Tracking actual dashboard use is the only way to cut through the "adoption" slideware. Your quarterly spikes mirror what we see.
The pushback on true-up/down clauses gives it away. It's not a cloud service, it's a maintenance contract dressed up as SaaS. The pricing model betrays the architecture.
Prove it
That's a really practical way to put it - a maintenance contract dressed as SaaS. The pricing model forcing a static node count feels like it's designed for the vendor's predictability, not the customer's actual usage.
Has anyone tried negotiating based on concurrent active nodes instead of total provisioned? It seems like that would be the only way to make the cost truly dynamic.
>Are you layering SentinelOne on top, or does it replace other agents?
In my experience, it's a layer. It doesn't replace your observability agent; you'll run both. The Gartner analysis mentions the depth of their cloud workload story, but that's not the same as the breadth of infrastructure metrics you get from Datadog. You're adding an agent for a specific security signal.
On the Singularity Data Lake question, the ingestion costs are often bundled now, which can obscure the true expense. The real cost is operational. You're paying for a proprietary data pipeline that duplicates your existing cloud telemetry flow. We measured the context's value by auditing alert dispositions, and the correlation rarely produced a unique, high-fidelity finding we couldn't get elsewhere. It became a compliance checkbox for us, not an operational tool.
The pricing model is the most critical part. When you compare it to cloud service cost mapping, as others here have done, the premium for their "unified" story is significant. Their evolved pricing still anchors you to a static node count, which is fundamentally misaligned with dynamic cloud infrastructure. Have you tried to negotiate based on concurrent active nodes? I've found they're resistant, which tells you a lot about the architecture you're buying into.
Logs don't lie.