Datadog reached $3.42 billion in revenue in FY2025 by solving a problem DevOps teams had been living with for years: too many signals, too many sources, too little context at investigation time. It did not detect more problems than the tools before it. It made the problems that were already being detected comprehensible in one place. Security has the exact same structural problem, alert volume that has outrun analyst capacity, 28 separate monitoring tools per enterprise on average generating disconnected streams, and a burnout rate that is accelerating faster than hiring can cover. The difference is that nobody has built the Datadog equivalent for security yet. That gap is where the next $10B company is going to come from, and the founders who see it will not be building another detection tool.
Summary
- Datadog reached $2.68 billion in revenue in FY2024 and $3.42 billion in FY2025, growing from a standing start by solving cognitive load, not detection capability. The average enterprise SOC runs 28 separate security monitoring tools, each generating its own alert stream (Dropzone AI, 2026). The problem Datadog solved for DevOps is the same problem security has not solved.
- In 74% of breaches, alerts were generated but ignored because analysts were overwhelmed by volume (Verizon DBIR, 2024). Over 60% of alerts across live enterprise SOCs in 2025 were never reviewed (TechNadu, July 2026). Detection is not the bottleneck. Investigation capacity is.
- Current security vendors are structurally incentivized to produce more alerts, not fewer. SIEM pricing is ingest-based; telemetry growth directly drives cost growth (Databahn, 2025). A vendor whose revenue scales with alert volume cannot also solve the alert problem. The fix has to come from outside the existing stack.
- Chronicle, founded inside Alphabet in 2018 on the premise of petabyte-scale security telemetry normalization, was the clearest early attempt at this model. Google absorbed it before it could prove the hypothesis independently. The next company to build this will not have that exit available.
TLDR
The next dominant security company will not be built on a better detection engine. It will be built on a unified investigation layer that normalizes signals from across the security stack into one coherent context, the way Datadog normalized infrastructure metrics, application traces, and logs for DevOps teams. Current vendors cannot build this because their pricing models depend on alert volume. A single medium-to-high severity alert currently consumes 15 to 20 minutes of analyst time across multiple consoles. Platforms using AI-assisted investigation have reduced that to 3 to 4 minutes. That is not a detection improvement. It is a context delivery improvement. The founder who builds the investigation layer, not the detection layer, is building the category.
The Insight That Built Datadog: Sense-Making Beats Signal-Adding
Before Datadog, DevOps teams were doing what SOC analysts do now: context-switching between separate tools for infrastructure metrics, application performance, and logs. Each tool had its own interface, its own severity logic, its own data model. Correlating an application slowdown to a database query to an infrastructure change required pulling context from three places manually.
Datadog unified those three streams into one normalized data layer. The insight was not technical. It was structural. The problem was not a lack of detection capability. It was the cost of making sense of signals that were already there.
Revenue grew 75% year over year in Q3 2021 (Datadog SEC filing, November 2021). 3,490 customers reached $100k+ ARR by Q3 2024, growing 12% year over year (Datadog SEC filing, November 2024). Full-year revenue hit $2.68 billion in 2024 and $3.42 billion in 2025 (Datadog FY2024 earnings, February 2025; MacroTrends, 2026). That growth did not come from landing new categories. It came from expansion inside accounts that had already experienced what it felt like to investigate a production incident without switching consoles.
Security teams do not have that experience yet. A SOC analyst investigating a suspicious login event today opens their SIEM, switches to their EDR console, pulls context from their identity provider, checks their cloud activity log, and cross-references threat intelligence from a separate feed. Each tool speaks its own data language. The analyst builds the picture in their head, manually.
That is not a detection problem. It is an architecture problem. And it is exactly the problem Datadog was built to solve for DevOps.
Security Vendors Are Structurally Incentivized to Produce More Alerts, Not Fewer
This is the part nobody in the vendor community says out loud: the business model of most security tools is incompatible with solving the alert problem.
SIEM vendors charge by data ingestion volume. The more telemetry you ingest, the higher the bill. Traditional SIEMs use ingest-based licensing, meaning telemetry growth directly drives cost growth (Databahn, 2025). The financial incentive is to collect everything. Collecting everything produces more alerts.
Detection tool vendors are measured on coverage breadth. Adding a new detection rule that fires on a new attack pattern is a product release. Removing a detection rule that fires too broadly is not. The asymmetry is structural.
Ponemon research found that 25% of analyst time is wasted chasing false positives. The average enterprise SOC now costs $5.3 million annually, up 20% in one year, yet only half of teams consider their security engineering effective (Radiant Security, 2026). In 74% of breaches, alerts were generated but ignored, usually because analysts were overwhelmed by volume (Verizon DBIR, 2024). The detection was there. The capacity to act on it was not.
No currently dominant security vendor has a financial incentive to solve this. Solving it would mean sending fewer alerts, ingesting less data, and charging less. That is not a product strategy any public company with ingest-based pricing can execute without restructuring its revenue model.
The company that solves the alert problem will not come from inside the existing vendor stack.

What the Unified Investigation Layer Actually Looks Like
Datadog’s architectural insight was the unified data model. Every signal infrastructure metric, application trace, log line- is normalized into a common schema at ingestion time. The analyst investigating a problem does not have to understand five different data formats. They work in one.
The security equivalent is harder to build, but the shape is clear.
A unified security investigation layer normalizes events from endpoint, identity, cloud, network, and email into a single queryable schema at ingest time. When an analyst investigates a suspicious login, they do not switch consoles. They pivot from the identity event directly to the associated cloud API calls, then to the network connection, then to the endpoint process tree, all in the same interface, correlated by the same entity graph.
Chronicle’s 2023 unified update brought SIEM and SOAR into a single console, integrated Mandiant’s attack surface management technology, and enabled analysts to pivot between alerts, cases, investigations, and playbooks without leaving the interface (Google Cloud, September 2023). That is the architecture. The problem is that Chronicle is now Google Security Operations absorbed into a $2 trillion company where it competes for enterprise SIEM displacement, not for category definition.
The average enterprise runs 28 separate security monitoring tools, each generating its own alert stream (Dropzone AI, 2026). A unified investigation layer does not try to replace all of them. It sits across them. It normalizes their output, correlates their signals, and hands the analyst coherent investigation context rather than a raw alert queue.
A single medium-to-high severity alert currently consumes 15 to 20 minutes of analyst time, requiring switching between multiple log sources and tools. Platforms using AI-assisted investigation have reduced that to 3 to 4 minutes (Abnormal Security, 2026). That is not a detection improvement. It is a context delivery improvement, the same thing Datadog did for engineering teams.
Why Current Vendors Cannot Build This Even If They Wanted To
The SIEM vendors cannot build a unified investigation layer because their revenue model depends on data volume. Normalizing data at ingest time and routing it intelligently reduces ingest volume. Cribl crossed $200 million in ARR in early 2025, only six years after launch, precisely by helping organizations reduce what they send to their SIEM (Software Analyst, 2025). That number growing while SIEM ingest revenue stays flat is a signal.
The endpoint vendors cannot build it because their data model is device-centric, not entity-centric. CrowdStrike’s Falcon is built around the device as the primary organizing concept. An investigation that spans a user identity, a cloud API call, and a network connection requires bridging across three data models built independently. The Falcon platform can ingest telemetry from all three. Correlating them coherently at investigation time is a different problem.
The platform vendors, Palo Alto Networks and Microsoft, have the data. They have integrated acquisitions across endpoint, cloud, identity, and network. What they do not have is the architectural coherence of a product built from scratch around a unified data model. Chronicle was designed from the start to normalize, index, correlate, and analyze security telemetry against itself and against third-party threat signals, enabling instant context on any risky activity (Google Chronicle whitepaper, 2019). That architectural advantage was built before the acquisition. The acquisitions Palo Alto and Microsoft made were assembled after their core platforms were established.
The company that builds the Datadog equivalent for security will be built from scratch, with the unified data model as the founding architectural decision, not as a layer bolted onto an existing alert management system.

Who Is Positioned and What Needs to Break First
The candidates are not obvious yet, which is consistent with where Datadog was in 2014.
Cribl is already solving the data pipeline layer. $200M ARR in six years by routing and normalizing security telemetry before it reaches the SIEM. That is the input layer of the unified investigation stack. The question is whether anyone moves from the normalized data forward into the investigation layer itself.
Elastic has the data model and the query layer. Its common schema is closer to what Datadog uses for infrastructure data than anything the SIEM vendors have built. Elastic Security has not scaled into a dominant security position, but the architecture is closer to correct than most alternatives.
A startup building this today would start from the entity graph, a real-time model of every user, device, workload, and data store in the environment and their relationships. Detection logic runs against the graph, not against raw events. Investigations start from the entity, not from the alert.
The timeline is three to five years, contingent on two things. First, an enterprise buyer approving a budget line for investigation infrastructure separate from their SIEM contract. Second, a vendor demonstrating measurable mean-time-to-investigate reduction, not detection improvement, as the primary value metric.
Analyst burnout rates hit record highs in 2025, with the average analyst staying in role only three to five years (Torq, 2026). Retention is already the forcing function. The enterprise that loses three experienced analysts in one year has a budget problem that a better SIEM does not solve.
Chronicle was the first real attempt. It became a Google product before the market could answer the question. The next attempt will not have that exit.
FAQs
Datadog grew through bottom-up developer adoption. Security buying is CISO-led and top-down. Does the analogy hold?
It holds at the architecture level, not the go-to-market level. Datadog’s growth engine was developer adoption; engineers used it before procurement got involved, creating organizational dependency before the contract was signed. That specific motion is harder in security because the tools sit in a regulated, compliance-driven environment where shadow IT is a policy violation. The Datadog-for-security company will need a different GTM motion, likely starting with SOC managers who control tool selection at the team level rather than individual developers. The architectural parallel holds regardless: unified data model, entity-based investigation, normalized schema across sources. Distribution differs. The fundamental insight does not.
Chronicle had petabyte-scale ingestion and Google infrastructure. If that was not enough, why would a startup succeed where Google could not?
Chronicle did not fail. It was acquired before it could prove the thesis independently. Inside Google, it competes for product priority against Cloud infrastructure, Workspace, and Mandiant. A standalone company with unified investigation as its only product has a different level of commercial urgency. The analogy is Looker before and after the Google acquisition; Looker’s best commercial years were as a standalone company with BI as its entire business, not as a product competing for roadmap priority inside Google Cloud.
What stops an incumbent from acquiring the startup at Series B, before it reaches scale?
Nothing, and that is the realistic exit for most companies that attempt this. The question is whether the acquirer can integrate the architectural premise or only the customer list. Palo Alto’s acquisition history suggests they absorb products into a bundle rather than restructuring the platform around a new data model. A startup that builds the unified investigation layer and sells to either PANW or Microsoft is likely to find its architecture absorbed into a platform that does not structurally change. The $10B outcome requires remaining independent long enough that the investigation layer has established category-defining market position. That is the harder path. It is also the only one that produces the outcome the title implies.
What is the specific signal that this category has arrived at the equivalent of Datadog’s observability becoming a board-level budget line?
Mean time to investigate (MTTI) appearing as a reported metric in CISO board presentations. Currently, boards hear MTTR and occasionally MTTD. MTTI, the time from alert to investigation context complete, is not reported because no existing tool makes it measurable as a standalone metric. The day a CISO presents to the board and says “our MTTI dropped from 18 minutes to 4 minutes since we deployed the investigation layer,” that is the signal the category has arrived. It means investigation has a defined value metric, which is what creates the budget line. Datadog’s equivalent was “time to root cause” becoming shared language between engineering and finance.
Sources Referenced
- Datadog FY2024 Q4 earnings release, February 13, 2025 (FY2024 revenue $2.68B, 26% YoY growth)
- MacroTrends, Datadog Revenue 2018-2026 (FY2025 revenue $3.42B)
- Datadog SEC filing 8-K, November 4, 2021 (Q3 2021 revenue growth 75% YoY)
- Datadog SEC filing 10-Q, November 7, 2024 (3,490 customers at $100k+ ARR, Q3 2024)
- Dropzone AI, Alert Fatigue in Cybersecurity glossary, February 2026 (28 tools per enterprise average)
- Verizon Data Breach Investigations Report, 2024 (74% of breaches had alerts generated but ignored)
- TechNadu, The Decision Burden Behind SOC Alert Fatigue, July 2026 (60% of alerts never reviewed)
- Databahn, The Cybersecurity Alert Fatigue Epidemic, June 2025 (ingest-based SIEM pricing mechanics)
- Radiant Security, The Toll of Useless Alerts, May 2026 (Ponemon: 25% analyst time on false positives; $5.3M average SOC cost)
- Google Cloud Blog, Introducing the Unified Chronicle Security Operations Platform, September 18, 2023
- Google, Redefining Security Analytics with Chronicle whitepaper, 2019
- Abnormal Security, Alert Fatigue, 2026 (15-20 minutes per alert; 3-4 minutes with AI-assisted investigation)
- Software Analyst Substack, Market Guide 2025: The Rise of Security Data Pipelines, October 2025 (Cribl $200M ARR)
- Torq, Alert Fatigue in Cybersecurity, April 2026 (analyst tenure 3-5 years; burnout at record highs 2025)
Talk to Noir Dove
If your security product’s GTM is built on a detection story, it is competing in the most crowded part of the market for the same enterprise budget. The investigation layer category does not have a dominant player yet. Noir Dove diagnoses where your commercial positioning sits relative to where the market is moving. Book a Clarity Call. One conversation before you set the messaging for the next sales cycle.

