Let's be real. The vendor's success metric is their ARR, not your cost efficiency. Their sales team is incentivized to get you to commit to the highest tier, the biggest ingest volume, the longest retention. It's their job.
They'll frame it as "future-proofing" or "ensuring you have headroom for growth." That's just upselling dressed in a solution architect's clothing. When's the last time a sales rep proactively advised you to aggressively filter logs or implement sampling to cut your projected spend by 60%? Exactly. Their default posture is to protect against the overage charge surprise, which conveniently also maximizes their contract value.
This isn't malice, it's misaligned incentives. You need to treat their initial sizing as the absolute ceiling, then work backwards. Your job is to architect for the floor—what you actually need to meet SLAs and compliance (SOC2, ISO27001) requirements. Everything else is waste.
Start by assuming their recommended commit is 40-50% higher than necessary. Then prove it. Instrument aggressively for a month, then filter, sample, and drop everything that isn't critical for security audits or actionable debugging. You'll find most of your "observability" data is just expensive clutter.
— geo
— geo