No more typing reviews! Try our Samantha, our new voice AI agent.

Datadog vs Security Onion comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Datadog
Ranking in Log Management
4th
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
210
Ranking in other categories
Application Performance Monitoring (APM) and Observability (1st), Network Monitoring Software (4th), IT Infrastructure Monitoring (2nd), Container Monitoring (3rd), Cloud Monitoring Software (1st), AIOps (1st), Cloud Security Posture Management (CSPM) (5th), AI Observability (1st)
Security Onion
Ranking in Log Management
29th
Average Rating
7.6
Reviews Sentiment
5.5
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Log Management category, the mindshare of Datadog is 4.0%, down from 6.0% compared to the previous year. The mindshare of Security Onion is 2.3%, down from 5.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
Datadog4.0%
Security Onion2.3%
Other93.7%
Log Management
 

Featured Reviews

Dhroov Patel - PeerSpot reviewer
Site Reliability Engineer at Grainger
Has improved incident response with better root cause visibility and supports flexible on-call scheduling
Datadog needs to introduce more hard limits to cost. If we see a huge log spike, administrators should have more control over what happens to save costs. If a service starts logging extensively, I want the ability to automatically direct that log into the cheapest log bucket. This should be the case with many offerings. If we're seeing too much APM, we need to be aware of it and able to stop it rather than having administrators reach out to specific teams. Datadog has become significantly slower over the last year. They could improve performance at the risk of slowing down feature work. More resources need to go into Fleet Automation because we face many problems with things such as the Ansible role to install Datadog in non-containerized hosts. We mainly want to see performance improvements, less time spent looking at costs, the ability to trust that costs will stay reasonable, and an easier way to manage our agents. It is such a powerful tool with much potential on the horizon, but cost control, performance, and agent management need improvement. The main issues are with the administrative side rather than the actual application.
Jörg Kippe - PeerSpot reviewer
Scientist at a educational organization with 10,001+ employees
A mature and affordable solution that is easy to install and easy to update
The product takes time to learn, it's not that easy. In the beginning we had a lot of questions. If you want to use such a tool in an real (industrial) environment, you have to ask how to get the network data. Can we do a full packet capture? Can we provide agents to our end systems? There are no simple solutions to these questions. It's a general problem when running such systems in an industrial environment.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The visibility that it provides is valuable, helping us be proactive around incident management and get more insight into our customers' applications so that we can assist them at the application layer and even call customers before they know about an issue."
"Datadog has impacted my organization positively as this is our main observability tool when it comes to monitoring services, traces, and all resources within key services."
"Having a wealth of information has helped us investigate outages, and having historical data helps us tune our system."
"When an alert fires, our on-call engineer can see the infrastructure metric spike (like CPU), pivot directly to the application traces (APM) running on that host, and see the exact, correlated logs from the services causing the problem—all in one place."
"From the number of outages stopped or shortened (which lead to lost revenue from non-renewals) and the number of hours saved on investigations (which correlates to engineering salaries), I estimate that the ROI of the implementation time and monthly charges to be between 10x and 20x."
"Dashboards and their versatility are among the most valuable features."
"Dashboards are helpful for reviewing occasionally to get a higher-level overview of what's happening."
"Features-wise, I'd give them a rating of ten out of ten."
"We use Security Onion for internal vulnerability assessment."
"The most valuable feature of Security Onion for security monitoring is its ability to find infected ports."
"Security Onion is the most mature solution in the market."
 

Cons

"It would also be nice if we had more insight into our own usage of Datadog (agents and custom metrics). They provide a usage page which does help, but it is not in real-time."
"Billing should be more transparent."
"Since the Datadog platform has so many separate features, solving so many use cases, there are often inconsistencies in feature availability and interoperability between products."
"I'd like to see more flexibility in the customization and they have a few settings which need to be changed but we are unable to make those changes as users or as the administrator."
"It is very difficult to make the solutions fit perfectly for large organizations, especially in terms of high cardinality objects and multi-tenancy, where the data needs to be rolled up to a summarized level while maintaining its individual data granularity and identifiers."
"It lacks consistency in the APIs."
"Datadog is too pricey when compared to its competitors, and this is something that its always on my mind during the decision-making process."
"When the logs are too big, and Datadog splits them, the JSON format breaks and it is not so useful for us."
"Security Onion's user interface could be improved."
"The initial setup of the solution is a little bit difficult."
"The product is not easy to learn."
 

Pricing and Cost Advice

"The tool is open-source."
"The cost is high and this can be justified if the scale of the environment is big."
"If you do your homework, you'll find that if you're really concerned with cost, it's good."
"At my last company, we did see ROI, specifically around response time. We could get to mission critical things that were down and losing revenue on immediately. So, the product paid itself back."
"Sometimes it's very hard to project how much it will cost for the monthly subscription for the next month when you add certain features. Having better visibility of the cost would give a better experience."
"Pricing seemed easy until the bill came in and some things were not accounted for."
"The price is better than some competing products."
"While it is an expensive product, I would rate the pricing level at four out of five."
"It is an open-source solution."
"Security Onion is an open-source solution."
"Security Onion is a free solution."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
893,221 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
9%
Manufacturing Company
8%
Healthcare Company
6%
University
12%
Government
10%
Comms Service Provider
10%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business82
Midsize Enterprise47
Large Enterprise100
No data available
 

Questions from the Community

Any advice about APM solutions?
There are many factors and we know little about your requirements (size of org, technology stack, management systems, the scope of implementation). Our goal was to consolidate APM and infra monitor...
Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several times lately using the dashboards we have created with Datadog; they are very good c...
Which would you choose - Datadog or Dynatrace?
Our organization ran comparison tests to determine whether the Datadog or Dynatrace network monitoring software was the better fit for us. We decided to go with Dynatrace. Dynatrace offers network ...
Ask a question
Earn 20 points
 

Comparisons

 

Overview

 

Sample Customers

Adobe, Samsung, facebook, HP Cloud Services, Electronic Arts, salesforce, Stanford University, CiTRIX, Chef, zendesk, Hearst Magazines, Spotify, mercardo libre, Slashdot, Ziff Davis, PBS, MLS, The Motley Fool, Politico, Barneby's
Information Not Available
Find out what your peers are saying about Datadog vs. Security Onion and other solutions. Updated: April 2026.
893,221 professionals have used our research since 2012.