Observability & Data Pipelines
Observability — monitoring application performance, infrastructure health and logs — grew up beside security operations as a separate discipline with a separate buyer (the platform/SRE team rather than the SOC). The two are converging because they run on the same raw material: telemetry. Logs, metrics, traces and events feed both the performance dashboard and the detection rule, and the economics of collecting, routing and storing that telemetry — the per-GB cost problem covered on SecOps & SIEM — are identical on both sides.
The market and its players
Datadog (NASDAQ: DDOG) is the scale reference: $3.43B revenue in 2025, with Q1 2026 revenue of $1.006B, up 32% year over year, and ARR crossing $4B — and a security product line (Cloud SIEM, CSM, application security) built directly on its observability data (Datadog reporting via market coverage). Splunk — acquired by Cisco for $28B (closed March 2024) — is the clearest single statement of convergence: a networking incumbent paying a landmark price for an asset that is simultaneously the most-deployed enterprise SIEM and a major observability platform (Deals). Dynatrace, New Relic (private; Francisco Partners/TPG), Elastic, Grafana Labs, Sumo Logic (private; Francisco Partners) and Honeycomb round out the platform tier — several of them carrying meaningful security revenue.
The strategically distinct layer is the telemetry pipeline: vendors that sit between data sources and destinations, deciding what gets collected, transformed, routed and stored. Cribl is the category leader, and it bought into security operations twice in 2026: CardinalOps (July 2026), an AI-native detection-engineering startup, and then, 36 days later, the technology assets and intellectual property of Radiant Security's AI-native SOC product (Aug 19, 2026) — autonomous alert triage, investigation and resolution, being adapted to run as an application on the telemetry platform, with terms undisclosed (11). The sequence matters for this page because it is the pipeline layer moving up the stack rather than defending its position in it: Cribl's stated rationale is that capabilities which once justified a standalone product increasingly make more sense running on shared telemetry infrastructure than as a separate tool with its own data silo. Abstract Security ($25M round, July 2026, ARR up 380%) runs detections in-stream on the pipeline itself. The pipeline layer matters because it is leverage over both markets at once: it can cut a customer's SIEM ingestion bill and re-route the same data into security tooling.
| Player | Position | Security relevance |
|---|---|---|
| Datadog | Public platform, ~$4B ARR | Native SIEM/CSM line; expands from observability into the SOC |
| Splunk (Cisco) | $28B acquisition | SIEM + observability in one asset under a networking parent |
| Cribl | Pipeline leader | Bought detection engineering (CardinalOps) and AI-SOC triage IP (Radiant); SIEM-cost disruptor |
| Dynatrace / New Relic / Elastic | Platform tier | Application security modules; Elastic runs a full SIEM |
| Grafana / Sumo / Honeycomb | Specialists | Security analytics adjacency; consolidation candidates |
The convergence mechanics
Traffic crosses this border in both directions. Security buying observability: Palo Alto Networks' acquisition of Embrace (announced July 2026) — real-user monitoring and digital experience monitoring, explicitly not a security product — put observability telemetry inside a security platform (11). Observability buying security: Cisco–Splunk, Cribl–CardinalOps and Cribl–Radiant. Both selling against each other: Datadog's Cloud SIEM competes with Microsoft Sentinel and CrowdStrike NG-SIEM for the same workloads, priced on the same data.
The structural logic is that the SIEM, the observability platform and the pipeline are all bids to own the enterprise telemetry estate, and AI raises the stakes: agentic SOC tooling (04c) is only as good as the data lake underneath it. Whoever owns the lake owns the substrate the agents run on.
A third direction opened in August 2026: the observability layer itself became a documented attack path once AI agents began reading it. Research presented at DEF CON 2026 on Aug 9, 2026 demonstrated that content planted in a web application firewall's block log, in an application-performance-monitoring console reachable through a public front-end key, or in an error-tracking report is read by an AI agent as a genuine finding and acted on with the standing access the agent already holds — with Cloudflare, Datadog and Sentry used as the demonstration cases and the vendors notified in June 2026. The commercial point for this page is that the exposure lives in monitoring and edge-delivery products rather than in a security product, which gives these vendors a security-adjacent control to build or buy on top of a footprint they already hold. The technique and its market consequences are treated on MCP & Agent Identity.
Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.