And it is the only category on this site where the bill scales with how much your software is used — data ingested, hosts monitored, events captured, CI minutes burned — rather than with how many people you employ.
Datadog publishes APM per host and logs per GB ingested plus per million events indexed — three meters in one product. A per-user mental model produces a forecast that is wrong by an order of magnitude, which is why the second-year bill is this category’s signature surprise. Three routes below, by the question each answers.
Three routes, by the question each answers. Open the one that matches your situation.
Something is slow or broken and the logs are not telling you why.
Code needs somewhere to live, a way to ship, and licences for the people writing it.
The database is the bottleneck, the risk, or the thing you are migrating off.
Events and audits send people here more often than job descriptions do. If one of these is your week, it already names your route.
The bill doubled and traffic only grew 30%
Observability & APM
A launch is in six weeks and nothing is instrumented
Observability & APM
An Oracle renewal quote arrived and somebody said Postgres
Databases & Data Tools
The database is the bottleneck and nobody can prove which query
Databases & Data Tools
CI minutes cost more last month than the seat licences
Developer Tools
A renewal counts seats nobody has committed code from in a year
Developer Tools
Nobody confuses the definitions. They confuse the pairs. Four overlaps, and the one question that settles each:
Are you asking “is it working” or “were we attacked”?
The same logs, two buyers, two meters. Buy observability and hand it to the security team, and the retention window is weeks when the regulator wants a year. Buy a SIEM to debug a latency problem and you pay security-grade ingest rates for traces nobody correlates. This is the most expensive confusion in the category, and the SIEM route lives on the Security category — cross-linked here, not repeated.
Do you need to know the query was slow, or why the plan changed?
APM traces the request and names the slow query. It rarely tells you that the statistics went stale, an index was dropped, or the plan flipped under a parameter sniff. Buy APM expecting database depth and the DBA still cannot see wait states; buy database monitoring expecting request tracing and you cannot follow a call across services.
Is the problem performance, or exceptions?
Error tracking captures the stack trace, the release and the user affected, at a fraction of APM pricing. Buy full APM when the requirement was “why did that crash” and you pay per host for a per-event problem. Buy error tracking expecting distributed tracing and a slow request across six services has no single owner.
Is the scanning a pipeline concern or a runtime one?
SAST, dependency and secrets scanning sit in the pipeline and are sold inside the SCM platform. Container and cloud posture scanning is CNAPP and is bought separately. Estates buy the SCM tier expecting cloud posture, or buy CNAPP and still ship a hardcoded key — the boundary is the deploy, and the runtime half lives on the Security category.
Compare any two terms
Checks the things you knew to check — dashboards and thresholds you defined in advance.
The Observability & APM boundary section →Answers questions you did NOT write a check for, from high-cardinality telemetry.
The Observability & APM boundary section →The difference
Monitoring checks the things you knew to check: you defined the dashboard and the threshold in advance, so it answers questions you already asked. Observability answers questions you did NOT write a check for — why is this ONE customer slow, on this build, in this region — by keeping high-cardinality telemetry you can slice after the fact. That is not monitoring done better; it is a different cost structure, because keeping the detail is what you pay for.
These are not tiers. Observability is not monitoring done better — it answers questions you never wrote a check for, from telemetry you pay to keep, at a materially different cost. Each route’s guide resolves only the four terms its buyer actually confuses.
Every route here except developer seats meters on volume — hosts monitored, gigabytes ingested, events captured, managed resources, CI minutes. That is why the second-year bill is this category’s signature surprise: the forecast was built on a per-user model that works everywhere else on this site and is wrong by an order of magnitude here. Model at today’s volume, at double, and at ten times before signing anything multi-year.
Prometheus, Grafana, OpenTelemetry, Postgres, Jenkins. Unlike every other category on this site, the open-source path is credible for real production estates — and pretending otherwise loses the engineer reading this in the first screen. It substitutes engineering time for licence cost, which is a real trade with a real owner attached, and it should be made deliberately rather than by default.
Seats plus CI minutes. Ingest plus indexing. Licence plus overage. Platform plus AI assistant. Every product here bills on at least two axes, and the one that breaks the forecast is almost never the one on the quote. Ask what else is metered before comparing any two vendors.
These purchases are triggered by a launch, an outage, a scaling event or a renewal — not by an audit or an incident report. The evaluator will run a proof of concept against real traffic and will not read a datasheet. That is why every page in this category leads with the meter and the failure mode rather than the feature list.
The licence is the small number. Onboarding, implementation and the population nobody governs are the purchase.
Source control is becoming the whole platform — GitHub and GitLab both sell CI, packages, security scanning and planning under one licence, so the question is no longer which SCM but whether you want one vendor or a toolchain. AI assistants are folding into those licences, bundled generously in the trial and itemised at renewal. And observability vendors are absorbing security, selling the same telemetry twice at two meters. Buying two of these today often means buying one thing twice — or discovering at renewal that the bundled thing was never in the contract.
Buy for the seam that is moving, not last year’s org chart — and buy the scope, not the brand.
Almost every buyer in this category already holds part of what they are about to purchase — usually the sign-in half, occasionally the governance half, almost never the machine half.
If the half you need is already on your invoice, we say so. It costs us a sale and saves you one.
Three meters live in this category, and a fourth number under all of them: the project. Which meter you are quoted tells you which route you are in — order of magnitude here, the tier- and term-matched USD + INR number is each guide’s job.
Every product on the guides is mapped by SKU, not by vendor — Splunk’s Observability SKU is carded here while Enterprise Security is carded on the Security category, and Quest and Idera split across two routes on the same principle. JetBrains is carried by TechBag’s sales team and belongs in Developer Tools; it has no intel pages yet, so it is named and not ranked. Its licence unit — per named user or a floating pool — differs materially from the per-seat model everything else here uses. WAF and CNAPP products are cross-linked to Network Security and Security rather than repeated on these guides.
Know your route and want it narrowed to a shortlist? That’s the next page’s job — or ours.
Talk to an advisorVendor-neutral · no gated content
Last reviewed