The journal
Teardowns, playbooks, and the economics of telemetry
The journal is where we publish the analysis we run for ourselves: how platforms store and charge for telemetry, what migrations actually cost, and what ownership changes.
14 pieces
Architecture · 2026-04-30Latest
How Cribl Pipelines Move from the UI to Git: The Terraform Path to Pipeline-as-Code, AI-Assisted Maintenance, and DR You Can Actually Run
Most platform engineering teams went GitOps for everything in the 2020s. Observability tends to be the last UI-driven holdout, with pipeline configuration, parsers, detection rules, and routing logic still living inside vendor consoles with no diff history, no test suite, and no automated rollback. The Cribl Terraform provider plus Cribl's Git-backed worker groups close that gap. Here is how Cribl pipelines move from the UI to Git in production, why the Terraform provider is the load-bearing piece, how AI coding assistants become useful for pipeline maintenance once configuration is declarative, what disaster recovery looks like as a terraform apply instead of a manual rebuild, and the test layers that let detection engineering catch pipeline regressions before they reach production.
cribl · cribl-terraform-provider · pipeline-as-code
Most platform engineering teams went GitOps for everything in the 2020s. Observability tends to be the last UI-driven holdout, with pipeline configuration, parsers, detection rules, and routing logic still living inside vendor consoles with no diff history, no test suite, and no automated rollback. The Cribl Terraform provider plus Cribl's Git-backed worker groups close that gap. Here is how Cribl pipelines move from the UI to Git in production, why the Terraform provider is the load-bearing piece, how AI coding assistants become useful for pipeline maintenance once configuration is declarative, what disaster recovery looks like as a terraform apply instead of a manual rebuild, and the test layers that let detection engineering catch pipeline regressions before they reach production.
Read the piece →
Analysis · 2026-04-29
Why Companies Are Buying Observability Pipelines Without a Cost Problem
More 2026 Cribl deployments now start without acute cost pressure. Companies are adopting the pipeline as insurance against the next SIEM migration, destination swap, or compliance ask. Here is what the new buying motive looks like, why teams like Yale New Haven Health moved 30,000 endpoints to Sentinel in two weeks because of it, and why pipeline insurance is reshaping how observability stacks get built in 2026.
cribl · pipeline-insurance · observability
More 2026 Cribl deployments now start without acute cost pressure. Companies are adopting the pipeline as insurance against the next SIEM migration, destination swap, or compliance ask. Here is what the new buying motive looks like, why teams like Yale New Haven Health moved 30,000 endpoints to Sentinel in two weeks because of it, and why pipeline insurance is reshaping how observability stacks get built in 2026.
Read the piece →
Economics · 2026-04-28
Anatomy of a Two-Week SIEM Migration: Why the License Overlap Math Has Quietly Changed
Yale New Haven Health moved 30,000 endpoints onto Microsoft Sentinel in two weeks. Most teams still plan a SIEM migration as a 9-month, $350K project with a 30 percent failure rate. The cost story underneath is what most CFOs miss: the dual-license window where two SIEMs are paid for at once, which has historically run 3 to 9 months and consumed roughly half to three quarters of one year of the old SIEM's run-rate. Here is the license overlap math that has quietly changed under a pipeline-led architecture, why the conventional dual-license window collapses to days, and what to negotiate with the old and new vendors before the contract is signed.
siem-migration · cribl · license-overlap
Yale New Haven Health moved 30,000 endpoints onto Microsoft Sentinel in two weeks. Most teams still plan a SIEM migration as a 9-month, $350K project with a 30 percent failure rate. The cost story underneath is what most CFOs miss: the dual-license window where two SIEMs are paid for at once, which has historically run 3 to 9 months and consumed roughly half to three quarters of one year of the old SIEM's run-rate. Here is the license overlap math that has quietly changed under a pipeline-led architecture, why the conventional dual-license window collapses to days, and what to negotiate with the old and new vendors before the contract is signed.
Read the piece →
Analysis · 2026-04-23
Cyber Insurance SIEM Requirements: What Carriers Actually Ask For, and Why Most MSPs Cannot Produce It
Cyber insurance applications run 20+ pages and specifically require SIEM logs, MFA evidence, and centralized logging as conditions of coverage. Missing MFA is the #1 reason claims are denied. Here is what carriers really ask for, why most MSPs cannot produce the evidence across 76 tools, and the pipeline architecture that answers a 48-hour audit without scrambling.
cyber-insurance · siem · compliance
Cyber insurance applications run 20+ pages and specifically require SIEM logs, MFA evidence, and centralized logging as conditions of coverage. Missing MFA is the #1 reason claims are denied. Here is what carriers really ask for, why most MSPs cannot produce the evidence across 76 tools, and the pipeline architecture that answers a 48-hour audit without scrambling.
Read the piece →
Architecture · 2026-04-22
Cribl Reduction Is Not Data Loss. It Is a Replay Strategy Your SIEM Cannot Offer.
Cutting 40 to 70 percent of SIEM ingest does not mean dropping logs. It means reducing what hits the expensive tier while full-fidelity data streams to cold storage at 1/10th to 1/120th the cost. Here is how replay-from-archive works, why it is architecturally different from SIEM archive tiers, and what it looks like during a real incident.
cribl · reduction · replay
Cutting 40 to 70 percent of SIEM ingest does not mean dropping logs. It means reducing what hits the expensive tier while full-fidelity data streams to cold storage at 1/10th to 1/120th the cost. Here is how replay-from-archive works, why it is architecturally different from SIEM archive tiers, and what it looks like during a real incident.
Read the piece →
Analysis · 2026-04-21
The Alert Fatigue Crisis: Why 90 Percent of Your Alerts Are False Positives (And What To Do About It)
The average SOC processes 4,484 alerts a day and up to 90 percent of them are false positives. Industry-wide that costs $3.3B a year in wasted triage. Here is why in-SIEM tuning never closes the gap and what a pipeline-layer fix actually changes.
alert-fatigue · false-positives · soc
The average SOC processes 4,484 alerts a day and up to 90 percent of them are false positives. Industry-wide that costs $3.3B a year in wasted triage. Here is why in-SIEM tuning never closes the gap and what a pipeline-layer fix actually changes.
Read the piece →
Economics · 2026-04-17
Firewall Allow Logs: Why You're Paying Splunk $500K/Year for Data Nobody Searches
Firewall allow logs are 60 to 70 percent of Splunk ingest in most environments. Detection rules do not fire on them. Analysts do not query them. Here is the routing architecture that sends them to S3 for a fraction of the cost while keeping your compliance archive intact.
splunk · firewall-logs · cost-reduction
Firewall allow logs are 60 to 70 percent of Splunk ingest in most environments. Detection rules do not fire on them. Analysts do not query them. Here is the routing architecture that sends them to S3 for a fraction of the cost while keeping your compliance archive intact.
Read the piece →
Playbook · 2026-04-16
SIEM Migration Without the 9-Month Disaster: A Cribl-Based Playbook
SIEM migrations take a 9-month median, cost $350K, and fail 30 percent of the time. Here is how a Cribl routing layer cuts that to three to six months with zero compliance gap, zero double-licensing, and per-source validation.
siem-migration · cribl · parallel-routing
SIEM migrations take a 9-month median, cost $350K, and fail 30 percent of the time. Here is how a Cribl routing layer cuts that to three to six months with zero compliance gap, zero double-licensing, and per-source validation.
Read the piece →
Economics · 2026-04-15
Datadog Bill Shock: Why You Are Paying Twice (And How To Stop)
Datadog charges you to ingest logs and again to index them. Custom metrics quietly become 30 to 52 percent of the bill. Twenty-five plus SKUs make cost modeling impossible. Here is where the money actually goes and the routing architecture that stops it.
datadog · cost-optimization · observability
Datadog charges you to ingest logs and again to index them. Custom metrics quietly become 30 to 52 percent of the bill. Twenty-five plus SKUs make cost modeling impossible. Here is where the money actually goes and the routing architecture that stops it.
Read the piece →
Economics · 2026-04-04
The MSP Margin Trap: Why Your SIEM Bill Grows Faster Than Your Revenue
MSP profit margins should be 30 to 35 percent. Most operate at 8 to 12 percent. The structural problem is usage-based SIEM pricing against flat-rate client billing. Here is how the math works and what pipeline architecture changes.
msp · siem · cost-optimization
MSP profit margins should be 30 to 35 percent. Most operate at 8 to 12 percent. The structural problem is usage-based SIEM pricing against flat-rate client billing. Here is how the math works and what pipeline architecture changes.
Read the piece →
Playbook · 2026-03-28
Route Before You Index: How Cribl Reduces Splunk Costs 40 to 70 Percent
Firewall allow logs represent 60 to 70 percent of most Splunk ingest volumes. Nobody searches them. Here is the pipeline architecture that sends high-value events to Splunk and everything else to S3 at a fraction of the cost.
splunk · cribl · cost-reduction
Firewall allow logs represent 60 to 70 percent of most Splunk ingest volumes. Nobody searches them. Here is the pipeline architecture that sends high-value events to Splunk and everything else to S3 at a fraction of the cost.
Read the piece →
Analysis · 2026-03-21
5 Signs Your Observability Stack Needs a Pipeline Layer
Your SIEM bill keeps climbing. Onboarding new data sources takes weeks. Your team spends more time on parsing config than security analysis. These are signals that a routing layer belongs in your architecture.
observability · siem · pipeline-architecture
Your SIEM bill keeps climbing. Onboarding new data sources takes weeks. Your team spends more time on parsing config than security analysis. These are signals that a routing layer belongs in your architecture.
Read the piece →
Playbook · 2026-03-14
QRadar Is Sunsetting: Your Migration Playbook
IBM sold QRadar SaaS to Palo Alto. On-premises is maintenance-only. Forrester advises against new purchases. Here is how to plan a gradual migration using parallel routing through a Cribl pipeline.
qradar · siem-migration · ibm
IBM sold QRadar SaaS to Palo Alto. On-premises is maintenance-only. Forrester advises against new purchases. Here is how to plan a gradual migration using parallel routing through a Cribl pipeline.
Read the piece →
Economics · 2026-03-07
Why Sentinel Commitment Tiers Do Not Work for MSPs
Sentinel prices commitment tiers per workspace with no ability to pool across tenants. For MSPs managing 30 clients, that means 30 separate cost buckets with no optimization. Here is what a pipeline layer changes.
sentinel · microsoft · msp
Sentinel prices commitment tiers per workspace with no ability to pool across tenants. For MSPs managing 30 clients, that means 30 separate cost buckets with no optimization. Here is what a pipeline layer changes.
Read the piece →
Start with the review
You share your diagrams, we review them with you, and you leave with your version of the Logmetry Blueprint drawn on your stack. No system access, no obligation.