Pricing

$6,000 per node unit per year. That's it.

A node unit is up to 16 vCPU. A bigger box counts as more units. Nothing is metered by volume, by event, or by host — and HA needs three nodes, which is physics, not a sales floor.

Community
Free

forever, on one node unit

No volume limit. No retention limit. No agent limit. No license key needed.

  • Logs, metrics, infrastructure, traces and APM
  • SonQL — all 100+ commands
  • Dashboards and alerting
  • Basic SAML / OIDC SSO
  • Offline update bundles
  • Community support
Copy Install Command
Enterprise
From $60,000

per year, ten node units and up

Everything in Team, plus the tooling that large and disconnected estates need.

  • Air-gap update tooling — signed pipelines, staged rollout, rollback
  • Multi-tenancy
  • Source escrow
  • Custom retention architecture
  • Named support engineer
Book 30 Minutes

Node Unit Pricing. $6,000 per node unit per year. That's it. A node unit is up to 16 vCPU; a bigger box counts as more units. Nothing is metered by volume, event count, or host. High Availability requires 3 nodes ($18,000/yr) due to cluster consensus physics, not sales floors.

The unit

What counts as a node.

If a node were "whatever machine you install it on," someone would run one 128-vCPU box and pay $6,000 while a team running three small boxes paid $18,000 for less capacity. So the unit is defined, in one line, on this page rather than in the license agreement.

Definition

Up to 16 vCPU = one node unit.

RAM isn't counted. Gigabytes aren't counted. Events aren't counted. Hosts aren't counted. One dimension, because two dimensions invite arguments.

Worked example

16 vCPU1 unit$6,000
32 vCPU2 units$12,000
64 vCPU4 units$24,000
3 × 16 vCPU (HA)3 units$18,000

Why the rate stays flat

16 vCPU handles about 50 GB/day, so a node unit works out at roughly $0.33 per GB ingested. A 64-vCPU box at ~200 GB/day is four units and still $0.33. The model neither rewards nor punishes how densely you pack, which is the property you want from a capacity license.

This is capacity licensing, not consumption metering, and the difference is the whole argument. We attack per-gigabyte pricing because it makes every decision about visibility a decision about money. Charging for the compute you chose to provision doesn't do that — nobody has ever hesitated to turn on debug logging because of a vCPU count. Per-core licensing is also how Oracle, VMware, SQL Server and Confluent have always worked, so it carries no explanatory burden.

Run your own numbers

The comparison, with every rate cited.

50 GB/day
5 GB/day 250 GB/day 500 GB/day
12 months
1 month 12 months 24 months

Why does this default to 12 months? Because per-gigabyte vendors charge again for time, and we think you should keep a year. Drag it down to 30 days and we land at rough parity with Grafana Cloud — that's the honest picture, and it's exactly why the argument here is retention rather than ingest.

Sondar (Capacity Model) $11,620 / yr

1 node unit · $6,000 license + $4,500 hardware + $1,120 storage

Grafana Cloud $9,125 / yr

Ingest only ($0.50/GB), 30-day retention included

Datadog Logs $32,850 / yr

Ingest + indexing ($1.70/M events), 15-day retention, 1 KB events

Splunk Cloud $50,000 / yr

Ingest-based pricing (~$1,000/GB/day/yr)

Sondar License Your Hardware Your Object Storage Metering Competitors
Assumptions, rates, and what this deliberately understates
Sondar license $6,000 per node unit per year. A node unit is up to 16 vCPU; a 16 vCPU / 32 GB box handles about 50 GB/day, so node count is ceil(GB per day ÷ 50). Published price, July 2026.
Your hardware $4,500 per node per year — the midpoint of a $2,000–$7,000 range covering a 16-core server amortised or its cloud-instance equivalent. This is an estimate, and it is the one number in this table that is ours rather than a vendor's.
Your object storage $0.023 per GB-month (S3 Standard, us-east-1, July 2026) applied to the retained volume after the measured 4.5x compression. Cheaper on infrequent-access tiers, which we don't assume.
Grafana Cloud ~$0.50 per GB ingested, 30-day retention included. July 2026.
Datadog Logs $0.10 per GB ingested plus $1.70 per million events indexed at 15-day retention on an annual commitment, July 2026. Event count is derived at 1 KB per event, which is the single biggest lever in this row — the indexing line scales with event count rather than volume, so if your logs average 500 bytes, double this figure. On-demand indexing is $2.55 per million rather than $1.70.
Splunk Cloud ~$1,000 per GB/day per year on ingest-based pricing, July 2026. Workload pricing (SVCs) can be materially cheaper at scale and is not modelled.

What this understates. The three competitor bars are ingest only, at their included retention window — they do not charge you for the retention you selected above, even though all three do in reality. We model it that way because we won't publish a guess at a rate we can't cite. So the comparison is more favourable to them than their real invoice would be. Sondar's bar, by contrast, is the whole cost: license, hardware, and storage for the full retention window.

What it leaves out on both sides. Operator time. Running Sondar is one container, but it isn't zero — and neither is the alternative of continuing to run what you have.

What's in each tier

The gates, in full.

Community is gated on one node and nothing else. Basic SSO is in the free tier because paywalling SAML is a tax on security, and we're not going to charge you to log in safely.

Capability Community Team Enterprise
Logs, metrics, infrastructure, traces, APM
SonQL, all 100+ commands
Dashboards and alerting
Basic SAML / OIDC SSO
Offline update bundles
Volume, retention and agent limits None None None
Object-storage cold tier, queried in place
Clustering and HA From 3 nodes
SCIM provisioning
Fine-grained RBAC and audit log
Data masking
Support with a response SLA
Air-gap update tooling
Multi-tenancy
Source escrow

Pricing questions.

Q1 Is Sondar open source?

No. Sondar is commercial software and we don't publish the engine's source — we'd rather say that plainly than blur it. What we do publish: an independent source code audit by a US security firm, a full third-party penetration test, an SBOM with every release, signed reproducible builds, our source-escrow terms, and a written cap on renewal pricing. And your data stays in your own object storage in open formats, so nothing you've collected depends on us.

Q2 How is this different from SigNoz, OpenObserve, or Grafana?

They're good, and if you're happy with them you should stay. The difference is the analytics layer and the operating burden. SigNoz means you now run and scale ClickHouse and Kafka; Grafana's LGTM stack is four systems to operate. Sondar is one engine with one store for logs, metrics and traces, and a Splunk-class query language — stats, join, transaction, timechart — rather than a filter syntax. On raw storage efficiency, OpenObserve and VictoriaLogs publish bigger numbers than ours. We're not claiming to beat them there.

Q3 Is SonQL the same as Splunk’s SPL?

No. SonQL is Splunk-inspired, not Splunk-compatible — your existing Splunk searches will not run unmodified, and we're telling you that here rather than letting you find out on day one. What does transfer is everything you know about how to search machine data. Most Splunk users are productive in SonQL in an afternoon. There's a command-by-command translation table in the docs and a converter you can paste a query into.

Q4 What are the actual hardware requirements?

One server with 16 vCPU and 32 GB of RAM handles about 50 GB/day. Retention is bounded by your disk and your object storage, not by us. Above that, Sondar clusters — the architecture runs past 50 TB/day. The full sizing table is in the docs, including agents per node and the marginal cost of each one.

Q5 What counts as a node?

Up to 16 vCPU. A bigger machine counts as more nodes — a 64-vCPU box is four. That's the only dimension: we don't count RAM, gigabytes, events, or hosts. The effective rate works out the same whether you run four small boxes or one large one, so the model neither rewards nor punishes how you pack them.

Q6 Will my bill go up as we grow?

Yes, in steps — if you outgrow your nodes you add nodes. What won't happen is a bill that moves because you ingested more, kept data longer, added tags, or stopped sampling. Nothing you do inside the product generates a line item.

Q7 Can I run this air-gapped?

Yes, genuinely. Licenses are signed keys your instance verifies offline against a public key baked into the binary — there is no activation server to reach, so Sondar never calls home. Offline update bundles are available on every tier including Community; patching a disconnected install is not a paid feature. Enterprise adds tooling around those bundles — signed pipelines, staged rollout, rollback orchestration.

Q8 What happens to my data if Sondar goes away?

It's already on your infrastructure — we never had it. Cold-tier data sits in your object storage in a format you can read without us, your instrumentation is OpenTelemetry so it repoints anywhere, and our escrow agreement releases source on insolvency or discontinuation. The terms are published, not just referenced.

Q9 What happens if my single node dies? There’s no HA on one node.

Correct, and worth being explicit about since we sell a single-node production tier. Two things make it less bad than it sounds. Most of your data already lives in your own object storage — the hot window on local disk is the only part at risk, and it's days, not months. And we continuously snapshot that window plus config and metadata to your bucket, so recovery is: start a new node, point it at the same bucket. RPO under 5 minutes, RTO under 15. We run a restore in CI on every release. If you need genuine HA, that's three nodes — physics, not a sales floor.

Q10 Why is SSO free but SCIM isn’t?

Because paywalling SAML is a tax on security, and we're not going to charge you to log in safely. Basic SSO is in Community. What's on Team is the administration layer around it — SCIM provisioning, fine-grained RBAC, audit logging, data masking — which is genuinely what larger deployments need and genuinely what costs us to build and support.

Q11 Do you have SOC 2? HIPAA?

Not yet on SOC 2 — our observation window opens January 2027, with a Type II report expected Q3 2027. Worth noting what SOC 2 does and doesn't cover here: it audits how a vendor handles your data, and we never receive your data. For the same reason we're generally not a HIPAA Business Associate and no BAA is required — the PHI never leaves your environment. What we have today: a third-party penetration test, an independent source code audit, an SBOM with every release, signed reproducible builds, and a published vulnerability disclosure policy.

Q12 Who builds this, and where are you based?

Sondar is built in Mountain View, California. The whole team is in the Bay Area — founder, engineering and support — and I answer the tickets myself. The more useful half of that answer is what it means for your risk: Sondar runs entirely inside your network and we never receive your data, so there is no vendor to breach that holds your telemetry. For the binary itself we publish an independent source code audit scoped to backdoors and undisclosed telemetry, a full penetration test, an SBOM with every release, and signed reproducible builds. We're small and new, and we'd rather hand you those than ask you to take our word for it.

Something not answered here? Ask the person who built it →