Rendered at 17:35:14 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
jesol 3 minutes ago [-]
Personally I think security is far ahead here compared to normal observability tools. I decided to work on a side-project to try and add SIEM like functionality to a clickhouse backed otel platform; by the end of it the thing I came to believe the tooling blue teams use should be used in observability generally, not just security. Incident/event management is a very powerful concept, and provides a clean framework to hang all of this information on. Then your solution for mechanically finding the neighborhood in k8s is one way to add observations to an event. Some SIEMs have started having agents recommend stuff to be added to an event, which is a nice middle-ground of having agents help but not completely control the discovery and diagnostic effort (as well as providing a clean feedback loop for training data synthesis).
That's all to say, have you considered that framing, and if so, have any opinions on why more general observability tools haven't gone that direction?
That's all to say, have you considered that framing, and if so, have any opinions on why more general observability tools haven't gone that direction?