TL;DR: Only 13% of collected telemetry is used, while 84% of companies consume less than a quarter of what they ingest and average annual observability spend reaches $905,000, according to Sawmills’ 2025 State of Observability and Telemetry Report. The governance problem is no longer visibility alone, but how to control telemetry volume, quality, and cost without blinding incident response.
NHIMG editorial — based on content published by Sawmills: 2025 State of Observability and Telemetry Report
By the numbers:
- Only 13% of collected telemetry is used.
- 86% of companies run two or more observability platforms.
Questions worth separating out
Q: How should teams reduce observability costs without losing useful telemetry?
A: Start at the pipeline, not the backend.
Q: Why do observability endpoints create governance issues for platform teams?
A: Because metrics endpoints reveal service behaviour, error patterns, and deployment structure, which can help both operators and attackers map the environment.
Q: What do security and engineering teams get wrong about collecting more telemetry?
A: They often assume that more data automatically means better detection.
Practitioner guidance
- Measure telemetry utility, not just ingestion volume Track the percentage of collected telemetry that is actually queried, correlated, or used in incident response.
- Consolidate overlapping observability platforms Inventory where logs, traces, and metrics are duplicated across platforms, then designate one system of record for each telemetry class.
- Protect identity-related telemetry as an investigation asset Ensure logs tied to service accounts, privileged access, and authentication events are retained, normalised, and searchable long enough to support root-cause analysis and access abuse investigations.
What's in the full report
Sawmills' full report covers the operational detail this post intentionally leaves for the source:
- Survey methodology and respondent breakdown across US and EU senior DevOps and engineering leaders
- Platform-by-platform observability stack patterns showing where tool sprawl is most common
- Detailed spending breakdowns behind the average $905,000 annual observability bill
- AI adoption findings on copilots and agents for telemetry optimisation and incident response
👉 Read Sawmills' 2025 State of Observability and Telemetry Report →
Observability telemetry sprawl: what it means for SRE and security teams?
Explore further
Observability sprawl is becoming a control-plane problem, not a tooling problem. Once multiple platforms ingest overlapping telemetry, organisations lose consistency in retention, correlation, and escalation paths. That weakens both operational resilience and security investigation quality, especially when access events and infrastructure anomalies need to be joined quickly. The practical conclusion is that telemetry governance now belongs in the same conversation as platform governance.
A question worth separating out:
Q: How do organisations know if telemetry governance is working?
A: Look for fewer unnecessary ingestions, higher-value events reaching the SIEM, and clearer ownership of collection rules and routing logic. A working programme can explain why data is collected, who can change it, and how enrichment improves both cost and detection outcomes.
👉 Read our full editorial: Observability data waste is raising costs and slowing incident response