Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Telemetry intent gap: are unified pipelines hurting security visibility?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Telemetry pipelines optimized for observability can erase adversarial context before security teams need it, according to DataBahn. The real risk is not transport efficiency but using the same retention and compression logic for data that serves different investigative and operational purposes.

NHIMG editorial — based on content published by DataBahn: Why are Legacy SIEMs a problem?

By the numbers:

Questions worth separating out

Q: How should security teams separate observability and security telemetry in practice?

A: Use different policy objectives for each stream.

Q: Why do identity and access logs need longer retention than operational logs?

A: Because their value often emerges only after an incident, not at the moment they were created.

Q: What do security teams get wrong about AI-based log filtering?

A: They assume low recent alert volume means low security value.

Practitioner guidance

  • Separate evidence retention from operational compression Create distinct policy paths for observability data and security telemetry so that authentication events, privilege changes, and other evidence-bearing records are not pruned by the same rules as performance logs.
  • Classify identity events as long-horizon evidence Tag IAM, PAM, NHI, and federated access logs as future-correlation data, then set retention and indexing rules that preserve investigative context even when the event looks low value today.
  • Validate AI filtering against attack reconstruction Test relevance scoring models against multi-stage identity abuse scenarios, including compromised credentials, low-and-slow escalation, and lateral movement, before they are allowed to suppress data.

What's in the full article

DataBahn's full article covers the operational detail this post intentionally leaves for the source:

  • Pipeline design guidance for separating observability retention from security evidence retention
  • Examples of how AI relevance scoring can suppress low-frequency but security-significant telemetry
  • Practical discussion of enrichment timing, pre-SIEM filtering, and cost-control trade-offs
  • The operational distinctions between stream enrichment and enrichment at query time

👉 Read DataBahn's analysis of the telemetry intent gap in unified pipelines →

Telemetry intent gap: are unified pipelines hurting security visibility?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Telemetry intent separation is now a governance requirement, not a pipeline preference. Security teams have spent years trying to reduce cost by converging observability and security pipelines, but the article shows that the shared-infrastructure model only works when optimisation logic is separated. If the same retention policy governs both operational and adversarial telemetry, one of them will lose fidelity. For identity programmes, that loss often appears first in missing authentication context and weak incident reconstruction. Practitioners should treat intent separation as a control boundary, not a tuning choice.

A question worth separating out:

Q: How do you know if a telemetry pipeline is failing security governance?

A: Look for broken event chains, missing identity context, stalled investigations, and a growing need to replay data from cold storage. Those are signs that the pipeline is optimising for efficiency while eroding evidence quality. If analysts cannot reconstruct who did what, when, and under which privilege state, governance has already degraded.

👉 Read our full editorial: Telemetry intent gap is breaking security outcomes in unified pipelines



   
ReplyQuote
Share: