The Business of Cyber Security

Observability & Data Pipelines

Observability — monitoring application performance, infrastructure health and logs — grew up beside security operations as a separate discipline with a separate buyer (the platform/SRE team rather than the SOC). The two are converging because they run on the same raw material: telemetry. Logs, metrics, traces and events feed both the performance dashboard and the detection rule, and the economics of collecting, routing and storing that telemetry — the per-GB cost problem covered on SecOps & SIEM — are identical on both sides.

The market and its players

Datadog (NASDAQ: DDOG) is the scale reference: $3.43B revenue in 2025, with Q1 2026 revenue of $1.006B, up 32% year over year, and ARR crossing $4B — and a security product line (Cloud SIEM, CSM, application security) built directly on its observability data (Datadog reporting via market coverage). Splunk — acquired by Cisco for $28B (closed March 2024) — is the clearest single statement of convergence: a networking incumbent paying a landmark price for an asset that is simultaneously the most-deployed enterprise SIEM and a major observability platform (Deals). Dynatrace, New Relic (private; Francisco Partners/TPG), Elastic, Grafana Labs, Sumo Logic (private; Francisco Partners) and Honeycomb round out the platform tier — several of them carrying meaningful security revenue.

The strategically distinct layer is the telemetry pipeline: vendors that sit between data sources and destinations, deciding what gets collected, transformed, routed and stored. Cribl is the category leader, and its acquisition of CardinalOps (July 2026) — an AI-native detection-engineering startup — showed a pipeline vendor buying directly into security operations (11). Abstract Security ($25M round, July 2026, ARR up 380%) runs detections in-stream on the pipeline itself. The pipeline layer matters because it is leverage over both markets at once: it can cut a customer's SIEM ingestion bill and re-route the same data into security tooling.

Player Position Security relevance
Datadog Public platform, ~$4B ARR Native SIEM/CSM line; expands from observability into the SOC
Splunk (Cisco) $28B acquisition SIEM + observability in one asset under a networking parent
Cribl Pipeline leader Bought detection engineering (CardinalOps); SIEM-cost disruptor
Dynatrace / New Relic / Elastic Platform tier Application security modules; Elastic runs a full SIEM
Grafana / Sumo / Honeycomb Specialists Security analytics adjacency; consolidation candidates

The convergence mechanics

Traffic crosses this border in both directions. Security buying observability: Palo Alto Networks' acquisition of Embrace (announced July 2026) — real-user monitoring and digital experience monitoring, explicitly not a security product — put observability telemetry inside a security platform (11). Observability buying security: Cisco–Splunk and Cribl–CardinalOps. Both selling against each other: Datadog's Cloud SIEM competes with Microsoft Sentinel and CrowdStrike NG-SIEM for the same workloads, priced on the same data.

The structural logic is that the SIEM, the observability platform and the pipeline are all bids to own the enterprise telemetry estate, and AI raises the stakes: agentic SOC tooling (04c) is only as good as the data lake underneath it. Whoever owns the lake owns the substrate the agents run on.


Updated 2026-08-16 18:47 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.