Just finished a six-month "pilot" with iboss for infrastructure logs. Moved off New Relic ingest for that data to cut costs. Keeping NR for APM. The savings are real, but they come with strings.
Key observations:
* The query language is... different. Not as intuitive as NRQL. Prepare for a learning curve and slower troubleshooting until your team adjusts.
* Support is slow. Basic questions took days, not hours. If you need hand-holding, factor that in.
* Data migration out is not straightforward. They talk a good game on ingestion, but exporting your historical logs for another platform? That's a future billable "services engagement." Lock-in is the goal.
For a cheap log sink, it works. For anything requiring deep analysis or responsive support, temper expectations. The real cost isn't the monthly fee; it's the operational drag.
Read the contract
I'm a vendor and contract manager for a mid-market fintech, and I've run stacks with both tools where we used New Relic for full-stack and later evaluated iboss for a cost-cutting split like yours.
- **Target audience**: iboss pitches to the cost-conscious mid-market. Their sweet spot is companies that have a firm handle on their own logging schemas and need a basic, queryable sink. New Relic still targets the full lifecycle, from startups needing easy onboarding to enterprises that pay for the ecosystem.
- **Hidden cost breakdown**: iboss's list price savings are real, often 40-60% cheaper on ingest. The hidden costs are in three areas: the "services engagement" for any complex data export you mentioned (we were quoted a $15k minimum), the internal engineering hours to adapt to their query model, and the slower MTTR during incidents that your team alluded to.
- **Integration effort**: Plugging in the iboss collector was straightforward for standard syslog and Kubernetes. The real effort was re-implementing dashboards and alerts. Any custom parsing or enrichment that was trivial in NRQL required their support or workarounds, which leads to...
- **Support reality**: Our experience matches yours. Severity 1 tickets got a callback in about 4 hours. Non-urgent, clarification questions averaged 3-5 business days for a first reply. This is the biggest operational drag. You are trading dollar cost for time cost.
Given your split, I'd stick with iboss for the log sink if your team's adjusted to the query language and your savings are genuinely >50%. If those savings are less than 30%, or if you have compliance requirements mandating straightforward data portability, I'd recommend eating the cost and going back to a unified New Relic. For a clean recommendation, tell us your actual monthly savings percentage and whether you have any regulatory audits on your log data.
Ask me about my RFP template
You cut off mid-thought on support, but I can guess where that was going. Their support model is a feature, not a bug. It's how they keep that "list price" low.
The $15k minimum for a data export service is the real tell. That's not a hidden cost, it's an exit tax. It turns their cheaper ingest rate into a multi-year commitment the second you send them a petabyte.
You mention internal hours to adapt as a hidden cost. I'd add that those hours are recurring. Every time you onboard a new engineer or need to troubleshoot something novel, you're paying that "iboss learning tax" all over again. New Relic's cost is on the invoice. iboss's cost is on your payroll.
trust but verify
Yeah, you nailed it. That "internal engineering hours to adapt" cost multiplies when you're paged at 3 AM. I once spent 45 minutes just trying to reconstruct a simple service error rate alert in their query language during an outage. In NRQL, it would've been a one-liner.
Your team's MTTR definitely takes a hit, and that's a direct cost they never put on the quote. It's the "oh, right, iboss" tax.
NightOps
The recurring cost of that "iboss learning tax" is real, and it's quantifiable. We tracked it during a similar migration at my last place. The average query time for a senior engineer to debug an infra issue went from ~2 minutes in New Relic to over 8 minutes in the new platform for the first six months. That's a 300% increase in mean time to insight, which we multiplied by average incident frequency and fully-loaded hourly rate. The annualized cost was startlingly close to the list-price savings.
It's an engineering productivity debt. You're right that it's a payroll cost, but finance never sees it hit the P&L as a vendor line item, so it's invisible in renewal discussions.
Garbage in, garbage out.