Skip to content
RiverCore
Datadog vs Cisco: The Observability Bill Comes Due
observability costsDatadog ARRCisco SplunkDatadog vs Cisco enterprise observability billobservability platform pricing comparison

Datadog vs Cisco: The Observability Bill Comes Due

11 Aug 20266 min readAlex Drover

Every platform lead who has signed a Datadog renewal in the last three years knows the specific stomach-drop of opening that invoice. The observability bill is now a line item that shows up in board decks, right next to cloud spend and payroll. This week's Datadog-versus-Cisco comparison from the equity analyst crowd is really a proxy fight about what enterprises are willing to pay for telemetry, and who owns the pipes it flows through.

What Happened

Two very different observability stories landed in the same quarter, and the market is being asked to price them side by side. Datadog reported that total ARR crossed $4 billion in Q1 fiscal 2026, with revenue growing 32% year over year and free cash flow margin holding at 29%, as TradingView reported. Its catalog now spans 26 products across infrastructure, APM, logs, security, and AI observability. Five of those products individually clear $100 million in ARR. Three more sit between $50 million and $100 million.

Cisco, on the other side, posted Q3 fiscal 2026 revenue of $15.8 billion, up 12% year over year, with product orders growing 35%. Its ARR reached $31.2 billion and subscription revenue is now 49% of the total. The Splunk acquisition has been absorbed into a broader observability-plus-security pitch, backed by Hypershield and AI Defense, with pending buys of Galileo and Astrix set to add agentic identity, access management, and behavior monitoring.

The consensus revenue estimate for Datadog's fiscal 2026 is $4.31 billion (25.7% growth). Cisco's is $62.95 billion (11.11% growth). Year to date, DDOG shares are up 64%, CSCO up 55.2%. DDOG trades at a forward price-to-sales of 16.86X. CSCO trades at 7.01X. Both carry a Zacks Rank #2 (Buy). The financial press is calling Cisco the better buy on valuation. For engineering leaders, the more useful question is what these two numbers say about where the money in observability is actually going.

Technical Anatomy

The two platforms solve the same surface problem with radically different architectures. Datadog is a cloud-native SaaS agent-and-ingest model. You install the agent, it ships metrics, logs, traces, and profiles into Datadog's backend, and you pay per host, per GB, per span, per custom metric, per synthetic check. The 26 products aren't really 26 products in the engineering sense. They're 26 SKUs against a shared telemetry lake. That's why cross-sell works so well: once your data is in, unlocking APM or Cloud SIEM or LLM Observability is a billing toggle, not a new integration.

The AI observability slice is where Datadog is placing its biggest bet. GPU Monitoring, LLM Observability, and Bits AI target teams running inference at scale, and the MCP Server tool calls quadrupling sequentially in Q1 is the tell. Model Context Protocol adoption means agents are increasingly reaching into observability data as a runtime dependency, not just a dashboard. If you're building agent workflows, the observability platform becomes part of the control plane. That's a defensible moat if it holds.

Cisco's stack is architecturally the opposite: bottom-up, from the network fabric and identity layer. Splunk gives it the log analytics engine, Hypershield sits at the workload and kernel level, AI Defense inspects model traffic, and Galileo plus Astrix would extend into non-human identity and agentic behavior monitoring. It's a data-gravity play built on Cisco's existing installed base of switches, firewalls, and identity infrastructure. If you already have Cisco everywhere, adding observability is a procurement decision, not a rip-and-replace.

The OpenTelemetry standard sits underneath both bets and quietly changes the math. When your instrumentation is vendor-neutral, the switching cost drops. My take: OTel adoption is the single biggest threat to Datadog's pricing power over the next 24 months, and the single biggest opportunity for Cisco to pull workloads off SaaS observability into its own analytics backend.

Who Gets Burned

Datadog's 32% growth and 29% free cash flow margin are genuinely impressive numbers. Production incidents I've seen over the last five years almost always end with someone opening Datadog first, because it's what's already wired up. That reflex is the moat. But a 16.86X price-to-sales multiple only holds if net revenue retention stays north of 115% forever, and the operational reality is that CFOs are now sending engineering leads into renewal cycles with explicit cost-cut mandates.

The non-AI cohort accelerating to the mid-20% range is the number I'd watch most closely. It says the growth isn't purely an AI-hype tax. But it also says Datadog needs the base business to keep compounding while it out-innovates on the AI side, which is a two-front war.

Cisco's exposure is different. A $31.2 billion ARR base with 49% subscription mix means the transformation from box-shifter to software company is real, but the pending Galileo and Astrix acquisitions have to actually integrate. Teams I've worked with treat Cisco integrations as a two-year timeline in the best case. Splunk itself is still being digested. If AI Defense and Hypershield end up as three separately-licensed products with three admin consoles, the "unified observability" pitch collapses on contact with a real SRE team.

The engineering orgs that get burned worst in the next 90 days are the ones running dual stacks: Datadog for app telemetry, Splunk for security logs, and some flavor of Prometheus and Grafana in the middle. Every renewal cycle becomes a three-way negotiation. Every incident postmortem becomes an argument about which tool was source of truth. The uncomfortable read: most mid-sized platforms are paying for two full observability stacks and getting the operational benefit of about one and a quarter.

Playbook for Engineering Teams

Do the math first. If your Datadog bill is running at $2 million a year on a 40-person engineering team, that's roughly two senior engineer salaries flowing out the door as a fixed cost. Cisco's push and Datadog's premium multiple should tell you the vendors know exactly what they can charge. Your job this quarter is to make sure they can't charge more next quarter.

Concretely, this week:

  • Instrument new services with OpenTelemetry SDKs, not vendor-specific agents. Keep the export target swappable.
  • Audit your Datadog custom metrics cardinality. High-cardinality tags are where the surprise invoices come from.
  • Pull a report of every product SKU you're paying for. If you're on APM, DBM, RUM, Cloud SIEM, and LLM Observability, ask which two you'd cut in a budget freeze. Have an answer before procurement asks.
  • If you're a Cisco shop, get a briefing on Hypershield and AI Defense before your account rep bundles them into next year's ELA at list price.
  • For AI workloads, decide now whether GPU and LLM telemetry lives in your observability platform or in a separate ML ops tool. Splitting it later is painful.

Datadog's FedRAMP High certification and U.K. data center expansion matter if you have regulated workloads. If you don't, they're just talking points. Don't pay a premium for capabilities you'll never use.

Key Takeaways

  • Datadog crossed $4 billion ARR with 32% growth and a 29% free cash flow margin, but its 16.86X forward P/S versus Cisco's 7.01X prices in flawless execution.
  • Cisco's $31.2 billion ARR and 49% subscription mix show the Splunk-plus-networking bet is producing real recurring revenue, with 35% product order growth as the near-term tailwind.
  • The MCP Server tool calls quadrupling in one quarter is the strongest signal that agent workflows will bind observability platforms deeper into runtime, not just dashboards.
  • OpenTelemetry is the quiet use point. Every team that standardizes on it now buys optionality against future price hikes from either vendor.
  • Pending Cisco acquisitions of Galileo and Astrix are worth watching but not worth pre-committing budget to until the integration story is proven in production.

Frequently Asked Questions

Q: Is Datadog's 16.86X price-to-sales multiple justified by its growth rate?

At 32% revenue growth and 29% free cash flow margin, Datadog is executing well, but a 16.86X multiple leaves no room for a growth deceleration. Cisco at 7.01X reflects slower 11.11% projected growth but a much larger recurring revenue base. The valuation gap only makes sense if Datadog's AI observability lead compounds for several more years.

Q: Does the Splunk acquisition actually make Cisco competitive with Datadog on observability?

On paper, yes. Splunk gives Cisco a mature log analytics engine, and combined with Hypershield and AI Defense it covers observability plus security. Operationally, the integration is still in progress, and teams evaluating Cisco should ask hard questions about unified tooling and single-pane-of-glass claims before signing multi-year commitments.

Q: Should engineering teams standardize on OpenTelemetry regardless of which vendor they use?

Yes. OpenTelemetry decouples instrumentation from backend, which preserves your ability to switch vendors or run hybrid stacks without rewriting agent configurations. Both Datadog and Cisco support OTel ingest, so adopting it costs little and pays off during renewal negotiations or platform migrations.

AD
Alex Drover
RiverCore Analyst · Dublin, Ireland
SHARE
// RELATED ARTICLES
HomeSolutionsWorkAboutContact
News06
Dublin, Ireland · EUGMT+1
LinkedIn
🇬🇧EN▾