SolarWinds Observability Self-Hosted makes its strongest case to Windows-based IT teams through one subscription that bundles a substantial amount of the former Orion product line, but the “self-hosted” label has a meaningful boundary: the new AI assistant and ML-based anomaly alerts require an opt-in connection from the on-premises deployment to SolarWinds’ SaaS service.

That distinction is the important finding behind ITPro’s August 12 review of SolarWinds Observability Self-Hosted, or SWOSH. The review found a clean Windows Server 2025 deployment, broad discovery and monitoring coverage, and a unified web console for NPM, SAM, IPAM, Log Analyzer, VMAN, NTA, NCM and other modules. SolarWinds’ current documentation confirms the suite’s three-tier packaging and the Platform Connect requirement for its cloud-delivered intelligence features. For organisations replacing several separately licensed SolarWinds modules, the bundle can simplify both purchasing and administration. For organisations whose monitoring environment must remain completely disconnected, however, the most heavily marketed newer capabilities are unavailable.

A server monitoring dashboard displays network health, VMware metrics, alerts, and secure cloud connectivity.The bundled node model is simpler, but it is still a contract model​

ITPro characterises the Essentials, Advanced and Premier editions at roughly £6, £10 and £13 per node per month respectively. Its tested configuration focused on the Advanced tier, which brings Network Configuration Manager, NetFlow Traffic Analyzer, Virtualization Manager, Server Configuration Manager and anomaly-based alerts into the package.

SolarWinds’ own current pricing page presents comparable tiers with starting prices of $8, $14 and $17.50 per node per month. The company also states that those prices are based on multi-year contracts billed annually. In other words, the monthly figure is useful for comparing editions, but it is not a monthly cancellation price and should not be treated as an all-in operational expense.

That does not invalidate the basic licensing argument. Node-based licensing is considerably easier to forecast than buying a base product and then discovering that flow data, configuration backup, virtualisation visibility, log retention or a separate polling engine require another meter. Essentials includes network performance monitoring, application and server monitoring, log analysis, IP address management, VoIP and network-quality monitoring, and user and device tracking. Advanced packages the capabilities many network operations teams would otherwise buy individually.

The caveat is scale. SolarWinds says Enterprise editions are available for every tier, are available above 500 nodes and required above 1,500 nodes. Those editions include such things as additional polling engines, additional web servers, high availability, lab licences, Enterprise Operations Console and Advanced Support. The published per-node starts therefore should be treated as a starting point, not a reliable forecast for a large, highly available deployment.

Premier’s value-based licensing is also more nuanced than “everything counts as a node.” SolarWinds says containers and wireless access points consume capacity at a 10:1 ratio; on-premises VMs and cloud entities consume at 3:1; network devices, servers, hosts, wireless controllers, storage arrays and Web Performance Monitor players are counted at 1:1; ICMP-only nodes are free. That can materially improve the economics in VM- and container-heavy estates, but only in the highest tier.


The Orion console remains the practical reason to buy it​

The review’s more persuasive observations concern the familiar SolarWinds Platform console, still recognisable to long-time Orion administrators. The product has been renamed and repackaged as SolarWinds Observability Self-Hosted, but the operational experience is a consolidated console with modules accessible from the same dashboard, reporting, alerts and settings framework.

ITPro reports that its lab installation on a Windows Server 2025 Hyper-V VM completed in 40 minutes and that Discovery Central identified its test network after credentials for SNMP, WMI and VMware were supplied. SolarWinds introduced Discovery Central in the June 9, 2026 release, positioning it as the common entry point for discovering and managing on-premises and cloud-monitored resources. The simplified wizards default to essential setup steps, while retaining advanced paths for more complex environments.

For a Windows-centric shop, the utility is less about a new interface than about cutting down the number of separate administrative routines. NPM provides conventional node, interface, routing and availability information; NTA adds flows and top-talkers analysis; SAM provides templates and application health data; VMAN extends virtual infrastructure insight; and NCM and SCM cover configuration drift. ITPro also found that Microsoft 365 monitoring has moved away from awkward PowerShell-query dependence to API poller templates, a necessary modernization for administrators who have had to revise automation around Microsoft’s changing cloud APIs.

The review also describes NetPath’s hop-by-hop maps for external locations, PerfStack’s ability to line up metrics from multiple devices, and QoE sensors linked to switch mirror ports for application classification. Those capabilities do not replace packet capture or a dedicated SIEM, but they provide a useful line from “users say an application is slow” to WAN path, interface, server and flow data inside one tool.

There is one practical warning in the module list: “included” does not mean “zero work.” SolarWinds’ breadth has always created a configuration burden, and the review reaches the same conclusion. A team can install SWOSH quickly, but turning templates, dependencies, alert suppression, retention, reports, role-based views and escalation actions into a useful service remains an engineering project.

SQL Server and infrastructure sizing are part of the real price​

ITPro’s lab started with eight Xeon Scalable Gold virtual CPUs and 16GB of RAM, then increased the VM to 32GB after host-memory alerts. That is not an anomaly in the review; it aligns with SolarWinds’ own recommendation for a small deployment of up to 500 monitored elements, which calls for eight cores and 32GB of RAM on the SolarWinds Platform server.

The difference between nodes and elements deserves attention during planning. SolarWinds sizes infrastructure around monitored elements—nodes, interfaces, volumes and component monitors—rather than only the licensing node count. A few hundred licensed devices with numerous interfaces, WMI-monitored services, application components, flow records and logs can exert far more load than the purchase order implies.

The SQL Server requirements make this clearer. SolarWinds permits SQL Server Express for evaluation use, and ITPro used it in the lab. But production requires the platform server and database to run on separate physical or virtual servers, and the vendor explicitly says Express is not supported for production. Express is capped at a 10GB database size, four cores or one socket, approximately 1.4GB of database-engine buffer-pool memory and five simultaneous web-console users.

That is a sharper limitation than a casual trial installation may suggest. SolarWinds creates separate primary, log and flow-storage databases, and it recommends SSDs, with dedicated capacity for flow and log data. Its own guidance estimates roughly 8GB of storage for every 1,000 flows per second retained for 30 days, before the base allocation. Teams evaluating NTA and Log Analyzer should model retention and ingestion before selecting SQL Server editions and storage, rather than regard the database as a minor prerequisite.

SolarWinds also recommends keeping the management platform off the public internet. That remains sound operational advice for a system holding SNMP strings, WMI credentials, device configuration backups, topology information and privileged connections into core infrastructure.


The new AI features make SWOSH a hybrid service​

ITPro’s review describes the SW1 agent as a side-panel assistant that answered questions about VMware status, critical nodes and alert patterns. SolarWinds’ June 2026 release notes confirm that SW1 remains a Technical Preview, not a generally available feature with a permanent entitlement guarantee. The company says it is included during the preview, but may move to another licensing tier or incur extra charges once generally available.

More consequentially, SW1 is not computed wholly inside the customer’s self-hosted environment. To enable it, an administrator configures Platform Connect, accepts a SolarWinds SaaS supplement, creates or connects a SaaS tenant and installs a SaaS agent on the SolarWinds server. The platform requires internet connectivity for this arrangement. SolarWinds says data is encrypted in transit with TLS 1.2 and encrypted at rest using AES-256 volume-level encryption in the SaaS service, but it is still a cloud connection to consider in security reviews.

The same boundary applies to Advanced’s anomaly-based alerts. SolarWinds states that the feature sends the metrics required for those alerts to its cloud AIOps service through Platform Connect. It says the service uses up to seven days of metric data for detection, while associating it with hashed organisation and entity identifiers. The documentation also spells out the initial learning period: an alert may take several hours to train and, by default, does not trigger until training completes. Administrators can choose fallback behavior that fires an ordinary threshold-style alert when the metrics are untrained or the detection service is unavailable.

This makes anomaly detection a potentially useful addition rather than magic. It can reduce static-threshold noise for supported Linux and Windows server metrics including CPU, memory, response time and packet loss, but it does not cover Windows workstations. It also depends on outbound connectivity and a cloud service being available when the organisation wants the ML component.

A capable consolidation play, with boundaries administrators must accept​

ITPro’s conclusion that SolarWinds Observability Self-Hosted is good value holds up for the right buyer: a mid-sized or larger IT organisation already monitoring Windows servers, network gear, VMware, IP address space, NetFlow and configuration changes, and looking to stop assembling separate SolarWinds licences. Advanced is the practical centre of the lineup because its NCM, NTA, VMAN and SCM additions answer routine network-operations requirements rather than edge cases.

The platform’s core operational strengths are established: agentless and agent-based monitoring options, broad Windows and network-device coverage, a mature web console and a wide collection of modules that share inventory and alerting context. Discovery Central and the current release’s condition-based alert suppression improve usability around that foundation, rather than attempting to replace it.

But prospective buyers should cost the design they actually need: a production SQL Server, separate server roles, SSD capacity for logs and flows, high availability where required, and Enterprise scale licensing as node counts rise. They should also decide whether Platform Connect is acceptable before putting SW1 or anomaly detection into any runbook.

SWOSH is self-hosted where the monitoring platform runs and where its primary operational data lives. Its AI and anomaly features are deliberately hybrid. That is not a flaw if the cloud connection meets policy; it is the line that determines whether SolarWinds’ bundled observability pitch fits the environment at all.