Logz.io Adds Trivy Scanning Tool to Kubernetes Observability Platform

Logz.io today extended the reach of its observability platform for Kubernetes environments to now include the Trivy tool for discovering issues with open source software packages and dependencies, infrastructure-as-code (IaC) issues and misconfigurations and known common vulnerabilities and exposures (CVEs).

Asaf Yigal, Logz.io CTO, says adding Trivy to the company’s open source Kubernetes 360 observability platform will enable organizations to further their efforts to adopt DevSecOps best practices. The Kubernetes 360 platform already includes a security information event management (SIEM) platform to analyze security data.

Logz.io has been making a case for an observability platform that aggregates curated instances of open source monitoring and analytics tools such as Prometheus to provide IT teams with the tools required to correlate events across complex cloud-native application environments deployed on top of Kubernetes clusters.

It’s not clear whether IT teams are embracing observability to go beyond simply monitoring a set of pre-defined metrics. However, as modern cloud-native application environments become more challenging to manage, there is clearly a need for tools that enable IT teams to proactively investigate anomalies that indicate the potential for a major disruption. In effect, adoption of cloud-native applications is driving organizations to instrument applications so they can use queries to investigate issues to prevent a major disruption from occurring in the first place. Most recently, Logz.io went a step further by integrating the Chat GPT generative artificial intelligence (AI) platform with its observability portfolio to make it easier to surface recommendations to resolve issues.

The integration of Trivy into the Logz.io platform extends that capability to include the results of scans conducted using an open source scanning tool, notes Yigal. That’s critical because, the mean-time-to-remediation (MTTR) of vulnerabilities in cloud-native application environments has been increasing as organizations embrace Kubernetes, he adds.

There is, of course, no shortage of observability platforms, but Logz.io is betting as cloud-native applications become more complex, the first place IT teams will look to apply these platforms will be in these application scenarios. In contrast, legacy monolithic applications today are, in most cases, being adequately served by legacy application performance management (APM) platforms that track pre-configured metrics.

Regardless of the approach to observability, it’s clear there will soon come a day when IT teams will not want to manage application environments without the capabilities these DevOps tools provide. The level of stress would be too great otherwise, as IT teams try to determine, for example, the root cause of application performance degradation. In the longer term, machine learning algorithms will proactively surface issues without requiring IT teams to know what queries to launch.

In the meantime, the federation of application performance and cybersecurity observability is now underway. The only thing left to be determined is how IT and cybersecurity teams will be organized once it becomes apparent that both teams are working from the same centralized pool of data resources.

Mike Vizard

Mike Vizard is a veteran IT journalist with more than 25 years of experience covering the technology industry, having previously served as Editor-in-Chief of both CRN and InfoWorld and as editorial director for Ziff-Davis Enterprise, where he oversaw titles including eWEEK, CIO Insight and Baseline. Over his career he has also edited or contributed to a wide range of enterprise technology publications, including IT Business Edge, Channel Insider, ComputerWorld, TMCNet and Digital Review, and he later led editorial for CTOEdge.com. His reporting and analysis span software development, cloud computing, cybersecurity, IT channel strategy and, more recently, artificial intelligence and DevOps practices. A recognized voice in enterprise IT journalism, Vizard is known for tracking emerging technology trends as they move from early adoption into mainstream enterprise use. He now serves as Chief Content Officer for Techstrong Group, where he oversees editorial strategy across the full network — DevOps.com, Security Boulevard, Cloud Native Now, Digital CxO, Techstrong.ai, TechStrong.IT, Techstrong Semi and PlatformEngineering.com — in addition to writing and hosting content for Techstrong TV and the Techstrong Gang podcast.

    Mike Vizard has 1813 posts and counting. See all posts by Mike Vizard