Loki vs Elastic vs Splunk

Three log backends. Decision criteria.

Loki

Loki is the cheap, Kubernetes-native option. Label-based indexing on object storage gives you single-digit dollars per GB/month at the cost of weaker full-text search.

Elasticsearch

Elasticsearch is the full-text option with a mature ecosystem. Powerful queries, the Kibana surface, and a rich plugin ecosystem at the cost of real operational complexity.

Splunk

Splunk is the enterprise-scale, premium-priced option. Industry-standard at large enterprises with deep search capability and budget for it; the licence model rewards careful planning.

Decision matrix

The pick is shape-driven. Kubernetes-heavy and cost-sensitive, mid-market with full-text needs, or enterprise with compliance scope each point to a different default answer.