The error was in the logs. The cause was in the trace — Dynatrace keeps logs in Grail beside the traces and metrics they explain — and prices ingest, retention and query separately, so the bill follows what you keep and what you search.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Log Analytics — logs on the Dynatrace platform. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Logs in Grail, beside traces and metrics, queried with one language — DQL.
What consolidation actually replaces, dimension by dimension.
| Dimension | A separate log tool with its own index | Log Analytics (Dynatrace) |
|---|---|---|
| Where logs live | A separate log product | Grail, beside traces and metrics |
| Indexing | Design the schema, manage shards | No index to maintain |
| The bill | Flat per GiB ingested | Ingest, retain and query separately |
| Retention | One period for everything | Per bucket, per source |
| Personal data | Stored, then cleaned | Masked before storage |
| What it is NOT | — | Not cheap for unplanned wide queries |
Retention, not volume, usually decides a log bill. Settle it per source before migrating a single gigabyte.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Receives logs from OneAgent, OpenTelemetry, Fluent Bit and cloud sources, then parses, enriches, masks sensitive fields and extracts metrics before storage.
Logs sit beside metrics, traces and events in one store with no index to manage. Retention is set per bucket, which is where the cost is decided.
One language for every signal. The point is joins: a log line, the trace it belongs to and the host metric around it are one query, not three tools.
Log patterns feed the same root-cause engine as traces and metrics, so an error surge is tied to the service and deployment that caused it.
One store for logs beside metrics and traces — parsed on the way in and joined in one query, not searched in a silo.
Dynatrace puts logs beside the traces they explain — one store, one query language, and the rest of the Dynatrace portfolio.
OneAgent, OpenTelemetry, Fluent Bit, syslog and cloud services feed OpenPipeline — parsed and enriched on the way in.
Mask or drop personal data at ingest, so it never lands in the store — relevant under DPDP.
Keep audit logs for a year and debug logs for a week. Retention per bucket is the biggest lever on the bill.
Join a log line to its trace and host metric in one query — the step most log tools leave to a second product.
Extract a metric at ingest and discard the raw log — a common way to keep insight while cutting retention cost.
Davis AI ties an error surge to the service and deployment behind it, instead of leaving a spike on a chart.
Grail and DQL, logs without queries, and where the log bill goes.
How logs live in Grail.
Log insight for non-DQL users.
Where the log bill actually goes.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most log tools are a separate product with a separate index. In Grail a log line, its trace and the host metric around it are one DQL query — which is what turns an error message into a diagnosis.
$0.20 per GiB to ingest, a daily rate to retain, and a charge per GiB scanned. Logs you keep for audit but rarely query stay cheap; logs you search constantly cost more. A flat per-GiB model cannot make that distinction.
Grail stores logs without a schema decided up front, so a new field or a new question does not mean reindexing. That removes the capacity planning that consumes self-run log clusters.
Pay-per-query rewards discipline and punishes the opposite: broad queries over long windows scan a lot of data. Choose between pay-per-query and bundled pricing on how your team actually searches.
GiB per day, per source. Then decide retention per source — the step that sets most of the bill.
Wide, frequent queries favour bundled retention; audit logs rarely searched favour pay-per-query.
Configure OpenPipeline to drop or mask personal data before the first production log lands.
Move dashboards and alerts to DQL, run both in parallel for a cycle, then switch off the duplicate spend.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Having the log line and its trace in one query is what made us switch. Two tools became one question.”
“Setting retention per bucket cut the bill more than any ingest reduction. Debug logs never needed a year.”
“Pay-per-query caught us out in month one. Wide queries over thirty days add up — pick the plan to fit how you search.”
“Masking at ingest meant personal data never reached storage. That simplified our DPDP conversation.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the log management market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Logs beside traces; three price levers.
The grid nobody publishes — depth of log search vs how closely logs join the other signals.
One store for every signal.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Splunk, Elastic and Datadog Logs — on where logs live, index work, price model and India.
| Dimension | Dynatrace Log Analytics | Splunk | Elastic | Datadog Logs |
|---|---|---|---|---|
| Logs beside traces | Same store | Separate products | Same stack | Same platform |
| Index management | None | Managed indexes | Yours to run | Managed |
| Pricing model | Published, 3 levers | Mostly quoted | Resource-based | Published |
| Masking at ingest | OpenPipeline | Supported | Ingest pipelines | Supported |
| India region | AWS Mumbai | Check the region list | Wherever you host | Check the region list |
| Learning curve | DQL to learn | SPL | KQL / ES|QL | Moderate |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Log Analytics is one of 23 observability & APM products TechBag carries. The Observability & APM guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (GiB of logs per day; engineer-hour cost). Estimates model the time lost switching between a log tool and an APM tool during incidents, plus retention kept longer than needed. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Published: $0.20/GiB to ingest; retention at $0.0007/GiB-day with queries at $0.0035/GiB scanned, or $0.02/GiB-day with queries bundled — drawn down from one annual subscription. TechBag models both plans on your real query habits, then quotes in INR with GST.
Best for logs kept, rarely searched
Best for a broader rollout
Best for logs searched constantly
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many GiB per day, per source? Ingest is $0.20 per GiB, so the source list is the first cost driver.
Which logs need a year, and which a week? Retention per bucket usually decides the total.
Are queries narrow and occasional, or wide and constant? That picks pay-per-query or bundled.
Which fields must be masked or dropped at ingest to stay within DPDP obligations?
How many dashboards and alerts must move from SPL or KQL to DQL, and who does it?
Is the Mumbai region and the retention period written into the contract?
Which existing log tool retires, and when does its contract end?
Who learns DQL, and is training budgeted?
Inventory your log sources and set retention per source first, or let a TechBag advisor model pay-per-query against bundled on a month of your real queries.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.