Can an agent replace Datadog?
Infrastructure and application monitoring, logs, traces and alerting at scale.
The interpretation, yes. The collection, no. Datadog ingests and stores an enormous volume of telemetry, which is a genuine infrastructure problem. What an agent replaces is the engineer reading dashboards at 3am.
- Indicative spend
- €800/mo
- What it actually costs
- from €15/host/mo, and the bill is famously never that
- Verdict
- The agent does the work inside it. The tool stays because that is where the data lives.
What the agent takes over
Every job this product exists to perform, with our verdict on each. Follow one through for the step-by-step breakdown.
- Security monitoringMostly, for detection and triage rather than response. An agent watches logs continuously, investigates alerts and separates the noise from the real signal. Containment actions should stay with a person who can be woken up.MOSTLY
- Bug triageYes. Reading a bug report, reproducing it, finding the likely cause, checking for duplicates and routing it to the right team is exactly the work that clogs engineering queues — and an agent does it in minutes.YES
- Reporting and dashboardsYes. Pulling from several systems, reconciling the definitions, building the view and explaining what moved is exactly what agents do well — and it removes the recurring tax of someone rebuilding a spreadsheet every Monday.YES
Why it survives
Ingestion at scale.
What you would still need it for
- Telemetry ingestion and retention
- Alerting infrastructure
- Distributed tracing
What replaces it
- An agent doing alert triage and incident investigation against it
The brief
What you would tell an agent to take over from Datadog, assembled from the jobs above.
I want to cut the work inside Datadog. It currently does: Infrastructure and application monitoring, logs, traces and alerting at scale. Take over this work: - Security monitoring — MOSTLY. Mostly, for detection and triage rather than response. An agent watches logs continuously, investigates alerts and separates the noise from the real signal. Containment actions should stay with a person who can be woken up. - Bug triage — YES. Yes. Reading a bug report, reproducing it, finding the likely cause, checking for duplicates and routing it to the right team is exactly the work that clogs engineering queues — and an agent does it in minutes. - Reporting and dashboards — YES. Yes. Pulling from several systems, reconciling the definitions, building the view and explaining what moved is exactly what agents do well — and it removes the recurring tax of someone rebuilding a spreadsheet every Monday. Do not take over: - Telemetry ingestion and retention - Alerting infrastructure - Distributed tracing These stay with me across all of it: - Containment decisions - Breach disclosure - Anything with regulatory consequence - Declaring incidents - Prioritising against the roadmap - Customer communication - Choosing the metrics - What the numbers mean for the plan - Anything shown to investors Before we start, tell me: which of these you cannot do with the access I can actually give you, and what would break if this ran unattended for a month. — brief built at cananagentdo.com/datadog
Compare
Keep the tool, cut the hours
Datadog is not the line item worth attacking. The money is in the people-hours spent working inside it, and that is what an agent takes over — with Datadog still holding the data.
Put an agent on it