Fig + Cribl: Modernizing the SOC without compromising your coverage
Fig and Cribl are partnering to help security teams modernize their telemetry stack without compromising detection coverage.
Blog
Cribl gives security teams an AI-native platform for telemetry. You get control over routing, cost, and data movement across a changing security stack. In joint environments. Fig keeps detection and response in sync with telemetry changes during migration and optimization, ensuring continuous security operations resilience.
Detection rules rely on data, and that data changes constantly. Telemetry keeps growing, and the systems producing that data change on their own schedules, without letting anyone downstream know.
When the data behind a rule changes shape, a vendor updates a log schema, IT upgrades a forwarder upstream, the rule keeps running but no longer matches what it’s reading. Rules don’t raise alerts, so they keep saying “covered” even though they’re not catching anything anymore. This is drift, and it’s everywhere.
When we first connect to an environment, we typically find about a quarter of detection logic running on data that changed upstream without anyone in the SOC knowing.
That’s where Fig comes in for joint clients. Our security data lineage engine maps how data flows from each source, through pipeline and parser to downstream detections. When something changes upstream, we trace it to the detections it affects and show you the impact. Beyond highlighting the issue and its root cause along the data lineage, Fig drafts a fix and runs a full CI/CD cycle to safely test and deploy it. This ensures your detection and response remain resilient throughout the migration.
Cribl addresses the problem even further upstream, providing control over the data itself. As the AI Platform for Telemetry, Cribl lets you collect your telemetry once and routes any source to any destination. You can reshape, reduce, and route it along the way, without lock-in to a single SIEM or lake.
With Cribl, you can decide where your data goes and what shape it takes. Fig adds visibility into how those telemetry decisions may affect downstream detections. Together, we help teams modernize with more confidence and clearer dependency visibility.
Understand change impact earlier
As teams modernize telemetry, they need a clearer view of downstream dependencies before changes hit production. Fig helps highlight which detections may be affected as sources, parsers, and pipelines change, so teams can focus validation where it matters most.
Migrate with more confidence
When you move to a new SIEM, Cribl normalizes and reshapes your existing sources into the new environment alongside the old one, so there’s no rip-and-replace. Fig checks that every detection fires on the new data before you cut over and tells you which ones wouldn’t, and Figaro rewrites those as code for the new platform. A migration that used to take years and leave you guessing about coverage now takes weeks, and you see the coverage before you commit.
Lower cost, clearer dependency visibility
Lowering SIEM spend means sending and storing less data in the SIEM. Cribl filters and reroutes less critical logs to cheaper datalakes instead. Before you cut a source, Fig shows you which detections depend on it, so you know what you can drop without losing coverage.
Build on an AI-native data foundation
AI outcomes depend on the telemetry underneath them. If a detection is silently broken, an agent won’t notice. It runs the broken logic faster and across more of your environment. Cribl helps you manage telemetry for people and agents at scale, keeping you in control even across a changing security stack. In joint environments, Fig keeps the detections and response logic underneath them accurate and adds visibility into how telemetry changes affect the detections and queryable data that both humans and AI agents rely on.
Get started
To learn more, watch our LinkedIn Live here. And if you’ll be at Black Hat Vegas 2026, join Fig and Cribl at our House of SOC.