No more typing reviews! Try our Samantha, our new voice AI agent.

Datadog vs ThreatSync NDR comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 18, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Datadog
Ranking in Network Monitoring Software
2nd
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
211
Ranking in other categories
Application Performance Monitoring (APM) and Observability (1st), IT Infrastructure Monitoring (1st), Log Management (4th), Container Monitoring (3rd), Cloud Monitoring Software (1st), AIOps (1st), Cloud Security Posture Management (CSPM) (6th), AI Observability (1st)
ThreatSync NDR
Ranking in Network Monitoring Software
55th
Average Rating
8.6
Reviews Sentiment
8.7
Number of Reviews
2
Ranking in other categories
Network Detection and Response (NDR) (18th)
 

Mindshare comparison

As of October 2026, in the Network Monitoring Software category, the mindshare of Datadog is 2.2%, down from 3.1% compared to the previous year. The mindshare of ThreatSync NDR is 0.3%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Monitoring Software Mindshare Distribution
ProductMindshare (%)
Datadog2.2%
ThreatSync NDR0.3%
Other97.5%
Network Monitoring Software
 

Featured Reviews

Dhroov Patel - PeerSpot reviewer
Site Reliability Engineer at Grainger
Has improved incident response with better root cause visibility and supports flexible on-call scheduling
Datadog needs to introduce more hard limits to cost. If we see a huge log spike, administrators should have more control over what happens to save costs. If a service starts logging extensively, I want the ability to automatically direct that log into the cheapest log bucket. This should be the case with many offerings. If we're seeing too much APM, we need to be aware of it and able to stop it rather than having administrators reach out to specific teams. Datadog has become significantly slower over the last year. They could improve performance at the risk of slowing down feature work. More resources need to go into Fleet Automation because we face many problems with things such as the Ansible role to install Datadog in non-containerized hosts. We mainly want to see performance improvements, less time spent looking at costs, the ability to trust that costs will stay reasonable, and an easier way to manage our agents. It is such a powerful tool with much potential on the horizon, but cost control, performance, and agent management need improvement. The main issues are with the administrative side rather than the actual application.
Michael-Foster - PeerSpot reviewer
Head of IT at Bulkhaul Limited
Has improved threat detection and reduced manual workload through real-time cloud insights
ThreatSync+ NDR has helped identify potential security gaps in my network, and we are currently working on resolving them. The impact on incident response time varies. During daytime operations, it reacts instantly with a notification delay of 10 to 20 minutes, while nighttime notifications can have up to eight hours delay. ThreatSync+ NDR has enhanced our ability to proactively manage network risks by enabling us to implement extra measures at a lower level based on its findings. The compliance reporting tools are comprehensive and meet our requirements. Though we haven't conducted official compliance reporting yet, we anticipate it will save approximately one day of work in report compilation. Regarding pricing, WatchGuard rates a nine out of ten. We maintain 1,001 licenses for ThreatSync+ NDR, serving approximately 1,000 users, with about 300 local users in the UK. ThreatSync+ NDR's effectiveness in identifying weaknesses before exploitation is excellent and very quick. I recommend ThreatSync+ NDR to other users based on its rapid deployment and immediate value delivery. I rate ThreatSync+ NDR 9 out of 10.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Our teams use Datadog more than they used their old observability tool—they're more production-aware, conscious of how their changes are impacting customers, how the changes they make to their application speed up or slow down their app, and the overall request flow."
"The web app has a real-time support chat window in which a support engineer is chatting with you within a minute."
"Several critical dashboards were created years ago and are still in use today."
"The ease of correcting these dashboards and widgets when needed is amazing."
"The solution is good for complex integations which have lots of downstream and involve multiple combined systems."
"Datadog has had a significant positive impact on our organization overall, particularly in visibility, reliability, and cost efficiency, allowing us to centralize metrics, logs, and traces across our cloud, moving from reactive to proactive monitoring, with improvements including faster incident detection and resolution, enhanced service reliability, better cost and resource optimization, and shared dashboards providing the engineering and product teams a single source of truth for system health and performance, thus enhancing our overall observability and operational efficiency."
"We have hundreds of microservices, and knowing how top-level requests weave throughout all of them is invaluable."
"Datadog has helped us a ton by allowing us to set up a multitude of easily configurable alarms across our tech stack and infrastructure."
"Implementing ThreatSync+ NDR has influenced our business significantly as it provides enhanced security and saves several hours daily by eliminating manual log reviews."
"ThreatSync NDR is a strong addition to our company's security architecture."
 

Cons

"Pricing seemed easy until the bill came in and some things were not accounted for."
"There could be more easily identifiable documentation on how to find different things on the platform."
"It would be great if usage metrics were automatically created and we could create custom metrics, instead we ended up building some of our own stuff to track and alert on our own usage."
"Its pricing model can be improved. Its settings should be improved for a better understanding of billing. They should also provide some alerts when there is an increase in the usage. For example, if there is 20% more increase from one week to another, the customer should get an alert."
"There are so many different solutions; it is sometimes difficult to gauge where to start, and I sometimes miss a lot of functionality."
"It is very difficult to make the solutions fit perfectly for large organizations, especially in terms of high cardinality objects and multi-tenancy, where the data needs to be rolled up to a summarized level while maintaining its individual data granularity and identifiers."
"One area where I was really looking for improvement was the CSPM product line. I had really wanted to have team-level visibility for findings, since the team managing the resources has much more context and ability to resolve the issue, as the service owner. However, this has been added to the announcement in a recent keynote."
"Our main challenge is implementing the solutions in our Kubernetes cluster, separated just as logs to the specific namespace since the volume of logs is tremendous."
"After using ThreatSync+ NDR for about a year, areas for improvement include the ability to pull logs from other vendors using an API."
"There are definitely areas for improvements in ThreatSync NDR, as no product is perfect. Its effectiveness depends on proper network visibility, so if important traffic segments are not mirrored or monitored, detection may be incomplete."
 

Pricing and Cost Advice

"Pricing and licensing are reasonable for what they give you. You get the first five hosts free, which is fun to play around with. Then it's about four dollars a month per host, which is very affordable for what you get out of it. We have a lot of hosts that we put a lot of custom metrics into, and every host gives you an allowance for the number of custom metrics."
"The price is better than some competing products."
"The cost is high and this can be justified if the scale of the environment is big."
"The solution's pricing depends on project volume."
"It costs the same amount it would if we were hosting it ourselves, so we are incredibly happy with the cost."
"The tool is open-source."
"My advice is to really keep an eye on your overage costs, as they can spiral really fast."
"It didn't scale well from the cost perspective. We had a custom package deal."
Information not available
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
915,383 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Manufacturing Company
10%
Outsourcing Company
8%
Computer Software Company
7%
Comms Service Provider
18%
Construction Company
13%
Outsourcing Company
12%
University
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business81
Midsize Enterprise50
Large Enterprise100
No data available
 

Questions from the Community

Any advice about APM solutions?
There are many factors and we know little about your requirements (size of org, technology stack, management systems, the scope of implementation). Our goal was to consolidate APM and infra monitor...
Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several times lately using the dashboards we have created with Datadog; they are very good c...
Which would you choose - Datadog or Dynatrace?
Our organization ran comparison tests to determine whether the Datadog or Dynatrace network monitoring software was the better fit for us. We decided to go with Dynatrace. Dynatrace offers network ...
What needs improvement with ThreatSync+ NDR?
There are definitely areas for improvements in ThreatSync NDR, as no product is perfect. Its effectiveness depends on proper network visibility, so if important traffic segments are not mirrored or...
What is your primary use case for ThreatSync+ NDR?
I use ThreatSync NDR for monitoring across our hybrid and cloud infrastructure. For monitoring in our hybrid and cloud infrastructure using ThreatSync NDR, we investigate indicators such as IP addr...
What advice do you have for others considering ThreatSync+ NDR?
If I am evaluating an NDR solution for medium to large enterprises, especially with our experience using it with our WatchGuard security products, ThreatSync NDR delivers strong visibility, intelli...
 

Overview

 

Sample Customers

Adobe, Samsung, facebook, HP Cloud Services, Electronic Arts, salesforce, Stanford University, CiTRIX, Chef, zendesk, Hearst Magazines, Spotify, mercardo libre, Slashdot, Ziff Davis, PBS, MLS, The Motley Fool, Politico, Barneby's
Information Not Available
Find out what your peers are saying about Datadog vs. ThreatSync NDR and other solutions. Updated: September 2026.
915,383 professionals have used our research since 2012.