Talk to us
by DynatraceTechBag Intel Page

Log Analytics

The error was in the logs. The cause was in the trace — Dynatrace keeps logs in Grail beside the traces and metrics they explain — and prices ingest, retention and query separately, so the bill follows what you keep and what you search.

Logs beside tracesNo index to manageIngest, retain, query

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
ingest, retain, query
Published
Storage
one store, all signals
Grail
Query
joins across signals
DQL
India
AWS region for SaaS
Mumbai

Quick answer

Dynatrace Log Analytics stores logs in Grail, the platform's data lakehouse, and queries them with DQL beside the metrics and traces they explain. The price is published and split three ways: $0.20 per GiB to ingest, a daily retention rate, and a charge per GiB scanned — or a bundled plan with queries included. That split rewards a deliberate retention policy. Part of the platform Gartner named a Leader in 2026. Read more ↓ Show less ↑
Part 01 · Orient

The Dynatrace platform family

This page covers Log Analytics — logs on the Dynatrace platform. The rest:

Quick facts

30-second orientation
Product
Log management on the Dynatrace platform
Storage
Grail — one lakehouse for every signal
Query
DQL, with joins to traces and metrics
Ingest
$0.20 per GiB, published
Retain
$0.0007 per GiB-day (pay-per-query)
Query cost
$0.0035 per GiB scanned
Or bundled
$0.02 per GiB-day, queries included
India
SaaS on AWS Mumbai
The lever
Your retention policy, per source
In India via
TechBag — INR/GST, scoping and support
Part 02 · Learn

Understand log analytics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is Dynatrace Log Analytics?

Logs in Grail, beside traces and metrics, queried with one language — DQL.

A separate log index vs logs beside their traces — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA separate log tool with its own indexLog Analytics (Dynatrace)
Where logs liveA separate log productGrail, beside traces and metrics
IndexingDesign the schema, manage shardsNo index to maintain
The billFlat per GiB ingestedIngest, retain and query separately
RetentionOne period for everythingPer bucket, per source
Personal dataStored, then cleanedMasked before storage
What it is NOT—Not cheap for unplanned wide queries

Retention, not volume, usually decides a log bill. Settle it per source before migrating a single gigabyte.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
How logs get in

OpenPipeline

Ingest and process

Receives logs from OneAgent, OpenTelemetry, Fluent Bit and cloud sources, then parses, enriches, masks sensitive fields and extracts metrics before storage.

02
Where logs live

Grail

The data lakehouse

Logs sit beside metrics, traces and events in one store with no index to manage. Retention is set per bucket, which is where the cost is decided.

03
How you ask

DQL

The query language

One language for every signal. The point is joins: a log line, the trace it belongs to and the host metric around it are one query, not three tools.

04
The everyday value

Davis AI

Log-driven problems

Log patterns feed the same root-cause engine as traces and metrics, so an error surge is tied to the service and deployment that caused it.

One store for logs beside metrics and traces — parsed on the way in and joined in one query, not searched in a silo.

Part 03 · Evaluate

Six capabilities. Collect, analyse, act.

Dynatrace puts logs beside the traces they explain — one store, one query language, and the rest of the Dynatrace portfolio.

Collect
Ingest

Any source, one pipeline

OneAgent, OpenTelemetry, Fluent Bit, syslog and cloud services feed OpenPipeline — parsed and enriched on the way in.

Collect
Masking

Sensitive data out before storage

Mask or drop personal data at ingest, so it never lands in the store — relevant under DPDP.

Collect
Retention

Set per bucket, not globally

Keep audit logs for a year and debug logs for a week. Retention per bucket is the biggest lever on the bill.

Analyse
DQL

Query logs with their traces

Join a log line to its trace and host metric in one query — the step most log tools leave to a second product.

Analyse
Metrics from logs

Keep the number, drop the line

Extract a metric at ingest and discard the raw log — a common way to keep insight while cutting retention cost.

Act
Problems

Log surges become problems

Davis AI ties an error surge to the service and deployment behind it, instead of leaving a spike on a chart.

See it, don’t just read it

Watch Dynatrace Log Analytics in action

Grail and DQL, logs without queries, and where the log bill goes.

Dynatrace (official)·Overview

Log observability: introduction to Grail and DQL

How logs live in Grail.

Dynatrace (official)·Walkthrough

Mastering logs without writing queries

Log insight for non-DQL users.

Dynatrace (official)·Cost

Optimize your logs: save money and boost performance

Where the log bill actually goes.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Log Analytics

Most log tools store the line. Dynatrace stores it next to the reason.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Logs next to the traces they explain

Most log tools are a separate product with a separate index. In Grail a log line, its trace and the host metric around it are one DQL query — which is what turns an error message into a diagnosis.

02

The price separates what you keep from what you search

$0.20 per GiB to ingest, a daily rate to retain, and a charge per GiB scanned. Logs you keep for audit but rarely query stay cheap; logs you search constantly cost more. A flat per-GiB model cannot make that distinction.

03

No index to design, no shards to manage

Grail stores logs without a schema decided up front, so a new field or a new question does not mean reindexing. That removes the capacity planning that consumes self-run log clusters.

04

Where it stops

Pay-per-query rewards discipline and punishes the opposite: broad queries over long windows scan a lot of data. Choose between pay-per-query and bundled pricing on how your team actually searches.

The store
Logs beside traces
The index
None to manage
The price
Ingest, retain, query
Proof, not promises

The numbers behind the platform

$0.2 per GiB
to ingest and process logs, published
— Vendor
3 price levers
ingest, retention and query, billed separately
— Vendor
1 query language
DQL across logs, traces and metrics
— Vendor
2026
part of the platform Gartner named a Leader in 2026
— Gartner

What your log consolidation looks like

Week 1Model

Inventory log sources and volumes

GiB per day, per source. Then decide retention per source — the step that sets most of the bill.

Week 2Choose

Pick pay-per-query or bundled

Wide, frequent queries favour bundled retention; audit logs rarely searched favour pay-per-query.

Month 1Protect

Mask at ingest, then migrate

Configure OpenPipeline to drop or mask personal data before the first production log lands.

Month 2Consolidate

Retire the old log tool

Move dashboards and alerts to DQL, run both in parallel for a cycle, then switch off the duplicate spend.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.4
150+ reviews*
88% would recommend
Logs beside traces4.7
No index management4.5
Sensitive-data masking4.3
DQL learning curve3.5
Cost predictability3.7
5★
56%
4★
29%
3★
9%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Fintech
“Having the log line and its trace in one query is what made us switch. Two tools became one question.”
SRE Manager
Fintech
SaaS
“Setting retention per bucket cut the bill more than any ingest reduction. Debug logs never needed a year.”
Platform Lead
SaaS
Retail
“Pay-per-query caught us out in month one. Wide queries over thirty days add up — pick the plan to fit how you search.”
IT Operations Head
Retail
BFSI
“Masking at ingest meant personal data never reached storage. That simplified our DPDP conversation.”
Security Architect
BFSI
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the log management market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Log Management Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Dynatrace Log AnalyticsThis page

Logs beside traces; three price levers.

Grid 02 · The architecture

Log-Search Depth × Signal Correlation

The grid nobody publishes — depth of log search vs how closely logs join the other signals.

Bundled log viewsUnified observabilityBasic log toolsLog-search specialists
Dynatrace Log AnalyticsThis page

One store for every signal.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Dynatrace Log Analytics vs the log field

Against Splunk, Elastic and Datadog Logs — on where logs live, index work, price model and India.

DimensionDynatrace Log AnalyticsSplunkElasticDatadog Logs
Logs beside tracesSame storeSeparate productsSame stackSame platform
Index managementNoneManaged indexesYours to runManaged
Pricing modelPublished, 3 leversMostly quotedResource-basedPublished
Masking at ingestOpenPipelineSupportedIngest pipelinesSupported
India regionAWS MumbaiCheck the region listWherever you hostCheck the region list
Learning curveDQL to learnSPLKQL / ES|QLModerate
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Dynatrace Log Analytics if…

  • ✓You already run Dynatrace observability and want logs in the same store
  • ✓You want to price ingest, retention and query separately
  • ✓Managing a log index or cluster is consuming the team

Compare alternatives if…

  • ✓The team is fluent in SPL or KQL and switching costs matter
  • ✓You need logs self-hosted on your own infrastructure
  • ✓Your queries are wide and constant — model the scan cost first

Do not expect…

  • ✓Unplanned wide queries to be cheap on pay-per-query
  • ✓A Mumbai region to be a written storage commitment
  • ✓DQL fluency on day one

Log Analytics is one of 23 observability & APM products TechBag carries. The Observability & APM guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does a separate log tool cost you?

Drag the sliders (GiB of logs per day; engineer-hour cost). Estimates model the time lost switching between a log tool and an APM tool during incidents, plus retention kept longer than needed. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual log and triage cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Published: $0.20/GiB to ingest; retention at $0.0007/GiB-day with queries at $0.0035/GiB scanned, or $0.02/GiB-day with queries bundled — drawn down from one annual subscription. TechBag models both plans on your real query habits, then quotes in INR with GST.

Pay-per-query

Best for logs kept, rarely searched

  • $0.20/GiB ingest
  • $0.0007/GiB-day retention
  • $0.0035/GiB scanned per query

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Bundled queries

Best for logs searched constantly

  • $0.20/GiB ingest
  • $0.02/GiB-day retention
  • Queries included

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Volume

How many GiB per day, per source? Ingest is $0.20 per GiB, so the source list is the first cost driver.

2
Retention

Which logs need a year, and which a week? Retention per bucket usually decides the total.

3
Query habits

Are queries narrow and occasional, or wide and constant? That picks pay-per-query or bundled.

4
Personal data

Which fields must be masked or dropped at ingest to stay within DPDP obligations?

5
Migration

How many dashboards and alerts must move from SPL or KQL to DQL, and who does it?

6
Storage

Is the Mumbai region and the retention period written into the contract?

7
Overlap

Which existing log tool retires, and when does its contract end?

8
Skills

Who learns DQL, and is training budgeted?

FAQ

Questions buyers ask

Log management on the Dynatrace platform. Logs arrive through OpenPipeline, are stored in Grail beside metrics, traces and events, and are queried with DQL — so a log line and the trace it belongs to are one query apart. Ingest is published at $0.20 per GiB.

Ready to evaluate Dynatrace Log Analytics?

Inventory your log sources and set retention per source first, or let a TechBag advisor model pay-per-query against bundled on a month of your real queries.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.