trial.

Free

Cribl

Process up to 1TB/day, no license required.