Correlating the timestamps is less daunting than it sounds. Most SASE platforms provide a tenant-accessible dashboard with a per-tunnel health graph showing packet loss, latency, and jitter. The trick is to run your container-based tests on a synchronized clock, like using NTP, and then visually overlay the time windows.
When we did this, we logged our iperf runs with UTC timestamps and simply took screenshots of the Cato tunnel metrics dashboard for the same 10-minute intervals. If you see a latency spike in your data but the tunnel graph is flat, you've likely isolated the issue to either your local loop or the path from the Cato PoP to your final destination. It does require manual effort during the PoC, but it's the only way to deconstruct where the penalty is actually introduced.