TL;DR: AI-led telemetry management cut observability spend by 50% to 80% across its customer base while reducing noisy, low-quality data that slows incident response, according to Sawmills. The broader lesson is that telemetry governance is now a control problem, not just a data-volume problem, because signal quality directly shapes detection, response, and cost.
NHIMG editorial — based on content published by Sawmills: All posts We built Sawmills to fix observability's two biggest problems: cost and quality. Here's what year one looked like
By the numbers:
- Across its customer base, Sawmills says it is delivering 50 to 80% observability cost reductions.
Questions worth separating out
Q: How should teams reduce observability costs without losing useful telemetry?
A: Start at the pipeline, not the backend.
Q: Why does telemetry quality matter so much for AI-driven security operations?
A: AI-driven security workflows depend on complete, accurate, context-rich inputs.
Q: What breaks when telemetry automation removes too much data?
A: Detection breaks first, because alerting systems lose context and lose the ability to join events across services.
Practitioner guidance
- Set telemetry quality standards at ingestion Define required fields, naming conventions, and schema checks for logs, traces, and events before they enter long-term storage.
- Identify noisy integrations that drive disproportionate cost Rank telemetry sources by spend, volume, and incident value, then isolate the small set of services that create runaway ingestion or repeated alert churn.
- Preserve identity and access telemetry as high-value evidence Keep authentication, service account, and privileged activity logs separate from generic application noise, and validate that they remain searchable across retention windows.
What's in the full article
Sawmills' full post covers the operational detail this post intentionally leaves for the source:
- Customer-specific examples of how telemetry waste was identified and removed from the stream
- Descriptions of the shipped features that normalise and transform data in flight
- The company’s year-one implementation lessons for engineering teams managing observability sprawl
- Additional context on how customers measured cost reduction and telemetry quality improvements
👉 Read Sawmills’ year-one analysis of AI-driven telemetry cost and quality control →
Observability cost sprawl and telemetry quality: what teams need now?
Explore further
Telemetry governance is becoming a security control, not a data-management afterthought. When organisations pay for massive volumes of data they never operationalise, they are funding blind spots as much as visibility. The security issue is not simply cost inflation. It is the loss of trust in the evidence layer that defenders rely on for detection, forensics, and auditability. Practitioners should treat telemetry quality standards as part of control design, not a downstream analytics concern.
A question worth separating out:
Q: How do security teams decide which logs must never be filtered?
A: Protect records that support accountability, such as authentication, privileged activity, service account usage, and incident-response evidence. Those logs should be exempt from aggressive filtering unless you have a documented control that preserves their evidentiary value. If a record would matter in a post-incident review, do not let cost optimisation erase it.
👉 Read our full editorial: AI-driven telemetry governance cuts observability cost and noise