Dimitri Cabete Jorge, Co-Founder & CTO · Last updated: August 2026 · Facts verified: August 2026
TL;DR: Dynatrace is an agentic AI observability platform covering the full stack, applications through infrastructure, logs, user experience, and security, from a single data lakehouse. Davis AI and its autonomous domain agents measurably reduce mean time to resolve in large, complex environments. The hard limits are cost and complexity. Consumption billing scales fast, DQL has a real learning curve, and both the product and the contract are built for enterprises. Smaller or cost-sensitive teams should look at Datadog first.
Ratings: G2: 4.5/5 (1,366 reviews) · Gartner Peer Insights: 4.6/5 (1,789 ratings) · Capterra: 4.6/5 (84 reviews), verified August 2026
What Is Dynatrace?
Dynatrace describes itself as an agentic AI platform for unified observability, security, and automation, continuously analyzing system behavior, identifying important events, and acting across applications, infrastructure, cloud platforms, and AI workloads.
Founded in 2005, it has been listed on the NYSE as DT since 2019. Fiscal 2026 closed with revenue of $2.018 billion, annual recurring revenue of $2.054 billion, up 18% year over year, and free cash flow of $529 million. It has been named a Leader in the Gartner Magic Quadrant for Observability Platforms for the 16th consecutive time, most recently in the 2026 report, and ranked first in four of six use cases in the 2025 Critical Capabilities report.
Two foundations carry the platform. The Grail data lakehouse unifies observability, security, and business data with massively parallel processing, and keeps causal dependencies in graph context. Dynatrace Intelligence is the agentic AI layer above it, fusing deterministic and generative models to prevent, remediate, and improve automatically.
What Is Dynatrace Used For?
Enterprise IT, DevOps, SRE, and platform engineering teams run it across application performance, security, infrastructure, and user experience. The work splits into distinct jobs.
- Kubernetes and cloud-native observability: full-stack Kubernetes insight across cluster and workload metrics, events, logs, and automated distributed tracing, with no code changes, image modifications, or redeployments.
- Automated root-cause analysis: the Root Cause Agent walks dependencies across metrics, logs, traces, user sessions, and the causal graph to name the source of a problem in a distributed system. Dynatrace claims a 90% or greater reduction in mean time to repair. That is the vendor's own figure.
- Runtime application security: Runtime Vulnerability Analytics finds open-source and third-party vulnerabilities in production, documented in the vulnerability analytics reference. It surfaces a finding only when the affected component is actually in use, which keeps the queue short.
- Digital experience monitoring: real user monitoring, synthetic monitoring, and Session Replay are native capabilities on the same platform, and Dynatrace was named a Leader in the 2025 Magic Quadrant for that category too.
- AIOps and preventive operations: Davis AI pairs predictive forecasting with agentic automation for preventive operations, including proactive firewall configuration on the security side.
- AI and LLM observability: the AI Observability app monitors generative AI applications and agentic frameworks including Amazon Bedrock AgentCore, LangChain Agents, Google ADK, and the OpenAI Agents SDK, with signals unified through OpenTelemetry.
- Business observability: United Airlines feeds business data into its Digital Control Tower dashboards and reports a 35% reduction in business impact time. National Grid reports mean time to resolve improving by more than half after moving to Dynatrace SaaS.
Key Features of Dynatrace
Four things carry the evaluation, starting with the agentic layer that went generally available in 2026 and running through the data and topology foundation, the collection agent, and the automation and integration surface.
The agentic layer
- Dynatrace Intelligence: generally available since January 28, 2026, and introduced at the Perform 2026 launch as an agentic operations system. It combines deterministic and generative AI with Grail data and Smartscape topology to prevent issues, run remediation, and tune performance without a human in the loop for every step.
- Domain-specific agents at launch: the same announcement shipped ready-to-use agents for SRE, development, and security teams, built on Dynatrace Intelligence and available from launch. Dynatrace frames them as autonomous action with governance attached, and said more would follow.
- July 2026 expansion: Dynatrace added triage agents for incident remediation plus no-code custom agent creation, announced July 27, 2026. Cloud SRE Agent and the enhanced assistant shipped that day; Autonomous SRE Agent and Agent Builder were slated for August, so confirm availability before counting on either.
Data and topology
- Grail: a causal data lakehouse holding telemetry, security findings, and business data with dependencies preserved as a graph. The DQL Search command runs index-free, schema-on-read queries across metrics, logs, traces, and everything else in Grail. Log management passed $100 million in annualized consumption and was the fastest-growing major product category in Q3 FY2026, per a company SEC filing.
- Smartscape: a continuously updated real-time view of every entity and dependency, covering cloud and Kubernetes objects, domain metadata, and agentless cloud-discovered components, built to be read by humans and agents from the same source.
- Investigations app: released February 2026 as a central exploration tool over Grail, handling large DQL result sets, metadata-based query pivots, investigation history, and links between logs, metrics, events, and traces.
Collection
- OneAgent: a single host deployment that collects across the whole application delivery chain and auto-discovers nodes, pods, services, and running applications in Kubernetes with no manual configuration. It runs in three modes: Full-Stack Monitoring, Infrastructure Monitoring, and Foundation and Discovery, and those modes map directly to three different rate-card lines.
- Live Debugger: generally available in Sprint 1.311 in April 2025. It provides code-level debugging data with no extra code and no redeployment. It bills under the Code Monitoring rate-card item.
Automation and integrations
- AutomationEngine: combines that same data with causal AI, per the AutomationEngine documentation, to drive workflows end to end, with human-in-the-loop controls at high-risk decision points.
- MCP Server: the Dynatrace MCP Server is a governed interface letting external AI tools query and act on the platform in natural language. Supported integrations include AWS DevOps Agent, Azure SRE Agent, ServiceNow Assist, GitHub Copilot, and Atlassian Rovo Ops.
- Position on AI frameworks: Dynatrace was among the first observability vendors to support Amazon Bedrock AgentCore at launch, and its AI Observability app unifies signals through OpenTelemetry and OpenLLMetry.
- Recent acquisitions: Metis in March 2025 for AI-driven database observability, DevCycle in January 2026 for OpenFeature-based feature management, and Bindplane through an April 2026 acquisition for a unified OpenTelemetry pipeline.
Dynatrace Pros & Cons
Consumption pricing and deployment weight are the price of putting full-stack monitoring, Grail, Davis AI, runtime security, and autonomous operations in one platform.
What Users Say
What users consistently praise:
- Root-cause analysis: Davis AI surfacing one actionable root cause, where other tools produce a wall of symptoms, is the single most repeated point of praise on every platform, buyer and practitioner alike.
- MTTR and alert noise: a Gartner customer summary covering the 18 months to October 2025 credits Davis AI with simplifying issue identification, and practitioner reviews credit it with halving outage duration.
- OneAgent deployment: zero-configuration auto-instrumentation is the second most praised feature, with reviewers describing deployment as smooth and the first insights as immediate.
- Legacy applications: the agent gets specific credit for legacy and third-party applications where changing the code is not an option.
- Platform consolidation: holding APM, infrastructure, logs, digital experience, and cloud platforms in one place is the most common reason buyers renew.
What users consistently complain about:
- Pricing predictability: the dominant complaint everywhere. Consumption scaling with log ingestion makes forecasting unreliable, and per-query DQL charges make exploratory analysis feel financially risky.
- Billing complexity: reviewers describe billing structure as complicated and host-based costs as accumulating faster than expected.
- Migration cost: practitioner threads document complex Grail queries against large volumes producing surprise charges, and some older classic-licensing contracts costing considerably less than current pricing, so a migration can raise the bill.
- Dashboard customization: multiple 2026 reviews describe the block-based layout as restrictive, with no overlapping widgets and substantial manual work for advanced business dashboards.
- Documentation and support: a January 2026 reviewer reports sparse documentation and a concrete escalation failure, with advanced tickets cycling through L1 before reaching specialists, and cost-control features like data bucketing never surfaced proactively.
Where reviewers diverge:
- Whether the premium is justified: enterprise buyers on review platforms treat pricing as a known trade-off, with one describing Dynatrace as understanding its value and pricing accordingly. Practitioners in engineering communities treat it as potentially disqualifying, and one 2026 thread frames the whole question as whether AI-driven MTTR reduction is worth a threefold price increase.
- OneAgent performance: buyers rank it their top feature at procurement. Engineers report measurable latency moving from under a millisecond to 5 to 10 milliseconds on high-traffic services after installation, stability issues needing node restarts, and containers failing on LD_PRELOAD errors.
- Legacy-system stability: the same split shows up on legacy estates, where a March 2026 Gartner reviewer independently reports agent-related problems that buyer-side scores do not reflect.
Dynatrace Pricing
There are no seats and no tiers. Every capability draws down a platform-level commitment at published rate-card prices, a model Dynatrace calls DPS.
Rates come from the Dynatrace pricing page and the published rate card. All pricing information verified August 2026.
Gotchas:
- Full-Stack Monitoring bills by memory, so a 16 GiB host costs twice what an 8 GiB one does. Infrastructure Monitoring charges a flat host-hour rate regardless of memory, so the same fleet can carry two different bills depending on the mode you pick.
- Converted to monthly figures at list price, Full-Stack runs roughly $58 per 8 GiB host, Infrastructure roughly $29 per host, and Foundation and Discovery roughly $7. Those figures are calculated from the hourly rates above; Dynatrace publishes no monthly prices.
- Under Pay-per-Query, logs generate three charges where most tools have one, covering ingest, retention, and query. The alternative model, Retain with Included Queries, folds query cost into a higher retention rate of $0.02 per GiB-day.
- Metrics queries are included at no extra cost, but traces and events queries are billed per GiB scanned. Every exploratory DQL query against traces has a direct billing consequence, which is the root of the cost complaints above.
- Data Egress is its own line at $0.15 per GiB and is the item most often missed in estimates.
- Contracts run one to three years with a mandatory annual minimum commitment, and the minimum dollar figure is not published. Dynatrace uses $500,000 a year as an illustrative example in its documentation, which says most of what you need to know about who the product is sold to.
- Volume and multi-year discounts are negotiated, so the rate card is a starting point for negotiation.
- Capability availability varies by deployment model and cloud provider.
- There is no permanent free tier. A 15-day trial and a public Playground sandbox, which needs no installation, are the two ways to try it without a commitment.
Is Dynatrace Worth It?
Yes, if you run a large enterprise with complex distributed, cloud-native, or hybrid systems where full-stack visibility and automated root-cause analysis translate into measurable MTTR reduction, and where a multi-year commitment at enterprise pricing already fits the budget. It is strongest for organizations running AI workloads, Kubernetes at scale, or runtime application security alongside observability, and for teams that would rather hold one data lakehouse than stitch together point tools.
Model the consumption before signing, because the rate card is where this decision is actually made. A hundred 8 GiB hosts on Full-Stack is roughly $5,800 a month at list before a single log, trace, or synthetic check, and query charges land on top of that. The teams that get burned are the ones that budget the agent and forget the ingest.
Look elsewhere if your team is small, cost-sensitive, or early in its observability maturity, in which case Datadog is the more accessible route for cloud-native and AI-native work, with wider integration coverage and a lower entry price. The other case is log analytics or SIEM as the primary requirement, particularly in an organization already standardized on Cisco products, where Splunk is the stronger fit.
Dynatrace vs Splunk
These two are the most common head-to-head in enterprise observability, and Dynatrace is listed as the top alternative to Splunk Observability Cloud in Gartner's alternatives view. On Gartner Peer Insights, the two sit close: Dynatrace at 4.6 stars, Cisco Systems for Splunk at 4.5 from 1,230 reviews. Cisco closed its acquisition of Splunk in March 2024, the product now ships as Splunk Observability Cloud, and Cisco announced its own agentic AI observability at.conf25 in September 2025.
Where Dynatrace wins:
- Unified architecture: one lakehouse for every telemetry type against a log-centric design with separate repositories, which is the architectural difference Dynatrace leads with in its own comparison, and it should be read as the vendor's framing.
- Root-cause precision: Davis AI works from causation and topology, where rules-based and probabilistic alerting needs more human interpretation to reach the same answer.
- Topology mapping: Smartscape builds dependency graphs automatically and keeps them current, against service maps that need more manual definition.
- Gartner Critical Capabilities: Dynatrace ranked highest in four of the six use cases Gartner scored across 20 vendors: Cost Optimization at 4.32 out of 5, Site Reliability Engineering at 4.3, Business Insights at 4.3, and AI Engineering at 4.29.
Where Splunk wins:
- Log analytics depth: extremely large log volumes and highly complex log queries remain Splunk's home ground, particularly where log-only monitoring is the whole requirement.
- SIEM: Splunk was a Gartner Magic Quadrant Leader for SIEM for ten consecutive years through 2024 and, on its own account, the only vendor named a Leader in both SIEM and Observability three times. Dynatrace has no SIEM answer.
- Cisco breadth: post-acquisition, it connects to ThousandEyes, AppDynamics, and Cisco networking, so an organization already on that stack gets a portfolio with no migration.
- Query and dashboard flexibility: more manual configuration in exchange for more freedom in custom analytics and visualization.
Dynatrace Alternatives
Smaller teams usually need more accessible pricing and broader third-party integrations. Other buyers want log analytics and SIEM ahead of AI-driven full-stack observability.
Datadog: Pick this if your team is cloud-native or AI-native and wants infrastructure, APM, log management, and LLM observability in one platform with wide integration support and gentler pricing entry points. It rates level with Dynatrace on Gartner Peer Insights, so the choice comes down to fit.
Splunk Observability Cloud: Pick this if your organization already runs Cisco and Splunk and wants observability and SIEM in one portfolio. The post-acquisition roadmap connects it to ThousandEyes and Cisco networking, which is a real advantage on that stack and irrelevant off it.
How Dynatrace Works With Siit
Siit does not integrate directly with Dynatrace, and the two answer different questions. Dynatrace tells you a service is degraded and why. Siit handles the human side of what happens next, the requests, approvals, and cross-team handoffs that an incident sets off.
That gap is usually filled by hand. An incident becomes a request for elevated access, a temporary license, a device for the engineer covering out of hours, or an update to whoever is asking in a channel. None of that lives in an observability platform.
What Siit covers around a monitoring stack:
- Requests in chat: employees and engineers raise and track requests in Slack or Microsoft Teams, so the coordination happens in the channel where the incident is already being discussed.
- Access under time pressure: through the Okta integration, Siit can reset a password, add or remove group membership, and assign applications from inside a request, with approvals on the sensitive ones.
- Handoff to the system of record: Siit escalates into the ticketing tools it does integrate with, including ServiceNow, Jira Service Management, and Freshservice. That keeps an incident inside the incident workflow your team already runs.
One boundary worth stating plainly: Siit does not ingest Dynatrace alerts, monitor infrastructure, or replace any part of an observability platform. It sits on the employee request layer, which is a different job from watching the stack.
Siit connects with 500+ connectable apps across identity, device management, HR systems, knowledge bases, and ticketing. For a platform team, that is what keeps the human half of an incident in one thread.