Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Palo Alto Networks completed its acquisition of cloud-native observability company Chronosphere on January 29, 2026. The deal was announced on November 19, 2025, at a stated value of $3.35 billion in cash and replacement equity awards, subject to adjustments. Chronosphere is now a wholly owned Palo Alto Networks subsidiary—not a company the security vendor merely plans to buy.
The strategic bet is about more than adding dashboards. Chronosphere manages and routes the metrics, logs, traces and other telemetry that help organizations understand how applications and infrastructure behave. Palo Alto Networks wants that operational context to complement its Cortex security and AI-agent products. Whether that creates a better-integrated platform—or more vendor concentration and commercial complexity—depends on how the products, pricing and customer controls develop.
Deal timeline and price
| Date or figure | What it means |
|---|---|
| November 19, 2025 | Palo Alto Networks announced a definitive agreement to acquire Chronosphere. |
| $3.35 billion | Announced consideration in cash and replacement equity awards, subject to adjustments. |
| January 29, 2026 | The acquisition closed; Chronosphere became a wholly owned subsidiary. |
| About $3.0 billion | Purchase consideration recorded in Palo Alto Networks’ later accounting disclosure. |
The announcement and accounting figures describe different things. The $3.35 billion was the headline transaction value announced in November, subject to adjustments. A subsequent filing recorded approximately $3.0 billion in purchase consideration for accounting purposes, including about $2.842 billion in cash and $109 million in the fair value of replacement awards. The accounting figure should not be treated as a correction that makes the original announcement false. (deal announcement; purchase-accounting disclosure)
What Chronosphere does
Chronosphere is an observability company for cloud-native environments and large-scale workloads. Observability tools help teams investigate what is happening across software and infrastructure by collecting and analyzing telemetry: metrics, logs, traces and related signals. This data can help engineers spot slow services, failures and unusual behavior, then trace symptoms to possible causes.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Chronosphere’s strategic value to Palo Alto Networks is not just a set of monitoring screens. Its telemetry pipeline helps organizations collect, transform, filter and route data to the systems that use it. That matters because a company can generate far more telemetry than it can—or should—send to every monitoring and security product. Filtering and routing can reduce low-value data while preserving useful context, although aggressive filtering can also discard evidence needed later.
Palo Alto Networks said Chronosphere had more than $160 million in annual recurring revenue (ARR) as of September 2025 and triple-digit year-over-year ARR growth. Those are figures the buyer reported at announcement, not independently stated results in the acquisition announcement. ARR is a recurring-revenue measure, not profit, cash flow or a guarantee of future revenue. (Palo Alto Networks’ announcement)
Why a cybersecurity company bought an observability business
AI systems create more operational data
AI workloads add more components for teams to monitor: models and endpoints, prompts and responses, agents and their tool calls, cloud infrastructure, application performance and user activity. Palo Alto Networks’ thesis is that security automation works better when it can draw on operational context, not only a narrower set of security alerts.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #2
- APPLIANCE ONLY: Hardware unit sold without a service subscription — security services, firmware updates and support are NOT included and must be purchased separately to activate protection.
- PERFORMANCE: Up to 2.5 Gbps firewall inspection, 1 Gbps threat prevention and 1.2 Gbps IPSec VPN throughput driven by SonicWall's patented Reassembly-Free Deep Packet Inspection (RFDPI) engine.
- CONNECTIVITY: 8x1GbE + 2x1G SFP in a desktop form factor; zero-touch deploy and manage on-box or via cloud Network Security Manager (NSM).
- THREAT PROTECTION: SonicOS 8 delivers intrusion prevention, gateway anti-malware, application control, TLS/SSL decryption, Capture ATP multi-engine sandboxing (RTDMI) and reputation-based content & DNS filtering with an active service subscription.
- BUILT FOR SMALL BUSINESS & BRANCH: Secure SD-WAN, IPSec and SSL VPN plus Zero-Trust Network Access through Cloud Secure Edge keep distributed sites and remote workers protected.
That context could help teams connect a suspicious event to a service, deployment or infrastructure change, and give an AI agent more information before it recommends or takes action. More telemetry does not automatically mean better decisions, however. Data quality, retention, permissions and safeguards determine whether added context is useful.
Operational and security signals can complement each other
Observability systems often see performance and availability signals that security tools do not collect in the same way. Security operations may see suspicious activity without a full picture of its impact on production. Combining those perspectives could make it easier to investigate an incident, assess its operational effect and prioritize a response.
It also gives Palo Alto Networks a route to sell beyond conventional security data and into cloud-native operations. For customers, a common vendor may reduce some integration work. It may also increase reliance on one supplier, so the trade-off is not automatically favorable.
Telemetry has a cost
High volumes of metrics, logs and traces can raise storage, ingestion and processing costs. Palo Alto Networks has said Chronosphere’s pipeline can reduce data volume by 30% or more and require 20 times less infrastructure than legacy alternatives. Those are company claims, not independently verified comparative benchmarks in the cited materials. Actual savings depend on an organization’s data mix, retention and query patterns, vendor pricing, and the cost of downstream systems. (acquisition-completion announcement)
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallHow Chronosphere fits with Cortex
Palo Alto Networks has described a strategic plan to connect Chronosphere’s telemetry and operational context with its Cortex products, including Cortex AgentiX and Cortex XSIAM:
- Chronosphere supplies observability data and tools to manage and route telemetry.
- Cortex AgentiX is Palo Alto Networks’ platform for building and governing AI agents.
- Cortex XSIAM is its security-operations platform, where security teams may use relevant, filtered telemetry alongside security data.
The intended direction is a system in which AI agents can use broader system signals to help identify anomalies or security issues, investigate possible causes and initiate remediation. That is a product vision—not proof that every Chronosphere customer already has universal, fully autonomous remediation. The closing announcement described the integration objective, but it does not establish that every part of the vision is available in every deployment. (closing announcement)
Even when agents are available, automated action needs limits. A mistaken diagnosis can worsen an outage if an agent has broad permissions. Buyers should verify whether actions can be restricted by role, environment and risk; whether human approvals are available; whether actions are logged; and whether changes can be reversed.
What changed for customers after the acquisition
Palo Alto Networks said the Chronosphere Telemetry Pipeline would remain available as a standalone solution. That is relevant to organizations that want telemetry management without immediately adopting a wider Palo Alto Networks security platform. Co-founder and former CEO Martin Mao joined Palo Alto Networks as senior vice president and general manager of Observability. (closing announcement)
Standalone availability does not by itself answer the commercial and operational questions customers may care about. The cited announcements do not establish whether every contract, price, support contact, integration or product roadmap remained unchanged after closing. Existing and prospective customers should get current terms and commitments in writing rather than infer them from the acquisition announcement.
Best Value
- Integrated Hardware and Security Services: Comes with FortiGate-40F hardware, 5 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
- UTP Security Features: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
- Ideal for Smaller Settings: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
- Continuous Support and Maintenance: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
- Compact and Effective: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.
Questions to ask before signing or renewing
- Can the product be used independently of Palo Alto Networks’ security subscriptions, and what happens to access if those subscriptions end?
- What charges apply to ingestion, retention, querying, high-cardinality data, egress and security features? Are costs based on separate meters?
- Can telemetry be routed to multiple destinations, and what data-export tools, APIs and migration assistance are available?
- Which open standards and integrations are supported, and are there dependencies on proprietary schemas or workflows?
- What are the service-level commitments, data-residency options and retention controls for your required regions?
- What product changes are planned, and how will changes to pricing, packaging or support be communicated?
- For AI-driven remediation, can you set approval gates and blast-radius limits, audit all actions and roll them back?
Filtering can reduce the amount of data sent downstream, but it may not lower total costs if query or retention charges dominate. Too much filtering can create investigative blind spots. A unified vendor offer can still involve distinct products, consoles, agents and data models, so test the integration against actual workflows rather than assuming that common ownership means a seamless system.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the price says—and what it does not
Using the more-than-$160-million ARR figure Palo Alto Networks reported for September 2025, the $3.35 billion announced consideration equates to roughly 21 times $160 million. Because the ARR was reported as “more than” $160 million, this is an indicative comparison, not an exact multiple. It is a calculation from company-reported figures, not a valuation multiple Palo Alto Networks announced.
The comparison also has limits: ARR is not recognized revenue or earnings, and the deal value was subject to adjustments. The premium may reflect expected growth, technology, customer relationships and strategic value to Palo Alto Networks, as well as Chronosphere’s standalone financial performance. The figures alone do not show whether the purchase will earn an adequate return.
Recommended Free Tools
A separate Palo Alto Networks update said its observability platform had surpassed $300 million in ARR in the third quarter of fiscal 2026. That is the company’s observability-platform figure after the acquisition, not Chronosphere’s standalone ARR. Its fiscal 2026 results also reported $388 million of revenue and $1.6 billion of next-generation security ARR from CyberArk and Chronosphere combined. Neither combined figure can be attributed to Chronosphere alone. (observability update; Q3 FY26 results)
How buyers should compare alternatives
Chronosphere’s acquisition does not make every observability platform interchangeable. Compare products based on the workloads you need to understand, data-volume economics, operational model, integrations and portability—not on a deal headline.
- Datadog offers broad cloud observability, application and infrastructure monitoring, logs, security and user-experience capabilities.
- Dynatrace focuses on enterprise observability and application performance in complex environments, with an emphasis on automation.
- New Relic provides full-stack observability across applications, infrastructure, logs and user monitoring.
- Grafana Cloud or Grafana Enterprise may suit teams already using the Grafana ecosystem, including Prometheus, Loki or Tempo, and seeking an open-source-oriented approach.
- Elastic Observability offers a search-and-analytics-oriented route for logs, metrics and traces.
- Splunk can be relevant to organizations already invested in its security or operational analytics products.
- Honeycomb emphasizes event-oriented, high-cardinality investigation and exploratory debugging.
- OpenTelemetry with cloud-native tools offers a composable, vendor-neutral instrumentation and collection layer, but typically requires more operational ownership.
These are market categories, not like-for-like substitutes. Product scope, pricing and availability vary by edition and over time. The acquisition alone is no reason to assume Palo Alto Networks/Chronosphere is the least expensive choice—or that existing Chronosphere pricing and packaging are unchanged. Ask each vendor to itemize relevant charges and provide written terms for export, cancellation, retention and migration.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

