
Work Here?
Cribl provides data observability solutions that help tech teams collect, route, transform, and analyze logs and metrics. Cribl Stream routes and transforms data on either on-premises infrastructure or in the cloud, while Cribl Edge gathers real-time observability data from edge devices and forwards it to Stream or other destinations. The platform integrates with services like Office 365 and Microsoft Azure to simplify data collection and visualization. The goal is to give organizations real-time visibility into their data, improve operational efficiency, and strengthen security by managing data flows and observability insights.
Industries
Data & Analytics
Consulting
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Series E
Total Funding
$596.4M
Headquarters
San Francisco, California
Founded
2018
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$596.4M
Above
Industry Average
Funded Over
7 Rounds
Competitive Salary
Stock Options
Medical, dental, and vision insurance
Flexible spending account (FSA)
401(k) plan offered (US)
Parental Leave
Professional Development and Career Growth
Generous Vacation and Holiday Policy, including 2 Floating Holidays for holidays you observe
Employee Resource Groups that reflect our values driven company culture
Locking down apps at Cribl: RBAC, elevated permissions, and user identity. Last edited: August 5, 2026 If you've started building or installing Cribl Apps, you know the power. Apps let you make Cribl's AI Telemetry platform work for you. Now Cribl is making apps better and more secure. Admins will have more control on who can use apps, more visibility on what they can do, and Cribl is giving app authors more capabilities for building secure apps. Its June release shipped three meaningful upgrades to how Apps handle access and identity: per-App sharing, declarative permission elevation, and signed-in user identity. Together, these enhancements make Apps something you can govern and build real multi-user experiences on top of. RBAC for Apps. Cribl is continually hardening the security of apps and providing more tools to admins. Cribl has introduced app sharing to allow admins to control which users and teams can use them. You can now share installed Apps with specific Members or Teams instead of exposing them to your whole Organization. From Apps > Installed, open the row's actions menu and select Share, then assign App user access on the Members or Teams tab. Say you built an internal App for reviewing Worker Group health, but it's really only relevant to your Platform team - now you can limit it to just that team. Or maybe you've got an App that touches something sensitive, and you want to limit the blast radius to a named set of people while you validate it. App sharing puts admins in full control to decide. For its MVP, RBAC is limited to whether or not a user can see an app. This will get richer and you can imagine more roles appearing in the future like Editor, Viewer, etc. Elevated permissions: let your App do more than the user can. Apps previously only ran under the permissions of the user accessing them. Cribl has seen customers hitting scenarios where apps need to access specific endpoints that the user may not have access to. An app author now has the ability to declare elevated access to APIs that it needs. For example by design an app may need to access diagnostic / health data for displaying a dashboard. An author can now declare in policy.yml that it needs access to those APIs and the app will get those permissions. Administrators review these declarations during install and upgrade, right alongside any outbound API declarations from proxies.yml, so nothing sneaks in - you can see exactly how the app will elevate before you install. In the example below you can see the author has elevated the roles endpoint so that the app can see all the roles in the org regardless of the user's permission. Signed-in user identity: apps finally know who's using them. Previously App authors had to jump through hoops in order to determine the user's identity. This impacted significantly the ability to personalize apps, or to limit their capabilities. Apps can now read the signed-in member's identity - id, name, and other profile details - directly. You can use the id as part of your namespace keys, so you can really offer a personalized experience. Does your app want to store a list of recent queries for each user? No problem. Want to add your own internal authorization system for parts of your app? Now you can. Better apps, more secure, more personalized. With the new features apps are getting better. Admins will have more governance, authors will have richer security and personalization options. Most importantly, users will get a more secure and tailored experience. Cribl, the AI Platform for Telemetry, empowers enterprises to manage and analyze telemetry for both humans and agents with no lock-in, no data loss, no compromises. Trusted by organizations worldwide, including half of the Fortune 100, Cribl gives customers the choice, control, and flexibility to build what's next. Cribl offer free training, certifications, and a free tier across its products. Its community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. Cribl also offer a variety of hands-on Sandboxes for those interested in how companies globally leverage its products for their data challenges.
Cribl expands AI Observability and security operations. Cribl has announced new AI-focused security capabilities that transform existing enterprise telemetry into actionable AI visibility, stronger threat detection, and faster security response. The release introduces an AI Observability app that helps organizations monitor AI token usage, spending, model adoption, and risk across teams and applications. Expanded detection engineering and stream-native detections further improve threat coverage while enabling earlier identification of high-confidence threats without duplicating telemetry or rearchitecting existing infrastructure. AI adoption is moving from experimentation to infrastructure faster than enterprises can govern it. Many cannot answer basic questions about which teams and applications use which models, how token consumption maps to spend, when demand peaks, whether a smaller model could do the job, or where sensitive data is entering prompts. Security teams face a parallel problem: more telemetry, faster threats, and more disconnected tools. The market's default answer remains another collector, another copy of the data, and another closed platform. Machine Learning & Artificial Intelligence In contrast, Cribl's new capabilities represent a pivotal expression of the company's platform strategy, building on the AI Platform for Telemetry as a foundational infrastructure layer to offer real, customer-facing applications that solve urgent enterprise problems today. "Security teams are telling us they don't want to keep solving every new problem by sending the same data into more closed boxes," said Clint Sharp, co-founder and CEO of Cribl. "They want visibility into enterprise AI usage and risk, stronger detections, and the flexibility to work across the tools and environments they already have. This is our new approach: keep the data open, run the security capabilities on top, and give teams a path forward without rebuilding the stack every time the market changes." Understand AI usage, cost, and risk across the enterprise. Cribl's new AI Observability app gives organizations a fast, unified view of AI activity across models, applications, departments, and environments. Using existing telemetry already flowing through Cribl or retained elsewhere, teams can compare usage and spend by model, app, department, or workload; see demand peaks; understand token consumption across applications; and identify workloads better served by a smaller, less expensive model. Teams can also detect sensitive data exposure in prompts and traces, analyze usage and cost, and investigate complete sessions over time. This is done without duplicating pipelines, paying to pull data back out of closed platforms, or locking themselves into another proprietary stack. Security Products & Services Continuously improve detection engineering across environments. New detection engineering capabilities enable Cribl's platform to more intelligently identify relevant events in telemetry data. Building on Cribl's recent acquisition of CardinalOps, these capabilities map detections to the MITRE ATT&CK framework, expose coverage gaps, identify broken and noisy rules before they fail silently, and apply AI-assisted workflows so detection content can be maintained and improved over time instead of quietly drifting. That gives teams clearer visibility into what is covered, what is broken, and where to focus next across a broader security environment than any single SIEM can see on its own. Generate high-confidence security signals in motion. Cribl is bringing stream-native detections in Cribl Stream, enabling teams to identify high-confidence, event-based conditions and new classes of security-relevant events from normalized and enriched telemetry as it moves through the pipeline. Designed for known-bad indicators, policy violations, canary events, and other atomic tripwires, these detections help teams alert, route, or fast-track critical data while reducing what is sent to premium analysis tiers. More complex detections continue to use full-fidelity history for stateful correlation, backtesting, threat hunting, and investigation. The result is speed where it matters, without sacrificing the context required for trustworthy decisions. "With Cribl's platform model, AI Observability and SIEM solutions are not separate walled gardens. They are applications that can sit on a variety of data stores running over Cribl's telemetry infrastructure," said Chris DePuy, co-founder and analyst at 650 Group. "The SIEM is one app among others rather than the center of the architecture while the AI Observability app by itself is substantial enough to be its own company."
Black Hat USA news roundup - August 3, 2026: Sumo Logic, Cribl, Mimecast. Published: August 3rd, 2026 Sumo Logic expands agentic AI capabilities to turn telemetry into action. The company today announced at the Black Hat USA conference Sumo Logic Analyst Agent, MCP Server and a new version of its Mobot conversational interface for security and observability workflows "We believe that telemetry is the fuel of the AI future," Jeremy Powell, CISO for Sumo Logic, said in the announcement. "Every threat detection, investigation, and response traces back to telemetry. As AI agents become an increasingly valuable tool for security operations, telemetry is the source of truth that separates a confident answer from an educated guess. We're seeing this in our very own SOC, building from trusted telemetry from Sumo Logic Dojo AI, we were able to reduce MTTR by 64% and saved 25 hours per week per analyst." The Sumo Logic Intelligent Operations Platform refines telemetry to intelligent, actionable vulnerability detection and remediation, while Mobot, and MCP Server provide access to security operations from where teams work. The SOC Analyst Agent investigates SIEM alerts automatically, makes decisions about how to deal with them, and through Mobot enables humans to analyze the decisions. Finally, MCP Server can connect code assistants via API tools to Sumo Logic SIEM and Log Analytics. Cribl's AI Platform debuts powerful new security capabilities. Cribl's new AI Observability app provides a view of AI activity to help manage token usage, spend, model adoption, and risk. The company said these new capabilities address the issues of increasing alerts, faster threats and a tool chain that is disconnected. The new capabilities build on the AI Platform for Telemetry as a foundational infrastructure layer to offer real, customer-facing applications that solve urgent enterprise problems today. "Security teams are telling us they don't want to keep solving every new problem by sending the same data into more closed boxes," said Clint Sharp, co-founder and CEO of Cribl. "They want visibility into enterprise AI usage and risk, stronger detections, and the flexibility to work across the tools and environments they already have. This is our new approach: keep the data open, run the security capabilities on top, and give teams a path forward without rebuilding the stack every time the market changes." New detection engineering capabilities can identify relevant events in the telemetry data, and due to Cribl's recent acquisition of CardinalOps, detections are mapped to the MITRE ATT&CK framework. Things like coverage gaps and broken and noisy rules are exposed and AI-assisted workflows can be applied to maintain and improve detection content, the company said in its announcement. Mimecast unveils tooling for agent risk. threat response. Mimecast Agent Risk Center for monitoring and governing agents is in beta, while Managed Threat Response is a service that provides AI-powered triage and analyst-confirmed remediation. Key capabilities of Agent Risk Center include a real-time inventory of AI tools and connections in an agent dashboard, an AI Rulebook to enforce policy by department, and response controls such as desktop app blocking, upload and paste blocking as well as contextual user nudges, the company said. The Mimecast Agent Risk Center is in beta as a free, opt-in capability for active Incydr subscription customers, with early access in September 2026 and general availability for those customers planned for January 2027. Article tags. About david Rubinstein. David Rubinstein is editor-in-chief of ITOps Times and SD Times.
Cribl acquires CardinalOps to further expand its AI Platform into security operations. Published: July 17th, 2026 SAN FRANCISCO, CA - Cribl, the AI Platform for Telemetry, today announced it is acquiring CardinalOps, an Agentic Detection Engineering solution. The acquisition adds detection engineering capabilities that help customers improve threat coverage, lower data costs, and strengthen their SOCs. This creates a flexible path toward replacing legacy SIEM architectures. Security teams are under pressure to process more telemetry, move faster against threats, and control the rising cost and complexity of their environments. With CardinalOps, Cribl can help customers connect those priorities: use telemetry more intelligently, continuously validate and improve detections, and do it in a way that lets customers modernize at their own pace, using the tools and architectures that make the most sense for their environment. "Security teams do not need more disconnected tools. They need a better way to turn telemetry into effective detections and outcomes," said Clint Sharp, co-founder and CEO of Cribl. "CardinalOps strengthens our AI Platform for Telemetry by adding deep detection engineering capabilities to the open data infrastructure our customers already rely on and serves as the foundation for a complete, open alternative to the SIEM stack they've outgrown." The acquisition reinforces Cribl's platform-first approach to the market. Rather than offering another rigid, all-or-nothing security stack, Cribl gives customers an open, vendor-agnostic platform to analyze, collect, move, store, and act on telemetry across their environments. That includes a federated model that lets customers search and work across telemetry where it already lives, without forcing everything into another centralized system. With CardinalOps, Cribl is adding foundational detection engineering capabilities to its AI platform, bringing the same open, AI-native model to the SIEM category itself: everything a SIEM does, on telemetry infrastructure customers already own. That federated foundation also allows Cribl to layer new security and observability solutions on the same shared telemetry foundation, giving customers more flexibility and better economics as they modernize their environments in the AI era. Founded in early 2020, CardinalOps is led by serial entrepreneurs and veterans of IDF's Unit 8200, Michael Mumcuoglu and Yair Manor, whose previous companies were acquired by Palo Alto Networks and Microsoft. CardinalOps uses AI to help organizations continuously assess and improve detection coverage by mapping security controls against real-world adversary behavior. It automates detection engineering tasks, helping teams identify and eliminate coverage gaps, find and fix broken or noisy rules, and unlock the full value of their existing security stack. Combined with Cribl's ability to manage telemetry at scale, CardinalOps adds the detection layer that helps customers move faster from raw data to actionable insights that improve security outcomes. "Too many security teams have good data, powerful tools, and endless alerts, but no real confidence that they are actually protected," said Michael Mumcuoglu, co-founder and CEO of CardinalOps. "We built CardinalOps so SOC teams could understand and improve coverage instead of just managing more noise. Joining Cribl lets us bring that directly into the telemetry layer and build what the market needs next: an open, AI-native alternative to the SIEM, where customers pay for better protection, not more data volume. That's what we're building next." With this acquisition, Cribl will also establish a new office in Tel Aviv, creating a strategic presence in one of the world's most active cybersecurity innovation hubs. The move will allow Cribl to tap into Israel's deep pool of cybersecurity talent and further accelerate the development of its modern security solutions. By bringing CardinalOps into the Cribl platform, Cribl is expanding its footprint in security operations while staying true to what differentiates the company in the market: an open platform, lighter-weight solutions on top, and the freedom for customers to adopt what they need without lock-in. The acquisition also creates a stronger foundation for future security offerings built on the Cribl platform. The integration of CardinalOps technology into the Cribl platform will bring Cribl's security capabilities together into a complete, open alternative to legacy SIEM architectures.
Cribl acquires Israeli cyber startup CardinalOps for around $100 million. The U.S. telemetry company will establish a Tel Aviv office after buying the AI-powered detection engineering startup. The acquisition marks Cribl's push into security operations and its effort to challenge traditional SIEM platforms. 16:28, 14.07.26 Cribl, a U.S. technology company specializing in telemetry management, announced on Tuesday the acquisition of Israeli startup CardinalOps, which develops agentic detection engineering solutions. The companies did not disclose the purchase price, but the deal is estimated at approximately $100 million. Following the acquisition, CardinalOps employees will join Cribl, which will establish a new office in Tel Aviv and is expected to expand its Israeli operations. Cribl develops an AI-powered telemetry platform for cybersecurity and IT teams and is considered one of the fastest-growing technology companies in the U.S., with annual recurring revenue of more than $300 million. The acquisition will extend Cribl's platform into security operations by adding detection engineering capabilities designed to help customers improve threat coverage, reduce data costs, and strengthen their security operations centers (SOCs). The move will allow Cribl to offer customers a more flexible alternative to traditional SIEM (Security Information and Event Management) architectures. Security teams are increasingly under pressure to process growing volumes of telemetry, respond faster to threats, and manage the rising costs and complexity of their environments. Through CardinalOps, Cribl will enable customers to use telemetry more intelligently, continuously validate and improve detection mechanisms, and modernize their security infrastructure at their own pace while maintaining flexibility over the tools and architectures they use. The acquisition reinforces Cribl's strategy of building an open, vendor-agnostic platform rather than another closed security stack. The company's platform allows organizations to collect, analyze, move, store, and act on telemetry across their environments. By adding CardinalOps' detection engineering capabilities, Cribl aims to create a broader alternative to legacy SIEM solutions based on the telemetry infrastructure customers already operate. "Security teams do not need more disconnected tools. They need a better way to turn telemetry into effective detections and outcomes," said Clint Sharp, co-founder and CEO of Cribl. "CardinalOps strengthens our AI Platform for Telemetry by adding deep detection engineering capabilities to the open data infrastructure our customers already rely on and serves as the foundation for a complete, open alternative to the SIEM stack they've outgrown." Founded in early 2020, CardinalOps is led by serial entrepreneurs and veterans of the IDF's Unit 8200, Michael Mumcuoglu (CEO) and Yair Manor (CIO). The founders previously built companies that were acquired by major cybersecurity and technology companies, including Palo Alto Networks and Microsoft. CardinalOps uses artificial intelligence to help organizations continuously assess and improve their threat detection coverage by mapping security controls against real-world attacker behavior. Its technology automates detection engineering tasks, enabling security teams to identify and close coverage gaps, fix broken or overly noisy rules, and maximize the value of their existing security infrastructure. Combined with Cribl's ability to manage telemetry at scale, CardinalOps adds a detection layer designed to help customers move faster from raw security data to actionable insights and improve their overall security posture. "Too many security teams have good data, powerful tools, and endless alerts, but no real confidence that they are actually protected. We built CardinalOps so SOC teams could understand and improve coverage instead of just managing more noise," said Michael Mumcuoglu, co-founder and CEO of CardinalOps. "Joining Cribl lets us bring that directly into the telemetry layer and build what the market needs next: an open, AI-native alternative to the SIEM, where customers pay for better protection, not more data volume. That's what we're building next." CardinalOps currently employs approximately 25 people, most of them in Israel. To date, the company has raised about $40 million from investors including Viola Ventures, Glilot Capital, Battery Ventures, In Venture, XT Hi-Tech, Gefen Capital, Symbol, and others.
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Consulting
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Series E
Total Funding
$596.4M
Headquarters
San Francisco, California
Founded
2018
Find jobs on Simplify and start your career today