Observability and security have traditionally been separate IT domains; however, as systems grow more complex and cyberthreats become more sophisticated, leading players such as Cisco, Dynatrace and ServiceNow are merging those two technologies for enhanced threat detection and application security.

Observability is the extent to which the internal states of a system can be inferred from externally available data, according to Dynatrace. It goes beyond monitoring by not just collecting data, but making sense of it. Traditionally, observability has provided three types of data — metrics, logs and traces; now, vendors add in UX, topology information and artificial intelligence (AI) and machine learning (ML) engines.

Analysis firm IDC expects that the observability market will reach $9 billion by 2025 and a recent Cisco survey of 6,700 security leaders across 27 global markets showed only 12% of respondents identified their organizations as “mature” in terms of application security readiness.

Dynatrace CEO Rick McConnell also forecasts “the number of use cases that involve both observability and security is going to explode, so this convergence becomes more and more relevant each day.”

“The observability and security information for application security is really inextricably intertwined,” he told SDxCentral.

One of the use cases is vulnerability tracking and intelligence. For example, when the Apache Log4J (Log4Shell) emerged, the Dynatrace platform offered better insights through its observability data. It not only identified where the vulnerable library call was made in the code, but also tracked how often it was being called, McConnell touted.

Dynatrace also partners with Snyk to combine the security vendor's vulnerability intelligence with Dynatrace's Davis AI-powered monitoring for enhanced DevSecOps. "They're constantly scanning for new vulnerabilities. We then ingest that information and then look for those vulnerabilities in your ecosystem," said McConnell.

He also sees a surge in observability and security convergence use cases including runtime application self-protection (RASP) and security information and event management (SIEM).

Looking ahead, Dynatrace expects its security business to be about $100 million in revenue in three years, McConnell stated. He emphasized that Dynatrace does not view security as an add-on service but as a core aspect of its offering.

ServiceNow extends observability and security convergence to the cloud

As organizations continue to transition to the cloud, end-to-end observability is “essential” for them to succeed, Ben Sigelman, GM of cloud observability at ServiceNow, noted, adding “observability and security are two sides of the same coin.”

“Organizations are building and running millions of new customer-facing apps and services in the cloud, making it more difficult to find and extract the right data to monitor and manage performance using traditional IT monitoring tools,” he told SDxCentral in response to questions.

The vendor today unveiled ServiceNow Cloud Observability (based on its Lightstep acquisition in 2021) to help organizations manage the hybrid cloud. The solution combines logs, metrics and traces for better security, workflows, experience and return on investment.

“The convergence of observability and security in the cloud is being driven by the complexity and distributed nature of modern cloud architectures, which makes it hard for organizations to continuously monitor and ensure that their cloud applications are secure and performing as expected,” Sigelman explained.

Pairing the precise data with security tools “allows organizations to identify anomalies and other security issues, which security solutions can then use to resolve incidents automatically and often before they even occur,” he added.

Cisco’s integration strategy

Cisco in 2021 integrated its AppDynamics acquisition into its application security portfolio to help developers and security teams detect vulnerabilities in production and automatically block attacks.

“It’s an opportunity to bring the security operations people together with application developers,” former AppDynamics CTO Ty Amell told SDxCentral in an earlier interview. “It lets them see in real time any vulnerabilities in the application and takes that a step further to remediate and block those exploits from happening.”

Earlier this year, Cisco rolled out its Business Risk Observability risk scoring service, which combines its Kenna Risk Meter score distribution with AppDynamics’ business transitions monitoring and insights. The service also has API and application security capabilities based on Cisco's Portshift acquisition, and s supported by the Talos team’s threat intelligence.

Most recently, the vendor updated its Full Stack Observability (FSO) strategy, designed to help enable Customer Digital Experience Monitoring. The strategy provides enhanced integration of application observability via Cisco AppDynamics and network intelligence via Cisco ThousandEyes. 

SVP and GM of Cisco’s Security Business Group Tom Gillis told SDxCentral in an earlier interview the observability and security capability integration is “a perfect example” of Cisco's security business leveraging components from across the company.