Skip to content

Guide · SIEM pricing

SIEM cost guide

How SIEM pricing works

SIEM does not price like most software. There is no simple per-user fee. The meter that matters is data volume — how many gigabytes of logs you ingest per day — multiplied by how long you retain them. Three cost layers stack on top of each other:

  • Ingest / license. Charged per GB/day (or GB/month, or events per second). This is the headline number and it scales directly with how chatty your environment is.
  • Retention & storage. Keeping searchable "hot" data for 90 days costs far more than archiving it cold for a year. Compliance often forces longer retention than you'd otherwise choose.
  • Staffing. The largest hidden cost. A SIEM produces alerts; someone must tune rules, triage, and respond. Without analysts (in-house or via MDR), the platform is expensive shelfware.

What it costs by data volume

Because volume is the master variable, the most honest way to scope SIEM cost is by GB/day. The table maps typical ingest tiers to annual licensing and the all-in cost once you add storage and the people to run it.

Ingest Profile License / year All-in (incl. staff) / year
< 5 GB/daySmall business$15K – $60K$60K – $180K
5 – 20 GB/daySMB / lower mid$50K – $150K$150K – $400K
20 – 100 GB/dayMid-market$120K – $400K$350K – $1.1M
100 – 500 GB/dayEnterprise$350K – $1.2M$1M – $3M+
500 GB+/dayLarge enterprise$1M+$3M – $10M+

Aggregated from public list pricing and field deals; negotiated and commitment pricing typically runs 20–40% below list.

The vendor landscape

The major platforms make fundamentally different pricing bets. Knowing the model tells you where your bill will balloon.

Vendor Pricing model Best fit
SplunkIngest / workload pricing; powerful but premium.Large, data-heavy SOCs.
Microsoft SentinelPer-GB ingested, commitment tiers; cloud-native.Microsoft / Azure-centric orgs.
IBM QRadarEvents-per-second / flows; appliance or cloud.Regulated enterprises.
Elastic SecurityResource-based; lower license, more self-managed.Engineering-rich teams.

The hidden costs

SIEM sticker shock usually comes from the line items not in the quote: storage for long retention, professional services for deployment and content, the integration engineering to onboard every log source, and — above all — the analysts to act on what it surfaces. Budget for the program, not the license.

"A SIEM is a question machine, not an answer machine. If you can't staff the people to act on its alerts, you're paying enterprise prices for an expensive log archive."

— SecurityBudget Research Team

Frequently asked questions

How is SIEM priced?

Most modern SIEMs price on data volume — either ingest (GB/day or GB/month) or events per second — plus retention. Microsoft Sentinel charges per GB ingested; Splunk has moved toward workload/ingest pricing; Elastic prices on resources. On top of the license, expect storage for retention and significant staffing cost to run it.

How much does a SIEM cost per year?

A small deployment (a few GB/day) can run $15K–$60K/year in licensing; mid-market (20–100 GB/day) commonly lands $80K–$400K; large enterprises ingesting terabytes daily reach seven figures. Tooling is often less than half the true cost once analysts and engineering are included.

What drives SIEM cost the most?

Data volume is the dominant lever — every additional log source and verbose setting adds GB/day, which compounds with retention. The second-biggest driver is people: a SIEM no one tunes or monitors is shelfware, and skilled analysts are expensive and scarce.

Is Microsoft Sentinel cheaper than Splunk?

Often, especially for Microsoft-heavy shops that benefit from bundled data sources and commitment-tier discounts. But Sentinel still charges per GB ingested, so a noisy environment can erase the savings. Total cost depends far more on your data volume and tuning discipline than on the logo.

How can I reduce SIEM costs?

Filter and route logs before ingest, drop low-value verbose data, tier retention (hot vs cold/archive), use commitment pricing, and consider a log pipeline or data lake in front of the SIEM. Disciplined source selection routinely cuts ingest 30–50% with no loss of detection coverage.

References

See SIEM in your full budget

SIEM rarely stands alone. See how it fits alongside EDR, MDR, and the rest of a defensible program.

Open the budget calculator

Estimates are based on public pricing, industry benchmarks, and security frameworks. For planning only — not professional, financial, or legal advice.