Skip to content

Observability Stacks Comparison

Summary

A seven-way comparison of the self-hostable observability platforms in this vault: Coroot, SigNoz, Apache SkyWalking, OpenObserve, the LGTM Stack, the Victoria Stack and Monoscope. It covers architecture, signals, ingestion, reliability, scale, cost, security, developer experience and operations. Versions, licenses and features match the topic pages as of 2026-09-25. Performance and cost figures are vendor claims or rough estimates and are labelled as such. For the two composable stacks in depth, see LGTM vs Victoria Stack.

Which One Should I Pick?

The flowchart gives a first cut. The tables below explain each branch, and When to Choose What lists common scenarios.

flowchart TD
    Q1{"Want telemetry without code changes<br/>(eBPF auto-discovery, built-in inspections)?"}
    Q2{"Java-heavy estate or Istio/Envoy mesh,<br/>or ASF governance required?"}
    Q3{"Main driver: replace Elasticsearch<br/>for logs at lower cost?"}
    Q3B{"Need a permissive license<br/>(no AGPL)?"}
    Q4{"Need profiles plus deep cross-signal<br/>correlation at large scale,<br/>and have a platform team?"}
    Q5{"Want one OTel-native product<br/>and UI for traces, logs, metrics<br/>and LLM traces?"}
    Q6{"API-heavy product team wanting request<br/>capture, NL search and AI reports,<br/>and pre-1.0 is acceptable?"}
    Q7{"Top priority: resource efficiency<br/>on local disks with minimal ops?"}
    COROOT["Coroot 1.26"]
    SW["Apache SkyWalking 11.0"]
    VLOGS["Victoria Stack<br/>(VictoriaLogs 1.52)"]
    O2["OpenObserve 1.0"]
    LGTM["LGTM Stack<br/>(Mimir 3, Loki 3, Tempo 3, Pyroscope 2)"]
    SIGNOZ["SigNoz 0.143"]
    MONO["Monoscope 0.6"]
    VM["Victoria Stack"]
    LGTM2["LGTM Stack"]

    Q1 -->|"Yes"| COROOT
    Q1 -->|"No"| Q2
    Q2 -->|"Yes"| SW
    Q2 -->|"No"| Q3
    Q3 -->|"Yes"| Q3B
    Q3B -->|"Yes"| VLOGS
    Q3B -->|"No"| O2
    Q3 -->|"No"| Q4
    Q4 -->|"Yes"| LGTM
    Q4 -->|"No"| Q5
    Q5 -->|"Yes"| SIGNOZ
    Q5 -->|"No"| Q6
    Q6 -->|"Yes"| MONO
    Q6 -->|"No"| Q7
    Q7 -->|"Yes"| VM
    Q7 -->|"No"| LGTM2

TL;DR

Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
Philosophy Zero-instrumentation eBPF APM OTel-native, one UI on ClickHouse ASF APM with language agents Rust, Parquet on object storage Composable per-signal backends Efficiency-first single binaries OTel ingest, AI search and agents
Best for Auto-discovery, SLO alerts, RCA OTel shops leaving Datadog Java estates, service mesh Log-heavy, cost-sensitive Large platform teams Max efficiency, minimal ops API-heavy product teams
License Apache-2.0 (Enterprise commercial) MIT core, ee/ commercial, collector AGPL-3.0 Apache-2.0 AGPL-3.0 (Enterprise commercial) AGPL-3.0 (Alloy Apache-2.0) Apache-2.0 (Enterprise commercial) AGPL-3.0 (TimeFusion MIT)
Storage Prometheus-compatible TSDB or ClickHouse, plus ClickHouse ClickHouse + SQLite/PostgreSQL BanyanDB, ES/OpenSearch, MySQL, PostgreSQL Parquet on object storage Object storage Local disks PostgreSQL/TimescaleDB (TimeFusion to S3 behind flags)

Versions and Licenses

Platform Latest version (date) Language License Governance
Coroot v1.26.8 (2026-09-24); operator 1.10.4 Go Apache-2.0 Community; commercial Enterprise; agent BPF code GPL-2.0 Vendor-led (Coroot)
SigNoz v0.143.0 (2026-09-23); collector v0.144.11 Go, TypeScript MIT outside ee/; SigNoz Enterprise License for ee/; collector AGPL-3.0 Vendor-led (SigNoz Inc., YC W21)
Apache SkyWalking OAP 11.0.0 (2026-08-28); BanyanDB 0.11.1 (2026-09-20); Horizon UI 1.0.0 Java, Go, TypeScript Apache-2.0 ASF top-level project
OpenObserve v1.0.4 (2026-09-24); 1.0 GA 2026-09-22 Rust AGPL-3.0; commercial Enterprise Vendor-led (OpenObserve, Inc.)
LGTM Stack Mimir 3.2.1, Loki 3.7.8, Tempo 3.0.3, Pyroscope 2.3.1, Grafana 13.2.2, Alloy 1.20.0 Go AGPL-3.0 backends; Alloy Apache-2.0 Vendor-led (Grafana Labs)
Victoria Stack VictoriaMetrics v1.152.0, VictoriaLogs v1.52.0, VictoriaTraces v0.11.1 (pre-1.0), operator v0.74.1 Go Apache-2.0; commercial Enterprise Vendor-led (VictoriaMetrics, Inc.)
Monoscope v0.6.27 (2026-09-07), pre-1.0 Haskell, Rust (TimeFusion) AGPL-3.0; TimeFusion and SDKs MIT Vendor-led (Monoscope, formerly APItoolkit)

Release dates and full histories are on each topic's reference page.

Signal Coverage

Signal Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
Metrics Yes (Prometheus-compatible TSDB or ClickHouse) Yes (ClickHouse) Yes (OAP + storage) Yes (PromQL on Parquet) Yes (Mimir) Yes (VictoriaMetrics) Yes (OTLP metrics)
Logs Yes (ClickHouse) Yes Yes Yes (SQL) Yes (Loki) Yes (VictoriaLogs) Yes
Traces Yes (eBPF spans + OTLP) Yes Yes (OTLP traces stored as Zipkin in 11.0) Yes Yes (Tempo) Partial (VictoriaTraces 0.x) Yes
Profiles Yes (eBPF CPU, Go heap, Java async-profiler) No (as of 2026-09) Yes (async-profiler, pprof, Rover eBPF) Yes (OTLP Profiles) Yes (Pyroscope) No No
RUM / browser No Yes (Web Vitals via OTel JS) Yes (browser JS agent) Yes (RUM, session replay) Yes: Grafana Faro Web SDK (Apache-2.0) sends to Alloy's faro.receiver, which forwards to Loki and Tempo; the Frontend Observability app is Grafana Cloud only (faro.receiver docs) No Yes (browser SDK, session replay)
Service map Yes (automatic, eBPF) Yes Yes (topology) Yes (service graph) Yes (Tempo metrics-generator) Partial (VictoriaTraces service-graph relations, 0.x) Yes
eBPF collection Yes (core) No Yes (Rover) Profiles only (OTel eBPF profiler) Via Beyla/OBI in Alloy No No
LLM / GenAI monitoring No Yes (v0.143.0) Yes (GenAI layers 10.4+, AI agents 11.0) Yes (agent tracing, evaluations, cost) Grafana Cloud AI/Agent Observability No No
AI assistant / MCP AI RCA (Enterprise or Coroot Cloud); MCP in both editions MCP server; Noz assistant (Cloud only) Horizon AI assistant and MCP endpoint O2 AI Assistant Grafana Assistant (Cloud, on-prem since 13.0); Cloud MCP server vmanomaly anomaly detection (Enterprise) NL-to-KQL search, scheduled AI agents, MCP server

Architecture Comparison

Dimension Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
Model Server + node and cluster agents signoz binary + collector + ClickHouse OAP cluster + storage + Horizon UI Router, Ingester, Querier, Compactor, Scheduler (one binary in single-node mode) Microservices per signal Shared-nothing insert/select/storage per signal Haskell server + database
Query languages PromQL (metrics) Query builder, PromQL, ClickHouse SQL GraphQL + MQE, PromQL, LogQL, TraceQL (optional) SQL (DataFusion), PromQL PromQL, LogQL, TraceQL, profile label selectors MetricsQL, LogsQL, Jaeger API, Tempo API (experimental) KQL, natural language to KQL, SQL on TimeFusion
Collection eBPF agents, OTLP signoz-otel-collector (OTel distribution) Language agents, Rover, OTLP, Envoy ALS OTel Collector, Fluent Bit, Vector, ES _bulk clients Alloy (OTel distribution) vmagent, vlagent, OTel Collector OTel SDKs/Collector, Monoscope SDKs
UI Built-in Built-in Horizon UI; Grafana via PromQL/LogQL/Tempo APIs Built-in Grafana Grafana + VMUI Built-in
External dependencies Prometheus-compatible TSDB (optional with ClickHouse metrics), ClickHouse ClickHouse, ClickHouse Keeper or ZooKeeper, SQLite or PostgreSQL One storage backend (BanyanDB default) Object storage; HA adds PostgreSQL + NATS (OpenFGA, Dex for Enterprise RBAC/SSO) Object storage, Memcached, Kafka (Mimir ingest storage, Tempo 3 microservices), PostgreSQL/MySQL for Grafana None (optional S3 for backups) PostgreSQL + TimescaleDB; optional S3 via TimeFusion; OpenAI-compatible LLM for AI features
Single binary Server yes No (three pieces + ClickHouse) No (JVM OAP + storage) Single-node yes; HA no No Yes (per product) No (server + database)
Kubernetes operator Yes (coroot-operator) No (Helm chart, Foundry) Yes (SWCK 0.11.0) and Helm chart 5.0.0 Config-only (o2-k8s-operator manages alerts, pipelines, dashboards; install via Helm) Helm/Jsonnet; Loki and Tempo Operators exist (OpenShift-focused) Yes (VictoriaMetrics Operator) No (plain manifests, no Helm chart)

Ingestion Protocol Support

"Via collector" means the protocol works through a receiver in an OpenTelemetry-style collector rather than natively in the backend.

Protocol Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
OTLP HTTP (:8080) and gRPC (:4317) HTTP and gRPC gRPC (11800); HTTP since 11.0 HTTP and gRPC (5081) All backends HTTP; gRPC opt-in on VictoriaTraces gRPC (:4317)
Prometheus remote_write From its own agents Via collector (off by default) No (Prometheus via OTel Collector) Yes Yes (Mimir) Yes No (Prometheus scraping since v0.6.24)
Jaeger / Zipkin No Via collector Zipkin (off by default) No Yes (Tempo) No (VictoriaTraces is OTLP-only) No
Elasticsearch _bulk No No No Yes No Yes (VictoriaLogs) No
Loki push API No Via collector No No Yes (Loki) Yes (VictoriaLogs) No
InfluxDB, Graphite, Datadog, NewRelic No InfluxDB and Datadog via collector Telegraf, Zabbix No Via Alloy Yes (VictoriaMetrics) No
Syslog No Via collector No Not documented in topic page Via Alloy Yes (VictoriaLogs) No
Other native paths eBPF node agent, Windows agent Kafka, Splunk HEC via collector Language agents, Rover eBPF, Envoy ALS, Cilium Hubble, Kafka, AWS Firehose Kinesis Firehose, GCP Pub/Sub, RUM SDK pprof push (Pyroscope) journald, JSON lines, OpenTSDB Kafka, Google Pub/Sub, browser SDK

Performance

No independent benchmark covers all seven platforms. The table collects the figures the topic pages can source. All are vendor-run or vendor-stated.

Platform Published figure Kind Detail
Coroot eBPF node agent: latency change within measurement error at 10,000 RPS, about 200m CPU Vendor test Coroot reference
SigNoz About 2.5x faster log ingestion than ELK, about half the storage (January 2023, old versions) Vendor benchmark SigNoz reference
SkyWalking BanyanDB about 5x less memory and about 30% less disk than Elasticsearch (BanyanDB 0.6, 2024) Project benchmark SkyWalking reference
OpenObserve Up to 140x lower storage cost than Elasticsearch Vendor claim (README) OpenObserve explanation
LGTM Mimir 1B+ active series in one cluster (2022 load test); MQE up to 92% lower peak memory Vendor LGTM reference
Victoria VictoriaLogs up to 30x less RAM and 15x less disk than Elasticsearch and Loki; VictoriaTraces up to 3.7x less RAM than Tempo Vendor claim Victoria reference
Monoscope None published — Monoscope topic

Resource estimates

Earlier versions of this page gave RAM-per-1M-series and bytes-per-sample figures for every platform. Only Mimir and VictoriaMetrics have sourced figures: Mimir's capacity-planning guide gives about 25 GB of ingester RAM for 1M active series at RF=3 and assumes 2 bytes per sample; VictoriaMetrics publishes no per-series RAM figure (size by test run), and its case studies report 0.4-1.75 bytes per sample (see the Victoria reference, rebuilt 2026-09-27). The other platforms' figures were unsourced and have been removed. Benchmark on your own data before sizing.

Log search model (qualitative): Coroot and SigNoz use ClickHouse columnar scans. SkyWalking relies on its storage backend. OpenObserve scans Parquet with opt-in bloom filters and Tantivy indexes per field. Loki needs a label selector first, then scans lines. VictoriaLogs does free-text search with per-block bloom filters. Monoscope uses KQL over TimescaleDB, or DataFusion over Delta Lake when TimeFusion is enabled.

Reliability

Dimension Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
Durability Inherits from the metrics TSDB and ClickHouse (optional S3 tiering for ClickHouse) ClickHouse replication (Keeper/ZooKeeper) BanyanDB in-cluster group replicas, snapshot backups to S3/GCS; no cross-datacenter replication Object storage; no in-app replication, so unflushed ingester data is a single copy Object storage; ingester replication (RF=3) or Kafka in the write path Local disks; metrics replication via -replicationFactor; logs and traces are not replicated (dual-write instead); no WAL Your PostgreSQL/TimescaleDB setup; TimeFusion is single-writer
HA model Backend HA (server HA not documented in the topic page) ClickHouse cluster; multi-replica signoz HA is not documented: the default noop sharder gives every replica every org (pkg/sharder), and multi-replica Alertmanager is discussed in SigNoz/charts#514 OAP cluster + BanyanDB cluster Stateless roles on Kubernetes with PostgreSQL + NATS Per-component replicas, zone-aware RF on vminsert; two independent clusters for logs and traces Not documented for self-hosted (no Helm chart)
Backup Backend-native ClickHouse backup BanyanDB snapshots to S3/GCS Data already on object storage Data already on object storage vmbackup (metrics), partition snapshots (logs, traces) PostgreSQL backup; S3 bucket for TimeFusion
Crash data loss Depends on backend Depends on ClickHouse settings No guarantee documented: OAP nodes keep no local state and buffer data in memory queues before bulk writes (15 s trace flush, 25 s L2 persist period), so a crash can drop what is buffered (SkyWalking) Unflushed WAL on a failed ingester Covered by replication or Kafka Seconds of unflushed data (senders retry) Depends on PostgreSQL settings

Scalability

Dimension Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
Horizontal scaling Scale the backends ClickHouse shards and replicas OAP cluster, BanyanDB liaison/data nodes Add stateless nodes per role Per component Per component (insert, select, storage) Limited (single-writer TimeFusion)
Storage capacity Backend-bound ClickHouse cluster Storage cluster (hot/warm/cold stages in BanyanDB) Object storage Object storage Sum of local disks PostgreSQL, or your bucket with TimeFusion
Stated scale Not published Not published (reference: 2 shards x 2 replicas) "100+ billion telemetry data" per cluster (README, vendor claim) Not published Mimir 1B+ active series (2022 test) Roblox: 5 billion active series (case study) Not published
Multi-tenancy Projects (one per cluster) with API keys; per-project roles in Enterprise No documented tenant isolation for telemetry: organizations exist in the metastore (and the sharder keys on org ID), but self-hosted docs describe no per-tenant data separation (checked 2026-09-27) No per-tenant isolation (one shared agent token) Organizations with per-org ingestion tokens and storage (all editions) X-Scope-OrgID (on by default in Mimir and Loki, off in Tempo and Pyroscope) accountID:projectID in cluster mode; none in single-node Projects as tenant boundary; org workspaces on the roadmap

Cost

Pricing Models

Platform Self-hosted Commercial / managed (as of 2026-09)
Coroot Community free Enterprise from $1 per CPU core per month; Coroot Cloud gives CE users 10 free AI investigations per month
SigNoz Community free Cloud: $49/month base (includes $49 usage), $0.30/GB logs and traces, $0.10 per million metric samples; Enterprise custom
SkyWalking Free (ASF) No vendor cloud
OpenObserve OSS free; Self-Hosted Enterprise free up to 50 GB/day Cloud: $0.50/GB ingested + $0.01/GB queried
LGTM Free Grafana Cloud Free ($0), Pro ($19/month + usage, about $6.50 per 1,000 series), Enterprise by contract (commonly cited from about $25k/year, secondary sources)
Victoria Community free Enterprise commercial; VictoriaMetrics Cloud capacity tiers from about $190/month (smallest tiers), other tiers priced in the console, $200 trial credits (billing docs, checked 2026-09-27)
Monoscope Community free Cloud free tier, then $29/month for 20M events + $1 per extra million; Cloud + S3 (BYOS) from $199/month for 100M events

Check each vendor's pricing page before budgeting; the topic pages hold the details and dates.

Self-Hosted Infrastructure (Estimates)

At 1M active series, 100 GB/day logs and 50M spans/day. The dollar figures are illustrative, unsourced estimates carried in the topic reference pages; no vendor publishes them. Platforms without a figure have no estimate in this vault.

Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
Est. monthly infra Not estimated $500-1,500 Not estimated Not estimated (vendor offers an AWS-based capacity planning sheet) $1,000-3,000 $500-1,500 Not estimated
Main cost drivers ClickHouse, metrics TSDB ClickHouse + Keeper operations, schema migrations JVM heaps, BanyanDB or Elasticsearch Object storage requests, PostgreSQL + NATS in HA Many components, Kafka, Memcached, object storage Local SSDs, backups TimescaleDB, LLM API usage

Sources for the estimates: LGTM cost estimates and Victoria cost estimates.

Security

Feature Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
Authentication Built-in users; SSO (SAML, OIDC) in Enterprise Users, API keys; SAML/OIDC SSO in Enterprise or Cloud Horizon UI login (local users, LDAP, API tokens) since 11.0; OAP HTTP and admin ports have no auth Basic auth; SSO via Dex in Enterprise Grafana auth (OAuth, LDAP; SAML in Enterprise/Cloud); backends need an auth gateway in OSS vmauth Basic/Bearer and JWT/OIDC (v1.137+); vmgateway in Enterprise Basic auth or Auth0 SSO
RBAC Fixed Admin/Editor/Viewer; custom roles in Enterprise Managed roles; custom roles in beta Horizon RBAC Enterprise (OpenFGA); OSS roles are root/admin/member Fine-grained RBAC in Grafana Enterprise/Cloud Routing rules in vmauth; no RBAC UI Project roles (view/edit/admin)
Ingestion auth Project API key (X-Api-Key) Unauthenticated OTLP on self-hosted; ingestion keys on Cloud Optional shared agent token Basic auth per user or service account Tenant header via gateway vmauth Project API keys
Encryption in transit TLS TLS TLS with hot reload (11.0) TLS TLS configurable per component TLS; mTLS is Enterprise-only TLS terminated at a load balancer or ingress; sslmode=require for PostgreSQL and TimeFusion; HTTPS to S3 (Monoscope)
Audit logging Enterprise, per Palark's review Enterprise plans (SigNoz lists audit logs as an enterprise feature) Not documented Enterprise audit trail Grafana Enterprise Not built in Not documented

Developer Experience

Dimension Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
Fastest start Operator + Coroot resource Foundry (foundryctl) or Helm Docker Compose, Helm or SWCK Single binary or container grafana/otel-lgtm container (dev only) Single binaries or containers Two-container Docker Compose
Learning curve Low (auto-discovery) Medium (OTel + ClickHouse SQL) High (OAP DSLs: OAL, MAL, LAL) Low to medium (SQL) High (four query models) Low to medium (MetricsQL, LogsQL) Low (KQL, natural language)
Instrumentation None required (eBPF); OTel SDKs optional OTel SDKs ASF language agents + OTel OTel SDKs, RUM SDK OTel SDKs, Alloy, Beyla/OBI OTel SDKs, vmagent OTel SDKs, Monoscope SDKs
APIs HTTP API, MCP HTTP API, MCP server, Terraform provider GraphQL, PromQL, LogQL, TraceQL APIs; MCP HTTP API, O2 CLI Per-component HTTP APIs, Grafana HTTP API Prometheus-, Loki-, Jaeger- and Tempo-compatible HTTP APIs REST, JSON CLI, MCP

Operations

Dimension Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
Components Agents, server, TSDB, ClickHouse signoz, collector, ClickHouse (+ Keeper), metastore Agents, OAP, storage, Horizon UI 5 roles + PostgreSQL + NATS (HA) or 1 binary 4+ backends, Alloy, Grafana, caches, Kafka vmagent, vmauth, 3 databases (each insert/select/storage in cluster mode) Server, PostgreSQL/TimescaleDB, optional TimeFusion
Release pace and upgrades Minor every 2-5 weeks, no LTS; operator can auto-upgrade Weekly pre-1.0 releases with required upgrade stops About two OAP releases a year; 11.0 is breaking; BanyanDB pinned in lockstep Minor every 4-7 weeks, no LTS Breaking majors (Mimir 3, Tempo 3, Pyroscope 2; Loki 4 ahead) VictoriaMetrics every ~2 weeks; Enterprise LTS lines Bursty pre-1.0 releases; TimeFusion migration unfinished

Community and Ecosystem

Dimension Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
GitHub stars (snapshot) ~7.9k (2026-09) Not in topic page ~24.8k (2026-04) ~22k (2026-09) ~120k across repos (2026-04) ~16.7k (2026-04) ~1.8k (2026-09)
Managed cloud Coroot Cloud (AI RCA for CE) SigNoz Cloud None OpenObserve Cloud Grafana Cloud VictoriaMetrics Cloud (metrics; logs since Q1 2026) Monoscope Cloud
Ecosystem Small Terraform provider, MCP ASF agents and sub-projects O2 CLI, config operator 100+ Grafana data-source plugins Grafana-compatible SDKs, CLI, Claude Code skills
Commercial backing Coroot SigNoz Inc. (about $6.5M seed, 2023) None (ASF) OpenObserve, Inc. Grafana Labs ($400M+ ARR in 2025-09; reportedly raising at about $9B valuation, 2026-02) VictoriaMetrics, Inc. Monoscope

Star counts are dated snapshots taken from the topic pages; each carries its date.

Scorecard

Scores (1 to 5) are editorial judgments derived from the tables above, not measurements. "n/a" means there is no public data to judge.

Aspect Coroot SigNoz SkyWalking OpenObserve LGTM Victoria Monoscope
Ease of setup 5 4 2 5 2 5 4
Signal coverage 4 4 5 5 5 3 3
Performance (published data) 4 4 3 4 4 5 n/a
Scalability 3 4 4 5 5 4 2
Cost efficiency 5 4 4 5 3 5 4
Operational simplicity 5 3 2 4 2 5 3
Security / RBAC 3 3 3 4 5 3 2
Community 2 4 5 3 5 3 2
Enterprise readiness 3 4 4 4 5 4 2
Licensing freedom 5 4 5 3 3 5 3
Auto-instrumentation 5 2 4 2 3 2 2
Dashboard quality 3 4 3 4 5 3 3

When to Choose What

Scenario Recommended Why
Small team, zero instrumentation Coroot eBPF auto-discovery, built-in inspections and SLO alerts; AI RCA in Enterprise or via Coroot Cloud
OTel-native Datadog replacement SigNoz One UI on ClickHouse, usage pricing without seat or host fees
Java enterprise, Istio/Envoy SkyWalking Mature Java agent, mesh topology from Envoy ALS, ASF governance
Elasticsearch replacement for logs OpenObserve or VictoriaLogs OpenObserve: SQL on object storage (AGPL). VictoriaLogs: LogsQL on local disks (Apache-2.0)
Large platform team, full correlation LGTM Metrics, logs, traces and profiles with exemplars, TraceQL and the Grafana ecosystem
Maximum efficiency, small budget Victoria Stack Low RAM and disk use (vendor and user reports), no external dependencies, Apache-2.0
API-heavy product, AI-assisted triage Monoscope Request capture, NL-to-KQL search, scheduled AI reports; plan around pre-1.0 maturity
LLM and agent applications SigNoz, OpenObserve or SkyWalking Built-in GenAI views; Grafana Cloud offers the same as a managed service
Air-gapped or compliance-heavy LGTM with Grafana Enterprise, Coroot Enterprise or OpenObserve Enterprise SSO, RBAC, audit trails (OpenObserve, Grafana) and vendor support
Long-retention log analytics on object storage OpenObserve Parquet on object storage; vendor claims up to 140x lower storage cost than Elasticsearch

Sources

Facts on this page come from the linked topic pages (researched 2026-09-25), which cite primary sources. Key vendor pages: