SolarWinds Loggly

SolarWinds Loggly is a cloud-based log aggregation and analysis platform designed for centralized visibility across distributed infrastructure and applications.

Reviewed by 7wData

On this page

Publisher review

SolarWinds Loggly is a cloud-based log aggregation and analysis platform designed for centralized visibility across distributed infrastructure and applications. Founded in 2009 and acquired by SolarWinds in 2018, it serves over 5,000 companies with automatic log parsing (Dynamic Field Explorer), real-time search, alerting, and pre-built dashboards. Loggly's primary strength is ease of setup—logs ship via syslog, HTTP, or pre-configured agents without requiring infrastructure expertise—making it popular with startup and small-to-mid teams that need quick log visibility.

Integration breadth is extensive: AWS CloudTrail, Azure App Insights, Kubernetes, Docker, Slack, PagerDuty, and GitHub code linking. However, trade-offs limit its appeal at scale. The SaaS-only deployment model excludes teams needing on-premises infrastructure for compliance or security.

Critically, pricing enforces hard caps on data ingestion—logs exceeding your plan limit are dropped, not charged as overages, creating blind spots during traffic spikes. A 1.5 GB/day volume on the Standard plan (1 GB limit) silently loses 33% of logs daily. At 250 GB/day with 30-day retention, Loggly Enterprise costs ~$97,000 annually compared to ~$27,000 for SigNoz Cloud or $15,000 for self-hosted ELK, making it uncompetitive at scale.

Dashboard UI is considered dated; alerting is basic without incident management, on-call scheduling, or SMS delivery. Query speed is slow on large log volumes. Feature parity issues mean advanced capabilities (anomaly detection, peak overage protection, S3 archiving) are locked behind Enterprise tiers.

The free tier (200 MB/day, 7-day retention) is useful for evaluation but insufficient for production use. Loggly remains a solid choice for small teams prioritizing simplicity and cloud-native integration over cost efficiency or comprehensive observability, but it faces pressure from faster alternatives like Better Stack, more feature-complete platforms like Datadog, and lower-cost self-hosted solutions like ELK.

Get the AI & data signal, daily.

335k+ subscribers read this every morning. One email, both newsletters. Unsubscribe anytime.

How it works

  1. Automatic log parsing

    Dynamic Field Explorer automatically extracts structured fields from 100+ common log types (Apache, Nginx, JSON, Kubernetes, Docker) without regex, making logs searchable immediately after ingestion.

  2. Real-time log search and surround search

    Search across all ingested logs in real-time; surround search returns events before and after a matched timestamp, useful for tracing event sequences during incidents.

  3. Multi-cloud log shipping

    Native integration with AWS CloudTrail, S3, Lambda; Azure App Insights, VMs; Google Cloud Compute Engine and GKE; supports syslog, HTTP API, and pre-built agents for Docker and Kubernetes.

  4. Custom alert routing

    Route alerts via Slack, PagerDuty, Microsoft Teams, email, custom webhooks, and AlertOps; support for SolarWinds AppOptics (APM) integration for linked alerting across metrics and logs.

  5. S3 archiving and extended retention

    Archive logs to AWS S3 after your plan retention expires (15-90 days) for historical access at lower cost; available on Pro and Enterprise tiers.

  6. Derived fields and custom parsing

    Create custom parsing rules without regex using key-value extraction, anchor patterns, or regex; extract meaningful fields from unstructured logs for alerting and dashboarding.

  7. Pre-built dashboards and anomaly detection

    Quick-start dashboards for Nginx, Apache, Docker, Kubernetes, and other popular stacks; ML-based anomaly detection available on Enterprise tier only.

Strengths and trade-offs

Strengths

  • No-agent setup: logs ship directly via syslog or HTTP; automatic field parsing eliminates manual extraction work.
  • Extensive pre-built integrations for AWS, Azure, GCP, and container platforms reduce time-to-value for cloud-native teams.
  • Free tier (200 MB/day, 7-day retention) and low Standard tier ($79/month) make entry cheap; suitable for startups and small teams.

Trade-offs

  • Hard data-loss caps on overages: logs exceeding plan limits are dropped, not charged as overages, creating blind spots during traffic spikes and losing audit trails when needed most.
  • High cost at scale: 250 GB/day costs ~$97,000/year (Enterprise), 3.6x more than Better Stack (~$27,000) or self-hosted ELK (~$15,000), making it uncompetitive for mid-to-large enterprises.
  • SaaS-only deployment and dated dashboard UI: no on-premises option for compliance-heavy industries; dashboard feels 2010-era; slow query performance on high-volume log sets; basic alerting without incident management, on-call scheduling, or SMS delivery.

Pricing context

Loggly uses tiered pricing: Lite (free, 200 MB/day, 7-day retention), Standard ($79/month, 1 GB/day, 15-day retention), Pro ($159/month, up to 100 GB/day customizable, 15-30 days, peak overage protection and S3 archiving), and Enterprise ($279+/month, terabyte scale, 15-90 days, unlimited rules, ML anomaly detection). Critically, all tiers except Enterprise enforce hard caps on daily ingestion—logs exceeding the plan limit are silently dropped, not charged as overages. A team ingesting 1.5 GB/day on Standard loses 33% of logs daily.

Retention extensions require tier upgrades (30-day to 90-day retention upgrade = ~$3,000/year for same volume). Annual billing discounts available. No per-GB overage pricing; this cost model differs sharply from Datadog (charged per GB ingested) and better-stack (usage-based without data loss).

Alternatives

User reviews

No user reviews yet. Be the first to write one.

Sources

Reporting on this tool draws on these publicly available sources.

  1. www.loggly.com — Official pricing tiers, daily ingestion limits, retention periods, and feature availability by plan.
  2. www.g2.com — User reviews on G2 (4.4/5 stars) highlighting UI speed issues, dashboard limitations, SaaS-only deployment, and lack of real-time monitoring as key complaints.
  3. signoz.io — Independent pricing analysis comparing Loggly cost-per-GB to alternatives (SigNoz Cloud $0.30/GB, self-hosted ELK baseline costs); concrete TCO examples at 250 GB/day scale.
  4. www.trustradius.com — TrustRadius user reviews on dashboard UX, search speed limitations, learning curve, and feature parity with enterprise-tier competitors.
  5. betterstack.com — Better Stack independent comparison; identifies data-loss risk on hard caps, feature gaps vs. unified observability platforms, and alternatives ranked by use case.
  6. en.wikipedia.org — Company founding year (2009), founders (Jon Gifford, Raffael Marty, Kord Campbell), original HQ (San Francisco), and SolarWinds acquisition date (January 2018).
  7. documentation.solarwinds.com — Official product documentation on features, integrations, API, Dynamic Field Explorer automatic parsing, and S3 archiving capabilities.
  8. www.dash0.com — Competitive analysis of 10 Loggly alternatives (Better Stack, Datadog, Splunk, ELK, Papertrail, Sumo Logic, New Relic, Logz.io); reasons users switch away.