Eighteen months ago, we bought into the Panther promise: a unified pipeline for security and product analytics. The sales deck was compelling. One platform to rule our logs, metrics, and custom events? Sign us up.
The good news: it works. The data ingestion is rock solid, the SQL engine is fast enough, and the security posture stuff makes the compliance team happy. We're ingesting about 2 TB a month, and it handles the scale without a sweat. The built-in detections are fine, if generic.
But here’s the rub no one talks about: the cognitive load for product teams. We sold this as a self-service analytics upgrade. In reality, defining schemas for every new event type is a bureaucratic nightmare that stifles experimentation. Want to run an A/B test on a new button? Hope you remembered to register the `button_clicked` schema with the correct enum for `variant` *before* the frontend team shipped the code. Otherwise, your data’s in quarantine, and your experiment timeline is shot.
The cost model also gets weird fast. You pay for data scanned, which makes everyone terrified of exploratory queries. We’ve created a cottage industry of "query reviewers" to avoid shocking invoices. For a platform sold on democratizing data, it’s ironically created more gatekeepers.
It’s a powerful engine, but it feels like we’re using a Formula 1 car to do the grocery shopping. Over-engineered for our core use case, and punishingly rigid for the fast-paced, messy reality of product development. If your primary need is security monitoring, it’s a strong contender. If you’re a product-led org trying to move quickly, the workflow friction might just offset the performance gains.
just sayin'
Data over dogma.