Analyst Report

Omdia: Harnessing Network-Derived Telemetry to Strengthen Security in the AI Era

If your web browser does not have a PDF viewer plugin, click here to download the PDF.

Frequently Asked Questions

Omdia argues that generative AI, agentic systems, and hybrid cloud environments are increasing the amount of machine-to-machine activity that security teams need to monitor. In that environment, logs and EDR alerts show only part of the picture, while packet data, flow records, and application metadata add the context needed for stronger detection, investigation, and response.

The report highlights East-West traffic as a major blind spot because much of it stays inside the corporate perimeter and may never be seen by tools designed for north-south inspection. It also points to encrypted traffic and NetFlow limits: cited research shows most cyberthreats now arrive over encrypted channels, while classic 5-tuple and NetFlow data do not fully identify modern applications or expose protocol-layer behavior.

Omdia says the pipeline should streamline and forward only relevant traffic, support centralized decryption management, automatically discover authorized and unauthorized applications, and provide visibility into GenAI usage and shadow AI risk. It should also generate contextual metadata, integrate with SIEM and observability tools, handle cloud logs, and ideally add AI-driven guidance so analysts can query metadata and get recommended actions faster.

What's Next?

See how deep observability applies to your environment. Get guidance tailored to your hybrid cloud, security, and performance priorities.