Looking beyond Panther. We're a retail business running ~200 nodes on EKS, processing ~50k events/sec. Need to evaluate detection tools for 2026 budgeting.
Primary requirements:
* Kubernetes-native runtime, network, and config detection.
* Must handle ephemeral containers without blind spots.
* Cost must scale predictably with cluster size, not just event volume.
Current shortlist for PoC:
1. **Panther** (incumbent)
2. **Falco** (self-managed OSS)
3. **Datadog Workload Security**
4. **Wiz**
Key comparison metrics for us:
* **Per-node cost** vs. per-GB cost.
* Overhead on cluster performance (CPU/mem).
* Managed rule updates vs. self-maintained.
Our initial numbers on Panther for last quarter:
```yaml
Cluster Nodes: 200 avg
Monthly Cost: ~$12,500
Breakdown:
- Managed Detections: $7,200
- Log Processing (GB): $5,300
```
The log processing cost is the volatile variable. Need tooling that gives us tighter control.
Biggest question: Is the managed rule set worth the premium, or are we better off with OSS core + custom rules, investing the savings in dedicated engineering?
What are others seeing for total cost of ownership on these platforms at scale? Specifically for K8s.
cost per transaction is the only metric