shouldiuse.io

Report

Should I Use SigNoz?

signoz.io·Analyzed 22 hours ago··Based on 12 sources

SigNoz Cloud is a one-stop observability tool built on top of OpenTelemetry. Get APM, logs, traces, metrics, exceptions, AI observability & alerts in a single tool.

Depends

Depends

Buy if you're an engineering team comfortable with OpenTelemetry and some ops work who wants to cut Datadog-class bills.

Solid budget Datadog alternative for OTel-savvy teams; expect rough UI, unstable log queries, and recent CVEs.

Confidence: Medium

3.4/5

Community rating

RFP.wiki, vs Middleware's 3.8

From $4

Cloud starting price

usage-based; open source self-host is free

Yes

Free tier

self-hosted OSS + 30-day cloud trial

350+

Paying customers

per co-founder on LinkedIn

Value for money4

Costs less than rivals, free self-host option

Ease of use2

UI complaints; 'perfect tool on paper'

Feature depth4

APM, logs, traces, metrics, alerts in one

Security posture2

SOC 2 claimed, but four recent CVEs

Pros

  • All-in-one: APM, logs, traces, metrics, exceptions, alerts, AI observability¹
  • Open source, OpenTelemetry-native; self-host to avoid lock-in³
  • Costs less than competing platforms at low volume12
  • Real case studies: Shaped AI, Outplay, TableFlow consolidated tooling

Cons

  • Users report unstable log queries
  • Production users report UI problems
  • Rated 3.4/5, below rival Middleware at 3.811
  • Self-hosting requires running ClickHouse yourself

Gotchas

  • highSQL injection CVEs in alert endpoints, unfixed until 0.142.110
  • highAuth-bypass/open-redirect CVE can steal session tokens
  • mediumSelf-hosting means running ClickHouse and upgrades yourself
  • mediumCloud pricing is usage-based; heavy ingest can inflate the bill²

Best for

  • Engineering teams ditching Datadog bills
  • OpenTelemetry-standard shops
  • Self-hosters with ops capacity
  • Startups consolidating logs, traces, metrics

Not for

  • Teams with nobody to run ClickHouse and upgrades
  • Buyers expecting polished, stable UX today
  • Orgs that can't patch within days of a CVE
  • Non-engineering teams; this is dev-only tooling

Companies that use it

  • Shaped AI
  • Outplay
  • TableFlow
  • Kernel
  • Wombo

Pricing

Open Source (self-hosted)

$0

  • Full platform, you run it
  • You own upgrades and ClickHouse ops

Cloud / Teams

From $4, usage-based

  • Managed hosting
  • 30-day free trial

Enterprise

Not disclosed

  • Built for scale
  • Enterprise-grade support

Security

SOC 2 Type II claimed, but multiple 2026 CVEs (SQL injection, auth bypass) mean you must patch fast.

  • CVE-2026-57955: SQL injection in alert history endpoints (through 0.130.1)Rule ID parameter injectable in alert history endpoints.
  • CVE-2026-63094: auth bypass via open redirectOpen redirect enables session token theft.
  • CVE-2026-57956: vulnerability before 0.133.0SigNoz before 0.133.0 contains a vulnerability; fix in 0.133.0.
  • CVE-2026-93292: SQL injection (0.88.0 before 0.142.1)Wide affected range; fixed in 0.142.1.10

What users say

Users like the price and OpenTelemetry approach but report unstable log queries and UI rough edges in production.

Signoz log queries seem unstable.
Reddit, r/kubernetes
Looks like a perfect tool on paper,
Reddit, r/kubernetes

Alternatives

Compare SigNoz with each alternative.

Grafana stack

Mature free self-hosted logs, metrics, traces; more assembly

Full analysis

Based on ~30 public sources: Reddit threads, CVE databases, official case studies, and pricing pages.

Sources

  1. official
  2. official
  3. official
  4. review
  5. review
  6. review
  7. news
  8. security
  9. security
  10. security
  11. review
  12. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Ask a follow-up

Ask if a use case fits. Answers stay inside this report and its sources.

    Comments

    One queue. No replies. Give a display name first. Limit: 7 comments per day.

    Save a name to write a comment.

    No comments yet.