← Back to home
Comparison · Analytics

ThingsBoard vs OpenObserve

A side-by-side editorial comparison of ThingsBoard and OpenObserve — release velocity, themes, recent moves, and the top alternatives to consider.

ThingsBoard vs OpenObserve: at a glance

FeatureThingsBoardOpenObserve
SectorAnalyticsAnalytics
Velocity score0.06.3
Sparks · 30d01
Top themesiot, cve-remediation, ssrf, rule-engineai observability, synthetic monitoring, incident workflows, open source
Last editorial update2h ago3d ago
WebsiteVisit →Visit →

What is ThingsBoard?

An IoT platform whose release notes have become a CVE ledger

ThingsBoard ships every release twice — once on the 4.3 line and once as a 4.2 backport with an identical security section — and those security sections now dominate the notes, running to twenty or thirty CVEs per release. The recurring classes are telling: SSRF through AI model provider URLs, SSRF and file access escapes from the TBEL script sandbox, DNS rebinding bypasses, and access control on alarm comments. Feature work continues underneath, mostly IoT Hub integration and an Angular 20 UI migration.

Read the full ThingsBoard trajectory →

What is OpenObserve?

One release turns a telemetry store into synthetics, workflows, and AI observability.

v0.92.0 landed today after four release candidates, spanning 836 commits across the OSS and enterprise repositories. It adds three surfaces the product did not have — synthetic monitoring with private locations and agents, Workflows v1 tied to incidents, and an expanded AI observability set covering trace and session evaluations, an eval scheduler, organization AI credits, and an agent/service graph. Running alongside it, a 0.91.x maintenance branch has been taking small backported fixes on its own cadence.

Read the full OpenObserve trajectory →

ThingsBoard vs OpenObserve: editorial side-by-side

T
ThingsBoard
ANALYTICS
0.0

An IoT platform whose release notes have become a CVE ledger

◆ Current state

ThingsBoard ships every release twice — once on the 4.3 line and once as a 4.2 backport with an identical security section — and those security sections now dominate the notes, running to twenty or thirty CVEs per release. The recurring classes are telling: SSRF through AI model provider URLs, SSRF and file access escapes from the TBEL script sandbox, DNS rebinding bypasses, and access control on alarm comments. Feature work continues underneath, mostly IoT Hub integration and an Angular 20 UI migration.

◆ Where it's heading

The platform is paying down the security cost of being extensible. TBEL scripting and user-configurable AI model endpoints are exactly the features that make ThingsBoard useful for industrial rule engines, and both are repeatedly the source of sandbox and SSRF findings — so the work has shifted to fencing them with allow-lists, opt-in SSRF protection and configurable security headers. Meanwhile the AI surface keeps growing, with structured output support spreading across more model providers.

◆ Prediction

The dual-branch pattern will hold, with 4.2 continuing to receive the same security sets as 4.3 until it reaches end of life; expect further hardening of the TBEL sandbox rather than new scripting capability.

O
OpenObserve
ANALYTICS
6.3

One release turns a telemetry store into synthetics, workflows, and AI observability.

◆ Current state

v0.92.0 landed today after four release candidates, spanning 836 commits across the OSS and enterprise repositories. It adds three surfaces the product did not have — synthetic monitoring with private locations and agents, Workflows v1 tied to incidents, and an expanded AI observability set covering trace and session evaluations, an eval scheduler, organization AI credits, and an agent/service graph. Running alongside it, a 0.91.x maintenance branch has been taking small backported fixes on its own cadence.

◆ Where it's heading

Scope is moving outward from storing and querying telemetry toward acting on it: alerting gained per-group and per-series rules with SLO measurement, incidents can be ingested from external alert sources, and Workflows connects automation to them. The second axis is observing AI systems rather than merely serving them, with evaluations and an agent graph now first-class. Moving Vortex and the MCP server into open source, the latter on the 2026-07-28 spec with OAuth 2.0 sign-in, points the same platform at agent clients as consumers of its data.

◆ Prediction

Expect a 0.92.x patch train within days — each of the last two GA releases drew several backport-only point releases — concentrated on the newly opened surfaces. The crate modularization noted in the release also makes a period of build and packaging fixes likely.

Alternatives to ThingsBoard and OpenObserve

Other Analytics products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either ThingsBoard or OpenObserve.

See all ThingsBoard alternatives → · See all OpenObserve alternatives →

Recent activity from ThingsBoard and OpenObserve

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 3d agoOpenObservev0.92.0 adds synthetic monitoring, workflows, and AI observability
  2. 4d agoOpenObserveRelease candidate 4 backports fixes before the v0.92.0 GA
  3. 5d agoOpenObserveRC3 adds agent-level filters and parallel zstd compression
  4. 11d agoOpenObservev0.91.5 patches an RBAC migration and a layout bug
  5. 13d agoOpenObservev0.91.4 fixes memtable rotation and a column migration
  6. 19d agoOpenObservev0.91.3 applies anomaly thresholds without a retrain
  7. 1mo agoThingsBoard4.3.1.3 clears 25+ CVEs and adds IoT Hub integration
  8. 1mo agoThingsBoard4.2.2.3 backports the full 4.3.1.3 security set
  9. 2mo agoThingsBoard4.3.1.2 fences the TBEL sandbox and AI provider URLs against SSRF
  10. 2mo agoThingsBoard4.2.2.2 backports the TBEL sandbox and SSRF fixes
  11. 4mo agoThingsBoard4.3.1.1 adds configurable security headers and a rebinding allow-list
  12. 4mo agoThingsBoard4.2.2.1 backports security headers and CORS configuration

Frequently asked questions

What is the difference between ThingsBoard and OpenObserve?

They serve adjacent needs but don't currently overlap on shipped themes. OpenObserve is currently shipping more aggressively (velocity 6.3 vs 0.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is ThingsBoard better than OpenObserve?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. OpenObserve is currently shipping more aggressively (velocity 6.3 vs 0.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Analytics products to evaluate alongside.

What are the best alternatives to ThingsBoard?

Top ThingsBoard alternatives in Analytics are ranked by recent ship velocity. Browse the "ThingsBoard alternatives" section above for the current picks, or visit /alternatives/thingsboard for the full list with editorial commentary on each.

What are the best alternatives to OpenObserve?

Top OpenObserve alternatives in Analytics are ranked by recent ship velocity. Browse the "OpenObserve alternatives" section above for the current picks, or visit /alternatives/openobserve for the full list with editorial commentary on each.