Cribl Detect Takes the Pipeline Company Into the SIEM Business

Cribl Detect Takes the Pipeline Company Into the SIEM Business

Analyst(s): Fernando Montenegro
Publication Date: September 30, 2026

At CriblCon, Cribl launched Cribl Detect, a SIEM built on its telemetry platform, alongside StreamAI, an AI gateway with a model router. We look at what it takes for a pipeline vendor to run the detection loop, and whether buyers will compose a security operations platform or consolidate onto one.

What Is Covered in This Article:

  • Cribl Detect combines CardinalOps, Radiant Security’s AI SOC technology, and Cribl’s pipeline into a SIEM priced on infrastructure.
  • Running detections on data where it already sits goes after the real switching cost, though detection content and migration remain the hard part.
  • Cribl moves from a neutral router to a competing destination just as its closest pipeline peers have been absorbed into platforms.
  • Most buyers run a mix of platform and point tools, yet consolidating SIEM and SOAR remains a top SOC priority for many.
  • StreamAI’s savings case rests on Cribl’s own benchmark, which will need independent testing.

The News: At its CriblCon user conference on September 29, 2026, Cribl announced Cribl Detect, a SIEM built on its telemetry data platform and available now to Cribl.Cloud customers. Detect runs detections in-stream and investigations across data where it already sits (pipelines, data lakes, object stores, and existing tools), and adds detection posture management that maps rules to MITRE ATT&CK and flags coverage gaps, broken rules, and missing telemetry. AI SOC triage and investigation, SOAR, and compliance capabilities round out the offering. Cribl prices Detect on infrastructure rather than ingest or search volume and says it costs up to 50% less than other SIEMs. The launch builds on Cribl’s July acquisition of CardinalOps and its August purchase of Radiant Security’s AI SOC technology assets. Cribl says it has passed $300 million in ARR with 1,500 customers.

Cribl also announced StreamAI, an AI gateway whose model router draws on Cribl’s SecIT Bench research, which tested 20 models across 30 IT and security investigations. StreamAI enforces budgets and spending cutoffs, falls back to alternative models at cost limits, redacts sensitive data in both prompts and responses, and logs every model call. Inference is free when StreamAI selects the model. Availability and supported providers have not yet been announced.

Cribl Detect Takes the Pipeline Company Into the SIEM Business

Analyst Take: The SIEM has been declared dead roughly every eighteen months for the better part of two decades, and yet the category keeps attracting new entrants. The latest is a company that spent years helping customers route data around their SIEM.

We have never found the obituary useful. What has been wearing thin is the SIEM-centric architecture: one vendor’s schema, one pricing meter, and every byte of telemetry moved into one place before anyone can ask a question of it.

Cribl Detect is a bet against that architecture, and it raises the question we think matters more in 2026: who runs the detection, investigation, and response loop, and do buyers get there by consolidating onto one platform or by composing one from the controls and data they already own?

From Feeding the Loop to Running It

The last three months have a clear logic to them. CardinalOps brought detection engineering and posture management in July, Radiant Security’s technology brought AI-driven triage and investigation in August, and Cribl already had the pipeline, search, and lake pieces underneath. Two design choices stand out to us. Running detections and investigations against data where it already sits goes straight at what we see as the main switching cost in this market, which has always been moving years of historical telemetry before a new SIEM is useful. Pricing on infrastructure also removes the penalty for asking your own data too many questions, an incentive problem we have long felt ingest- and query-metered SIEMs create.

That matters more once AI SOC agents arrive, since an agent testing every hypothesis at once will run far more searches than a human analyst ever did, and those query costs do not shrink on their own.

We think of a security operations platform as whatever runs the detection, investigation, and response loop end to end. A pipeline, however good, sits upstream of that loop. With Detect, Cribl is stepping inside it.

What Makes a SIEM Hard to Replace?

Moving data is the part Cribl knows best, and arguably the easier part. Detection content, tuning, and the years of analyst trust built up around an incumbent are harder. Splunk and Sigma content migrates through assisted translation, according to Cribl, with validation and tuning required. Cribl’s pitch to adopt one workload at a time lowers the stakes, though a large incumbent deployment still makes this a sizable project.

Federation raises a question we would put to any data-in-place design: how well does it hold up when a detection has to correlate across sources? A multi-stage intrusion that moves from a phished identity to the cloud control plane to an endpoint means joining telemetry that may sit in different stores, formats, and retention tiers, which is precisely where centralized SIEMs earned their keep. In-stream detection helps, but cross-source attack chains are where we would test it hardest.

We agree with Cribl on one point in particular: security teams decide what to send to the SIEM based on what they can afford, which turns a budget decision into a risk decision without anyone saying so. The more realistic entry point, in our view, is exactly that telemetry, the logs already routed around the SIEM and sitting in object storage because indexing them was too expensive, with nobody running detections against them.

That is a useful beachhead, and a different sale from displacing an incumbent. Cost opens doors, though SOC teams ultimately buy on detection quality.

Neutral Router or Competing Destination?

Much of Cribl’s value has come from neutrality, routing telemetry to Splunk, Microsoft Sentinel, Google SecOps, CrowdStrike, and others. Its closest peers have since been absorbed into platforms (Onum into CrowdStrike, Observo AI into SentinelOne, Chronosphere into Palo Alto Networks), which leaves Cribl as one of the largest independent pipelines just as it becomes a destination itself.

Partners whose SIEMs sit downstream of Cribl will notice, and SIEM is only the first stop: Cribl says APM, AI SOC, and AI observability are already live, with CSPM and DSPM on the roadmap, and each one adds competitors.

Detect also lands in a market already moving toward data-in-place. Splunk is reworking its pricing around federated data, Microsoft has made the Sentinel data lake generally available, and a crop of federated SIEM and AI SOC startups is pitching much the same architecture.
The buyer data suggests the composable bet is reasonable, if far from settled. In our 1H 2026 Cybersecurity Decision-Makers Survey (N=929), 41% of respondents describe their security tooling as a roughly even mix of platform and point offerings, and only 12% say more than 80% of it comes from platform vendors. Consolidation still pulls hard, though: in a smaller module of the same survey (N=100, directional), 36% cited consolidating legacy SIEM and SOAR tools into a unified platform among their top three SOC initiatives for the next 12 to 18 months.

Is StreamAI the Same Trick Applied to Tokens?

An AI gateway is a natural extension for a routing company. The SecIT Bench result Cribl cites, a 17% spread in diagnostic accuracy against a 20x spread in investigation cost, would mean a lot of AI spend in IT, and security work is going to models more expensive than the task requires. Cribl built both the benchmark and the router, though, so the savings math deserves independent checking.

The governance angle interests us more. Switching models to manage cost creates friction when the investigation context ends up flowing to providers the enterprise never approved, and logging every routing decision while redacting in both directions addresses part of that. Routing on the fly also means the evals behind a workflow have to follow the model: accuracy, refusal behavior, and output format validated on one model do not automatically carry over to its replacement, and the router has to keep that evidence current.

The field is crowded, with Palo Alto Networks (via Portkey), F5 (via CalypsoAI), Cloudflare, and Kong among others already selling AI gateways. Free inference when the router picks the model is an aggressive opening offer, and one whose economics get more interesting as agent traffic grows and someone has to absorb that cost.

What to Watch:

  • Will early Detect customers go beyond the cheap-data wedge? The test is whether anyone moves primary detection off an incumbent SIEM in the next few quarters, or whether Detect settles in as a second tier for data too expensive to index.
  • How will the SIEMs Cribl feeds respond? Watch whether Splunk, Microsoft, Google, and CrowdStrike keep treating Cribl as a partner, through their integrations, co-selling, and marketplace listings, now that it competes with them.
  • Can Cribl go deep enough in each market it enters? SIEM, APM, AI SOC, CSPM, and DSPM on one platform is a broad agenda, and detection content alone takes the threat research depth incumbents spent years building.
  • Will SecIT Bench hold up to independent testing? StreamAI’s savings case rests on a 17% accuracy spread against a 20x cost spread. Third-party reproduction, plus latency data from production, will decide how far buyers trust the router.
  • When does a self-managed Detect arrive? As long as Detect runs only on Cribl.Cloud, regulated, sovereignty-sensitive, and on-premises buyers are out of reach. A self-managed option would widen the market considerably.

For more information, read the full announcement from Cribl or the announcement on StreamAI.


Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.

Other Insights From Futurum:

Security Operations Platforms – Futurum Signal

A Loud Floor and a Quiet Gap: Security Summer Camp 2026

RSAC 2026: The AI Tragedy of the Commons and the Future of Agentic Security

The Hard(er) Challenge in Agent Governance Is Authorization

Author Information

Fernando Montenegro

Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice's growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.

Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.

Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

Related Insights
NVIDIA Wants Agent Safety Enforced in Silicon
September 29, 2026

NVIDIA Wants Agent Safety Enforced in Silicon

Fernando Montenegro, Mitch Ashley, and Brendan Burke from Futurum analyze NVIDIA's Open Agent Safety Platform, which pairs OpenShell runtime controls with Sentry DPU monitoring to contain AI agents outside their...
Wiz Bets on MSP Channel to Scale AI-Driven Cloud Security
September 29, 2026

Wiz Bets on MSP Channel to Scale AI-Driven Cloud Security

Wiz launched its Partner Alliance MSP Program, using the Wiz Tenant Manager to help managed services partners deliver AI-driven cloud security at scale, addressing operational gaps as AI expands attack...
Palo Alto Networks Bets Frontier AI Can Make Pentesting Continuous
September 28, 2026

Palo Alto Networks Bets Frontier AI Can Make Pentesting Continuous

Fernando Montenegro, VP at Futurum, analyzes Palo Alto Networks' Unit 42 Continuous Frontier AI Defense, weighing gated model access, tier economics, and whether always-on AI testing closes exposures....
Cohesity Extends Cyber Resilience to the AI Agents Themselves
September 28, 2026

Cohesity Extends Cyber Resilience to the AI Agents Themselves

Fernando Montenegro, VP at Futurum, analyzes Cohesity's Agent Resilience launch at Catalyst 2026, which brings backup and rollback to AI agents and ties recovery to business continuity....
WidePoint's DHS Contract Protest: Setback or Speed Bump?
September 26, 2026

WidePoint's DHS Contract Protest: Setback or Speed Bump?

The GAO sustained TurningPoint Global Solutions' protest of WidePoint's DHS CWMS 3.0 contract award. Futurum Group analyzes whether this represents a major setback or routine federal contracting process, examining WidePoint's...
Nomios Acquires Orbcom to Plant Its Flag in Iberia
September 24, 2026

Nomios Acquires Orbcom to Plant Its Flag in Iberia

Nomios, backed by Keensight Capital, acquired Orbcom, a €15M Portuguese cybersecurity firm with 80 professionals, establishing its first Iberian presence and gaining Palo Alto Networks Diamond Innovator Partner status....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.