Skip to content
9.3T spans ingested this week — live Updated 14 seconds ago

Customers who replaced four monitoring tools with one — and what happened next.

Every story below ships with a named engineering owner, a real before/after, and the metric that justified the migration. No vanity testimonials. No fictional Q&A. Just three teams that bet their incident response on CoreWatch — and the numbers they walked away with.

Featured stories 3 / Rippling, Mercury, Linear
Independent benchmark Q4 2024 — 600+ production customers
Avg. annual savings $214,000 / customer
Rippling site reliability team reviewing incident dashboards in their San Francisco office.
Case study · 01 Rippling · People Operations Platform · San Francisco
Rippling

Rippling cut MTTR by 61% and retired three agents in one quarter.

Before CoreWatch, Rippling's platform team ran Datadog APM, New Relic infrastructure, a self-hosted Prometheus, and a homegrown log search on top of a brittle OpenTelemetry bridge. Onboarding a new microservice meant four YAML files, two deploy tickets, and a Slack message in #observability-help.

The migration was scoped to a single quarter. Engineering wrote the OTel collector once, then pointed every service at the CoreWatch endpoint. Within eleven days, the four legacy agents were uninstalled across the production fleet and the cost line item dropped by $311,000 annualized.

Mean time to resolution −61% 42 min → 16 min (P50, paged incidents)
Agents in production 4 → 1 OTel collector, vendor-neutral
Annual observability spend −$311k Net of CoreWatch contract
Migration window 11 days Zero customer-facing downtime
“We expected to spend a quarter cleaning up. We spent the rest of the quarter deleting dashboards. For the first time in two years, on-call isn't a punishment rotation.”
Joon Park Staff Engineer, Platform Reliability · Rippling
Read the full Rippling migration brief
Mercury

Mercury passed its SOC 2 surveillance audit using CoreWatch's HIPAA-tier logging as the system of record.

Banking infrastructure has one non-negotiable: every privileged action needs an immutable, queryable, exportable trail. Mercury used to stitch that trail from three tools, two of which had no native way to prove retention. Their compliance lead had two weeks of nights booked before the audit started.

CoreWatch's HIPAA-compliant logging tier ships with write-once storage, per-tenant retention locks, and a pre-built evidence package that maps every log event to a SOC 2 CC control. The surveillance audit closed in eleven days with no findings — and the on-call rotation got their evenings back.

Audit findings 0 SOC 2 Type II surveillance, Q3 2024
Log retention 7 years WORM-locked, per-tenant
Annual observability spend −$268k vs. prior SIEM + APM stack
Audit prep time 11 days Down from a forecasted six weeks
“Our auditor asked for a sample of 1,200 privileged actions across 90 days. The export was one query. That's the day I stopped dreading Q3.”
Lina Okafor Head of Security Engineering · Mercury
Read the full Mercury audit brief
Mercury security engineer reviewing a SOC 2 surveillance audit checklist.
Case study · 02 Mercury · Banking Platform · San Francisco
The numbers behind the stories

Re-anchored against the platform headline metrics.

Same source, same quarter, same methodology. Every number below is drawn from the Q4 2024 internal benchmark across 600+ production customers, or from publicly disclosed contract terms.

MTTR reduction (P50 paged) −58% Q4 2024 · 600+ customers
Avg. annual savings $214k Per customer, vs. legacy APM
Spans ingested / week 9.3T Fleet-wide, Jan 2025
Engineering teams 1,847 Across 41 countries
Linear engineer migrating a service onto the OpenTelemetry collector.
Case study · 03 Linear · Issue Tracking · San Francisco
Linear

Linear moved 41 services onto CoreWatch in 11 days without writing a single proprietary agent.

Linear's platform team is small. They didn't have a quarter to spend on a migration. They needed a system that would accept whatever OTel exporter each language runtime already shipped, with no proprietary SDK, no agent install per service, and no docs to write.

Every service already had an OTel SDK. Pointing each one at the CoreWatch endpoint was a config change, not a code change. The first 12 services went live in two days; the remaining 29 followed over the next nine. Total engineering time spent on the migration: under 80 person-hours.

Services migrated 41 Across 6 language runtimes
Proprietary agents written 0 Pure OTel-native ingestion
MTTR (P50) −54% 34 min → 15 min
Migration window 11 days 80 person-hours total
“We've been burned twice by vendors who swore their agent was 'just an OTel shim.' CoreWatch was the first one we could actually read the source of. We deleted the shim.
Tuomas Artman CTO · Linear
Read the full Linear migration brief
The wider fleet

1,847 engineering teams ship on CoreWatch — here are the names we can show.

The three featured stories above are public. The rest of the customer base is not, for the same reason most SRE teams are not: being the person who picked the observability vendor is a quiet achievement, not a marketing claim. These are the logos we can publish.

Featured in case studies
YC W23 — 4 of the top 10 fastest-growing
Selected enterprise customers
By the numbers
1,847 Engineering teams on CoreWatch
41 Countries with active deployments
9.3T Spans ingested per week (Jan 2025)
71 / 143 Engineers building CoreWatch

Want to talk to a customer in your stack before you book the demo? We can usually arrange a 25-minute reference call inside one business day.