Observability

What actually drives your Datadog log bill, and how to control it

Log bills do not escalate because anyone chose them. They escalate because nobody chose anything: every service ships everything, everything gets indexed, and the invoice becomes the design document. This guide is the set of decisions that replaces that default, written for Saudi estates where the retention pressure runs the other way.

01The mechanics

The three numbers the bill is made of

Datadog’s log pricing has two main dials, and estates get surprised by both. Ingestion is the volume that arrives: priced per gigabyte, it is the smaller dial, and the one teams watch because it is intuitive. Indexing is what makes logs searchable, priced per million events, and it is where bills actually escalate, because the default posture, index everything that arrives, pays for search on logs nobody will ever query. The third number wears a different badge but behaves the same: custom metric cardinality, where every unique tag combination is a billable series, and one well-meaning user-ID tag can mint a million of them overnight.

The pattern behind all three: cost tracks decisions nobody made. Which is the good news, because it means the fix is making the decisions, not buying a different logo. Moving platforms with the same undisciplined pipeline moves the same bill.

02The split

Index, ingest, archive: the decision that does most of the work

The single highest-leverage move on most estates is separating three fates that the default configuration merges. Every log stream gets assigned one, deliberately.

FateWhat it meansWhat belongs there
IndexedSearchable immediately in the platform; the expensive tierWhat on-call engineers actually query during incidents: errors, warnings, and the request logs of the services that carry the business. Days to a few weeks of it.
Ingested and archivedReceived, processed, then parked in cheap storage (yours or the platform’s), rehydratable on demandThe long tail an investigation or audit might someday need: rehydrate the day in question when the question arrives, instead of paying to search it for months on the chance.
Never shippedDropped at source or held on your own infrastructure entirelyDebug noise nobody reads, health-check chatter, and the sensitive classes your residency rules keep in-Kingdom anyway.

03The Saudi tension

The retention pressure that pulls against every cost guide

Here is the contradiction every Saudi cost conversation eventually meets, and almost no published cost advice acknowledges. The generic guidance, from vendors and cost-tooling alike, is: drop aggressively, sample heavily, keep retention short. Meanwhile Saudi security frameworks push regulated estates in the opposite direction, toward long, centralised, queryable log retention as a security control. Follow the cost advice naively and you can engineer yourself out of a compliance position; a dropped log is not evidence, and a sampled audit trail is not an audit trail.

This guide will not tell you what your retention obligation is, that number belongs to your regulator’s own text and your compliance owner, not to anyone’s blog, including this one. What it will tell you is the design answer to the tension: the split above. Security-relevant classes are retained in full, for their mandated period, in the cheap tier, archived in-Kingdom where residency requires; investigation classes stay hot but short; noise never ships. Cost control and compliance stop being enemies the moment retention is assigned per class instead of per platform.

04Which lever first

Where to start, by the shape of your estate

If your estate is…Pull firstBecause
Kubernetes-heavyTag discipline and a cardinality budget, then per-namespace exclusion filtersCluster estates bleed money through metric cardinality and through system-component chatter that nobody chose to index. The Kubernetes guide covers the budget.
Legacy and chattyFix the logging itself: levels, deduplication, and dropping debug at sourceTwenty-year-old systems log like it is free because it was. Sometimes the answer is not pipeline engineering; it is turning the firehose down where it starts.
Hybrid with residency rulesThe in-Kingdom control point, doing filtering, redaction and routing before egressOne piece of infrastructure enforces the residency split and the cost split at once; the same rules serve both masters, which is why the two guides on this site keep pointing at each other.

What not to do.

Do not let a cost sprint delete the audit trail: dropping or sampling security-relevant logs to hit a budget number creates a compliance exposure that costs more than the storage ever did. Do not solve cost by switching platforms before disciplining the pipeline, because the bill travels with the habits. And treat any savings percentage quoted before someone has measured your actual volumes, this page included, as marketing.

Quick answers

The long-retention questions

Common question

How do we keep a year of logs without indexing a year of logs?

Through the archive tier: logs are ingested, processed, then parked in low-cost storage, rehydrated into the searchable tier only when an investigation or audit actually asks. Datadog also documents long-retention log SKUs with multi-month tiers; read their current terms carefully, at the time of writing the documentation notes real functional limits on those tiers (alerting among them), which is exactly the kind of fact to verify in docs, not marketing, before a procurement commitment.

Common question

Who should own the cost, ongoing?

A named person, with a monthly review: top log sources by volume, new custom metrics by cardinality, and exclusion-filter coverage. Unowned observability cost grows back within quarters of any one-off cleanup, because every new service ships with the default posture. Cost review is part of how Interkey operates deployments, for exactly this reason.

If the bill has already escalated, or a renewal is approaching and nobody can explain the number, Interkey runs a scoped cost review: a measured baseline, the waste ranked by size, and an implementation plan that respects your retention obligations.

Arrange a cost review

05Buyer questions

What buyers ask us

Direct answers to the questions that come up in real evaluations. Anything missing, ask us at the bottom of the page.

What determines Datadog log cost, in one paragraph?

Volume ingested, share indexed, and how long the indexed share is retained, plus custom metric cardinality wearing a different label. Indexing is usually the dominant term, which is why the index/ingest/archive split is the first lever, and why an estate that indexes everything is paying for search on logs nobody will ever run.

Will OpenTelemetry reduce the bill?

Not by itself: OTel changes how telemetry is produced and moved, not what you choose to index. It does make the control-point pattern easier to build vendor-neutrally, and it keeps your instrumentation portable, which strengthens your commercial position at every renewal. Discipline still has to be designed in.

Is switching platforms ever the right cost answer?

Sometimes, and Interkey has written honestly about when: large fixed on-premise fleets and hard residency constraints change the calculation. But switch after disciplining the pipeline, not instead of it, or the same bill follows you with a different logo on it.

Next step

Put a number you can explain on the next renewal

A month of invoice plus a list of your five loudest services is enough for a first read on where the bill can move.

Or directly

+966-11-2180999 info@interkey.com.sa

Tawuniya Towers, North Tower, 7th Floor, King Fahad Highway, Olaya, P.O. Box 56835, Riyadh 11564, Saudi Arabia

or The full implementation method

The Riyadh team replies on Saudi working days, in Arabic and English.

Elsewhere

Related on interkey.com.sa

Published by Interkey. Last updated . Interkey is registered in Riyadh, Saudi Arabia under commercial registration 1010156897.

Talk to us