Hi everyone! 👋 I've been reading through the forum and trying to wrap my head around Sysdig as we're looking at it for some container monitoring and security at my company.
I keep seeing the two main products: Sysdig Monitor and Sysdig Secure. On the surface, they both seem to be looking at my containers and clusters, right? So I'm a bit confused about where one stops and the other begins.
Could someone help break down the real, practical difference? Like, if I'm only using Monitor, what am I missing out on that Secure provides? And if I'm only using Secure, what visibility do I lose?
I'm thinking in terms of everyday use: alerts I might get, dashboards I'd see, or tasks each one is built for. Is it basically "Monitor is for performance, Secure is for vulnerabilities," or is it more blended than that?
Sorry if this is super basic, but the pricing and packaging seem to hinge on this distinction, and I want to make sure I understand it correctly before we go any further. Thanks in advance for any insight you can share!
Hey there, great question and absolutely the right one to ask before looking at pricing. The way I explain it to clients is this: Monitor tells you *if* your system is healthy and performing, Secure tells you *why* it might not be, from a security standpoint.
So with Monitor alone, you'd see metrics on CPU spikes, pod restarts, or network latency. You'd get alerts when a service goes down. But you wouldn't see the alert that the deployment was using a container image with a critical CVE, or that a process inside a container suddenly started making unexpected network calls to a suspicious IP, which is Secure's domain.
The practical gap is like having a dashboard for your car's speed and fuel (Monitor) but no warning lights for a failing brake system or a door left open (Secure). You might be driving fine until you suddenly aren't. They use the same underlying data, but the rules, alerts, and dashboards are built for entirely different teams - Ops vs. Security. Does that help frame the separation?
null
Great analogy from user453, really helped me too. The "if" vs "why" clicked.
I've been testing both in a trial for a small pipeline. One concrete thing I noticed:
Monitor shows me a memory leak alert for my ETL container. Secure shows me that the process suddenly started spawning shell subprocesses and trying to connect to a crypto mining pool IP *before* the memory spike.
So, if you only have Monitor, you know *something* is sick. Secure tells you it has a *specific disease* (and maybe caught it earlier). They're definitely looking at the same runtime data, just asking different questions of it.
Does that track with what you're seeing in your docs?