Skip to content
Logmetry

Observability data ownership: vendor-hosted vs a lake on Iceberg

Vendor-hosted telemetry is retained on the vendor's terms and read through the vendor's interfaces, while a lake on open table formats holds full-fidelity history that every engine and every model you ever run can read.

What actually differs

The unit each option charges on, and who owns what afterwards, matter more than any single quoted figure.

Vendor-hosted history versus a lake on open table formatsVendor-hosted telemetry lives in the vendor’s cloud on the vendor’s terms: a hot window your tools read, older data aged out because retention is priced to make keeping everything irrational, and egress metered on the way out. A lake on Iceberg holds full-fidelity history for years in your own storage under your keys, on open table formats that any query engine, any model, and the next tool can read.VENDOR-HOSTEDTHEIR CLOUD, THEIR TERMSTHE HOT WINDOWAGED OUT,PRICED AWAYEGRESSRetention priced so keeping everything isirrational, history read through theirinterfaces, egress metered on the way out.A LAKE ON ICEBERGYOUR STORAGE, YOUR KEYSFULL FIDELITY, FOR YEARSANY QUERY ENGINEANY MODELTHE NEXT TOOLComplete history at object-storage cost,on open table formats every engine andevery future model can read.
Who can read your history tomorrow. Vendor hosting keeps a hot window on their terms with egress on the way out, a lake on open table formats keeps everything, readable by every engine and model you ever point at it.

Every platform hosts your telemetry as part of the service, and every platform prices retention so that keeping everything is irrational. The result is an estate whose history is scattered across vendor retention windows, none of it complete, all of it readable only through the interfaces each vendor provides, exportable on each vendor's terms.

The alternative is structural: full-fidelity history in your own object storage, enriched at write time, partitioned the way investigations move, on open table formats with Iceberg as the market's direction. Retention becomes a storage-class decision instead of a licensing negotiation, replay into any destination is a query, and the history is readable by whatever query engine or model comes next. Sourced cells are being assembled row by row.

When each is the right answer

Every option in this comparison is the right answer for somebody, and saying when is the part most comparisons leave out.

Vendor-hosted

The right answer for the hot window: the recent data your detections and dashboards actively read, where the platform's query speed and integrations earn the hosting. The mistake is not hosting data there, it is letting that window define what you keep.

Lake on Iceberg

The right answer for everything else: complete history at object-storage cost, compliance evidence on demand, replay into any tool, and the foundation every AI ambition stands on. Not a replacement for the platforms, the ground beneath them.

Asked about this comparison

Is a telemetry lake a SIEM replacement?

No, and it should never alert. Detection stays on the SIEM, which is built for it. The lake holds the full-fidelity history the SIEM should not have to, serves audits and investigations, and feeds the agents. The two are complements priced for different jobs.

Why do open table formats matter for AI?

Because the model you run next year does not exist yet, and neither does its vendor. History held in a format one vendor controls is readable on that vendor's roadmap. History on open table formats is readable by every engine and every model, which is what makes it a foundation rather than an archive.

Model it against your estate

The comparison that matters is the one run on your volumes and your contracts. The review reads them with you, and you leave with your version of the Logmetry Blueprint. No system access, no obligation.