Your telemetry lands enriched in a Lake you own. Your Agent investigates every alert on it.
Collected by open collectors nobody licenses, stored at object-storage prices, enriched with context on the way in. The Agent runs in your account on open-weight models you swap, follows runbooks you write, and picks up the alert whichever tool fired it. Your expensive tools receive only what earns its place, everything as code, at a fraction of the cost.
No system access. No obligation. You leave with your stack, drawn.
We are telemetry engineers, and the problems we solve are business problems.
01What you run
What do you run today?
Pick the platform you already run and see exactly what we do to it: keep it and govern it, shrink its footprint, cut what it costs, extend it with an agent, or replace it only where replacement is honest. We are there to maximize what your platforms give you, and we are never necessary: when you want out of a rented capability, we build it as custom code you own, at a fraction of the cost. Either way, you are in control of your telemetry.
02The landscape
The landscape, untangled
SIEM, APM, infrastructure monitoring, observability pipeline, and lake are five different jobs, and no single vendor is the honest answer to all five. Their goal is to consolidate you and lock you in: once they hold all your data, the extra modules are oversold at a price you no longer control.
You run one of the common SIEMs or APMs and the bill climbs every year. Around it, five categories of tool compete for the same budget, and every vendor now claims to cover all five. Everyone else rents you the pane of glass over their agent, and what you see in it is what they chose to show.
The honest design underneath is one machine: collect once, shape in flight, route by value. Your most critical apps keep the tools that are genuinely great at them, and everything else, traces, metrics, and logs together, lands correlated in the Lake for your Agent to read. That is the future of observability: agentic, and on ground you own.
What deserves to stay
The SIEM your detections live in earns its place, and so does the APM, for deep traces on the crown jewel apps. We govern what flows in and we never replace them: what reaches them is cleaned, critical, and actually fires, so detection coverage grows from a fraction of the volume. And the landscape is changing: triage and root cause analysis now run on the Lake, with the Agent picking the model for each task.
What deserves to shrink
Per-GB ingest into the SIEM, and per-host licences on ordinary hosts that need infrastructure monitoring, not deep tracing. In most environments 50-80% of what flows in never earns its analytics-tier price. The rest collects cheaply over OpenTelemetry and lands in the Lake, correlated by your Agent on demand.
What you can own in code
Collection, routing, the metric store on an open source time series database with its rules and alerts, the fleet management console, and the AI agent with its runbooks and playbooks, in your account. The most expensive features of the big platforms, rebuilt as code the client owns.
03The Logmetry Blueprint
The future of observability, in three phases
The Logmetry Blueprint is a staged reference design where every phase makes you more vendor agnostic and solves a business problem. It starts with a collection foundation you own, because once collection is open you are truly vendor agnostic, and everything else follows from it. A smaller footprint comes second: the tiers and analytics you were locked into, consolidated and repriced year after year, rebuilt as custom systems at a fraction of the cost. An investigating agent comes third, and it is where observability is going: an AI agent in your account, reviewing and triaging everything on the cleaned, enriched Lake you own. Every later phase is optional.
Foundation
One open collection layer, a control layer deciding what each destination gets, and a full-fidelity Lake you own.
OpenTelemetry collectors nobody licenses on every host, a fleet controlled as code, and pipelines that send each platform only what it needs. Everything lands in your repositories.
A valid place to stop
Footprint
The expensive tools shrink to what earns its place. Infrastructure monitoring is rebuilt in code on an open source time series database you own, every alert proven at full parity, in writing, first.
Every alert and every rule is rebuilt and proven to behave exactly as it does today, tier by tier, before a single host comes off per-node pricing. Crown-jewel tracing stays where it earns its price.
AI triage
An agent you own investigates every alert your tools already fire, reading your enriched, cleaned Lake for full correlation. This is the foundation of the future of observability.
The agent starts on the alerts your current tools already fire, so value lands before anything moves. Playbooks written around your environment get sharper with every investigation, and the platforms we rebuild fire the same alerts into the same agent.
04Ownership
What you own after
After a complete engagement you own everything we built: the collectors, the fleet plane, the pipelines, the routing, the Lake, the playbooks, and the Agent, all as code in your repositories, and the IP with it.
- The CollectorsOpenTelemetry on every host. Nobody licenses them. Collection is now vendor agnostic.
- The PipelinesReal telemetry pipelines: every shaping, reduction, transformation, and enrichment decision, in code.
- The RoutingEach destination gets only what it earns, the SIEM especially. Everything else lands in the Lake, and swapping a vendor is a routing change.
- The LakeFull fidelity, enriched, partitioned for retrieval. Queryable like a database, by engines, agents, and humans, at a fraction of the cost.
- The ConsoleThe fleet management plane, in code, built for you to own. No vendor rents it to you.
- The PlaybooksHow your environment works and how you triage, written for the agent, so alerts get investigated and resolved on demand.
- The AgentInvestigating every alert from the SIEM, the APM, or the infrastructure monitoring platform, on models you swap and control: a cheap model for quick questions and compliance queries, a stronger one for investigations and anomaly detection. It follows your playbooks and runbooks, works on the Lake, and reaches back into the SIEM and the APM over MCP when it needs their context. This is the future of observability: an AI agent that is not a vendor’s, but your own.
This is what vendor agnostic means: any destination, and any vendor, is a routing change. And it is where observability is going: triage and root cause analysis on the Lake, run by AI agents you own. We make ourselves as replaceable as we make your vendors, and we stay until your team is ready to take over. The build survives its builders.
05The engagement
How an engagement actually starts
An engagement starts with a review of your diagrams that costs nothing and ends with your version of the Logmetry Blueprint drawn on your stack. We are there to solve a business problem, whether it is cost, visibility, AI, or vendor independence: we map your current architecture and where the gaps sit, because telemetry is an expensive budget line, complex, and crucial. Observability and security both run on it, and we are the telemetry engineers who orchestrate it.
01 · No charge
Architecture review
You share your diagrams and we review them with you in a session. You leave with where the cost sits, the direction we would take, and your version of the Logmetry Blueprint drawn on your architecture and your stack. No system access, no obligation.
02 · Fixed fee
Discovery
Scoped to what you asked for, never the whole estate by default. You own the output: a scoped plan with every project priced.
03 · Fixed price
Projects
Each project is quoted after discovery against your estate, with acceptance criteria in writing and a defined remedy if they are missed. Everything lands as code in your repositories, and when the work calls for it, we are also available hourly or on retainer.
04 · Retainer by choice
Operate, then graduate
We run what we built until your administrators do, and we teach them: everything is code in your repositories, so your operators can work on it with a coding assistant in plain English. The retainer stays because you want it, not because you need it. The exit is designed in, which is why clients stay.
06Questions
Asked on every first call
The four questions every verifying buyer asks, answered the way we answer them on a call.
Do you replace our SIEM?
No. Logmetry is a control layer in front of your SIEM, your APM, and your monitoring platforms, never a replacement for any of them. Your detections keep running where they run today, and they improve: data lands enriched and cleaned, so alerts that never fired start firing, detection coverage grows, and ingest into the expensive tier typically drops 40-70%. The exception we do build is infrastructure monitoring, where ordinary checks deserve a custom in-house metric store on an open source time series database instead of an analytics-tier price. And because the control layer sits in front, swapping a SIEM or an APM becomes a routing change and a migration in weeks, not months stuck in a licence. On top of it all, the Agent adds AI triage reading the Lake, a new kind of observability.
What does the architecture review cost?
Nothing. You share your diagrams, we talk through what you run and what concerns you, and we draw your version of the Logmetry Blueprint on the spot: what is happening, where it hurts the most, and what we would suggest. It is shaped by what you asked for, nothing more, because we are consultants before anything else. No system access, no obligation.
What do we actually own afterwards?
Everything we build. The collection layer, re-instrumented on open-source OpenTelemetry. The observability pipelines that clean your telemetry and cut the garbage headed for the expensive platforms, routing everything into your own account. The fleet management console, the grip that kept estates on vendor agents, built for you instead. The playbooks your Agent runs on. And if you choose it, infrastructure monitoring rebuilt custom in-house, an open source time series database you own firing the same exact alerts. All of it is code in your repositories. We onboard and teach your staff, and we make ourselves as replaceable as we make your vendors, because the build survives its builders.
How are engagements priced?
The builds are fixed projects: a fleet management console, or an infrastructure monitoring rebuild off a platform like SolarWinds, is quoted after discovery against your estate, with acceptance criteria in writing. The review costs nothing and discovery is a fixed fee. Where consulting is what you need, we work hourly or on retainer. There is no list price, because the price follows the estate.
07AI native
The future is agentic, and you own it
Everything we build lands as code, which turns operations into something an Agent can work: the alert is investigated on the Lake, the fix arrives as a pull request, a person approves it, and the merge updates the estate. That is agentic remediation, and it only exists on an estate held as code.
The Agent starts on the alerts your tools already fire and investigates them on the Lake. Its findings and hypothesis land in the ServiceNow ticket your desk already opened, and when it is confident the fix is right, it writes the correction and opens a pull request linked into that same ticket, the same way your engineers do. When it is not confident, the findings still land and a person takes over. Either way a person reviews the diff, and nothing ships without that approval.
The same readable estate answers questions, too. Your operators ask a coding assistant what is running, what changed, and why, in plain English, and the answer comes out of the files instead of out of whoever set it up. Read what AI native means →
08The journal
Latest from the journal
The journal is where we publish the teardowns and the economics we run for ourselves, with original charts in every piece.
Architecture · 2026-04-30
How Cribl Pipelines Move from the UI to Git: The Terraform Path to Pipeline-as-Code, AI-Assisted Maintenance, and DR You Can Actually Run
Most platform engineering teams went GitOps for everything in the 2020s. Observability tends to be the last UI-driven holdout, with pipeline configuration, parsers, detection rules, and routing logic still living inside vendor consoles with no diff history, no test suite, and no automated rollback. The Cribl Terraform provider plus Cribl's Git-backed worker groups close that gap. Here is how Cribl pipelines move from the UI to Git in production, why the Terraform provider is the load-bearing piece, how AI coding assistants become useful for pipeline maintenance once configuration is declarative, what disaster recovery looks like as a terraform apply instead of a manual rebuild, and the test layers that let detection engineering catch pipeline regressions before they reach production.
Analysis · 2026-04-29
Why Companies Are Buying Observability Pipelines Without a Cost Problem
More 2026 Cribl deployments now start without acute cost pressure. Companies are adopting the pipeline as insurance against the next SIEM migration, destination swap, or compliance ask. Here is what the new buying motive looks like, why teams like Yale New Haven Health moved 30,000 endpoints to Sentinel in two weeks because of it, and why pipeline insurance is reshaping how observability stacks get built in 2026.
Economics · 2026-04-28
Anatomy of a Two-Week SIEM Migration: Why the License Overlap Math Has Quietly Changed
Yale New Haven Health moved 30,000 endpoints onto Microsoft Sentinel in two weeks. Most teams still plan a SIEM migration as a 9-month, $350K project with a 30 percent failure rate. The cost story underneath is what most CFOs miss: the dual-license window where two SIEMs are paid for at once, which has historically run 3 to 9 months and consumed roughly half to three quarters of one year of the old SIEM's run-rate. Here is the license overlap math that has quietly changed under a pipeline-led architecture, why the conventional dual-license window collapses to days, and what to negotiate with the old and new vendors before the contract is signed.