The average enterprise SIEM cost runs $3-5M per year. That number grows 30-40% annually. Every budget cycle, the same conversation happens: the SIEM bill came in higher than expected, leadership wants answers, and someone suggests switching vendors.
Here’s what nobody tells you during the sales cycle: switching SIEMs doesn’t fix the cost problem. Every major SIEM on the market uses volume-based pricing. You’re not paying too much for Splunk or Sentinel or Elastic. You’re paying for data volume, and that volume keeps growing.
This post breaks down how SIEM pricing actually works, compares costs across vendors with real numbers, and shows the one approach that consistently cuts SIEM spend by 40-80% without ripping and replacing anything. Whether you are exploring observability cost optimization or evaluating a full SIEM migration, understanding the underlying cost dynamics is the first step.
How SIEM Pricing Works
Every major SIEM ties its pricing to data volume in some form. The meter might be labeled differently (ingestion, events per second, nodes, storage), but the underlying economics are the same: more data in, more money out.
Here’s how each vendor structures it.
Splunk
Splunk prices primarily on daily ingest volume. Their workload-based pricing (introduced with Splunk Cloud Platform) charges per GB of data indexed. On-premise licenses use a similar ingest-tier model.
Typical enterprise pricing: $1,800/year for 1 GB/day on the low end, scaling to $150,000+/year for 100+ GB/day. Volume discounts apply at higher tiers, but the per-GB cost still compounds as data grows. Splunk also offers entity-based pricing (per host), though most security deployments still land on ingest-based models.
The kicker: Splunk charges for data at ingest, whether you query it or not. Every log line that hits the indexer costs money the moment it arrives.
Elastic Security
Elastic takes a hybrid approach. Self-managed deployments are free (open-source core), but you pay for support subscriptions and node-based licensing. Elastic Cloud charges based on deployment size, storage, and compute consumption.
Cloud pricing starts around $95/month for small deployments and scales based on instance types and storage tiers. A production security deployment processing 5-10 GB/day typically runs $2,000-$5,000/month on Elastic Cloud. Self-managed looks cheaper on paper until you factor in infrastructure, staffing, and the operational overhead of running your own cluster.
Elastic’s pricing is less predictable than Splunk’s because it depends on how you architect your deployment. Hot/warm/cold storage tiers, snapshot repositories, and cross-cluster search all affect the final number.
Microsoft Sentinel
Sentinel charges per GB ingested, with a separate meter for log retention beyond 90 days. Pay-as-you-go pricing sits at roughly $2.46/GB ingested. Commitment tiers bring that down: 100 GB/day commitments drop to about $1.50/GB, and 500 GB/day gets close to $1.00/GB.
The hidden costs: Sentinel runs on Azure Log Analytics, so you’re also paying for workspace storage, data export, and any Logic Apps or automation playbooks you build. Microsoft offers free ingestion for some data sources (Azure Activity Logs, Office 365 audit logs), which helps, but security telemetry from non-Microsoft sources gets the full per-GB rate.
For a mid-size enterprise ingesting 50 GB/day, expect $3,000-$5,000/month in Sentinel costs alone, before automation and retention add-ons.
Datadog Security
Datadog prices security monitoring at $15/host/month as a base. That gets you Cloud SIEM. Add Cloud Security Management at $12/host/month, Application Security at $31/service/month, and log ingestion at $0.10/GB (with $1.06/million events for indexed logs).
For a 500-host environment, Datadog Security runs $7,500/month for SIEM alone. Add log management, and a 10 GB/day ingest pushes the bill past $10,000/month without blinking. Datadog’s per-host model looks appealing at small scale, but it compounds fast because host counts and data volumes grow in lockstep.
CrowdStrike LogScale (Falcon)
CrowdStrike’s LogScale (formerly Humio) prices on daily ingest volume, similar to Splunk. Pricing is typically negotiated at the enterprise level, but market estimates put it at $1.50-$3.00/GB/day ingested, depending on volume commitments and bundling with other Falcon modules.
LogScale’s compression and architecture are more efficient than legacy Splunk deployments, but the pricing model is functionally identical: more data, more cost.
SIEM Cost Comparison Table
| SIEM | Pricing Model | Cost for 1 GB/day | Cost for 10 GB/day | Cost for 100 GB/day | What Drives the Bill |
|---|---|---|---|---|---|
| Splunk | Per GB ingested | ~$1,800/yr | ~$18,000/yr | ~$120,000+/yr | Ingest volume |
| Elastic Cloud | Consumption-based | ~$1,200/yr | ~$30,000/yr | ~$120,000+/yr | Nodes, storage, compute |
| Microsoft Sentinel | Per GB ingested | ~$900/yr (PAYG) | ~$9,000/yr | ~$55,000/yr (commitment) | Ingest + retention |
| Datadog Security | Per host + per GB | ~$2,400/yr (base) | ~$12,000+/yr | ~$80,000+/yr | Host count + log volume |
| CrowdStrike LogScale | Per GB ingested | ~$1,500/yr | ~$12,000/yr | ~$90,000+/yr | Ingest volume |
Note: Prices are approximate and vary based on contract terms, commitment tiers, and bundling. Contact vendors for current quotes.
The comparison reveals an uncomfortable truth: the vendor you choose matters less than the volume you send. At 100 GB/day, every SIEM on this list costs six figures annually. At 1 TB/day, you’re in seven-figure territory regardless of platform. The pricing model is the same everywhere. Volume in, dollars out.
Switching from Splunk to Sentinel might save you 20-30%. But if your data volume doubles in 18 months (and it will), you’re back where you started. The SIEM isn’t the problem. The data is.
Why SIEM Costs Spiral (It’s Not the Platform)
SIEM costs don’t grow because vendors raise prices. They grow because data volume grows.
Cloud workloads multiply log sources. Every container, serverless function, and API gateway generates telemetry. A Kubernetes cluster with 200 pods produces orders of magnitude more log data than the 20 VMs it replaced. The infrastructure got more efficient. The log processing got worse.
Microservices create exponential telemetry. A monolith generates one set of application logs. The same application split into 40 microservices generates 40 sets of logs, plus inter-service tracing, API call logs, and service mesh telemetry. Companies that moved to microservices between 2020 and 2024 saw their SIEM ingest jump 3-5x without adding a single new application.
Edge and IoT devices keep expanding. Every branch office, retail location, and connected device adds its own telemetry stream. A telecom operator with 3,847 sites doesn’t just have data center logs. It has site-level firewall, access point, and network device logs from every single location.
Compliance requirements ratchet upward. SOX, PCI DSS, HIPAA, SOC 2. Each framework adds retention requirements and mandates logging for more systems. Security teams can’t reduce log collection because auditors want to see it all.
The result: enterprise data volumes grow 25-40% year over year. Your SIEM contract might be flat for the first year. By year two, you’re over your committed tier. By year three, you’re back in procurement negotiating a bigger commitment or eating overage charges.
This is not a Splunk problem. It’s not a Sentinel problem. It’s a data volume problem. And it follows you to every platform.
The Math: What Percentage of Your Logs Are Actually Useful?
Here’s where the cost conversation gets interesting.
Most security teams ingest everything and query almost nothing. Studies from SIEM vendors themselves show that the average organization queries less than 30% of its ingested data for security purposes. The other 70% sits in indexes, costing money per GB, and never gets touched until it ages out.
Where does all that noise come from?
Debug and verbose logs that got left on in production. Application teams set logging to DEBUG during development and never turned it down. Those logs are useless for security detection but cost the same per GB as firewall alerts.
Health checks and heartbeats. Load balancers pinging backend services every 5 seconds generate millions of “200 OK” log entries per day. These have zero security value. They consume real ingest budget.
Duplicate and redundant events. The same authentication event logged by the application, the identity provider, and the network access control system. Three log entries for one event. Your SIEM doesn’t deduplicate at ingest. You pay for all three.
Informational network traffic. DNS queries to known-good domains. NTP synchronization. DHCP renewals. Broadcast traffic. All of it gets logged, forwarded, and ingested.
A real-world example: A global bank audited their Splunk deployment and found that 73% of their daily 14.3 TB ingest was noise. Health checks, verbose application logs, and duplicate events. They were paying to index 10.4 TB/day of data that no analyst ever queried and no detection rule ever matched.
The math is straightforward. If 60-70% of your SIEM data is noise, you’re spending 60-70% of your SIEM budget on nothing. On a $3M annual Splunk bill, that’s $1.8-2.1M per year lighting money on fire.
The fix isn’t writing better queries. The fix is stopping the noise before it reaches the SIEM.
How to Actually Fix SIEM Costs
There are three common approaches to SIEM cost reduction. Two of them don’t work long-term. One does.
Approach 1: Switch SIEMs
The most common reaction to a high SIEM bill is shopping for a cheaper one. And yes, some platforms are 20-30% cheaper per GB than others.
But switching SIEMs is a 12-18 month project. It requires rebuilding detection rules, dashboards, integrations, and analyst workflows. By the time the migration is done, your data volume has grown enough to eat the savings. You spent $500K in migration costs to land in the same place.
Switching makes sense when you have platform-specific pain (performance, features, support). It does not make sense as a cost strategy.
Approach 2: Reduce Retention Periods
Shorter retention means less storage cost. Drop from 13 months to 3 months and your storage bill falls.
The problem: compliance frameworks often mandate specific retention periods. PCI DSS requires 12 months of log data. SOX can require 7 years. You can move old data to cold storage (Sentinel and Elastic both support tiered storage), but the ingest cost at the front end stays the same. Retention optimization helps at the margins. It doesn’t fix the core problem.
Approach 3: Filter Data Before It Reaches the SIEM
This is the one that works.
Instead of ingesting everything and hoping analysts find the signal, filter telemetry at the source. Strip out debug logs before they leave the server. Deduplicate authentication events at the collection layer. Route health checks to cheap storage instead of the SIEM. Aggregate verbose network logs into summaries.
The concept is simple: put a data control plane between your sources and your SIEM. Let it filter, route, transform, and reduce data in flight. Only security-relevant telemetry reaches your SIEM.
The bank case study in full: A global financial institution was ingesting 14.3 TB/day into Splunk at an annual cost of $3.7M. After deploying an upstream data control plane (Expanso), they reduced ingest to 5.2 TB/day, a 64% reduction. Their Splunk bill dropped to $1.4M, saving $2.3M annually (62% cost reduction). Security operations actually improved: with less noise, analysts achieved 4x faster triage times.
The telecom case study: A telecom operator with 3,847 sites deployed upstream filtering and achieved a 78% telemetry reduction. Their Splunk costs dropped 47%. The remaining telemetry was higher quality, with noise stripped out at the edge before it ever hit the network.
An enterprise-scale deployment: Another organization cut their monitoring spend from $240K/month to $71K/month (70% reduction). Query performance went from 45 seconds to 2.8 seconds, a 16x improvement, because the SIEM was indexing relevant data instead of drowning in noise.
This approach works with any SIEM. It sits in front of whatever platform you already use. Expanso operates as an upstream data control plane that integrates with Splunk, Elastic, Microsoft Sentinel, and Datadog Security. The SIEM stays. The noise goes.
Across deployments, upstream filtering typically achieves 50-70% volume reduction and 40-80% cost savings, depending on the environment and how much noise exists in the current telemetry pipeline.
SIEM Cost Calculator: Before and After
Let’s walk through the math with a concrete example.
Before: No Upstream Filtering
- Daily ingest: 10 TB/day
- Average cost per GB: $2.00 (blended rate across ingest + storage)
- Monthly ingest: 10 TB x 30 days = 300 TB = 300,000 GB
- Monthly cost: 300,000 GB x $2.00 = $600,000/month
- Annual cost: $7,200,000
After: 60% Upstream Reduction
- Daily ingest after filtering: 4 TB/day (60% noise removed)
- Monthly ingest: 4 TB x 30 days = 120 TB = 120,000 GB
- Monthly cost: 120,000 GB x $2.00 = $240,000/month
- Annual cost: $2,880,000
- Annual savings: $4,320,000
That’s $4.3M back in the budget. No SIEM migration. No renegotiated contract (though you should renegotiate at the lower volume). No reduction in detection coverage, because the 60% you removed was noise that didn’t trigger any security rules.
Scale It to Your Environment
| Daily Ingest | Cost/GB | Monthly Before | Monthly After (60% reduction) | Annual Savings |
|---|---|---|---|---|
| 1 TB/day | $2.00 | $60,000 | $24,000 | $432,000 |
| 5 TB/day | $2.00 | $300,000 | $120,000 | $2,160,000 |
| 10 TB/day | $2.00 | $600,000 | $240,000 | $4,320,000 |
| 20 TB/day | $1.50 | $900,000 | $360,000 | $6,480,000 |
| 50 TB/day | $1.00 | $1,500,000 | $600,000 | $10,800,000 |
At higher volumes, per-GB rates typically decrease with commitment tiers, but the absolute savings grow proportionally.
Want to run the numbers for your specific environment? Use our ROI Calculator to model your current ingest, noise ratio, and potential savings across different SIEM platforms.
FAQ
How much does a SIEM cost per year?
SIEM costs vary widely based on data volume and vendor. A small deployment ingesting 1 GB/day runs $1,000-$2,500/year. Mid-size deployments at 10-50 GB/day cost $10,000-$100,000/year. Enterprise deployments processing 1+ TB/day typically land at $500,000-$5M+ per year. The primary cost driver across all vendors is data volume. Managed SIEM services (MSSP-operated) add $5,000-$50,000/month on top for staffing and operations, depending on scope and SLA.
Which SIEM is cheapest?
No single SIEM is consistently cheapest across all scenarios. Microsoft Sentinel tends to be the most cost-effective at lower volumes due to free ingestion for some Microsoft data sources. Elastic self-managed has the lowest licensing cost but the highest operational overhead. Splunk and Datadog tend to be premium-priced but offer stronger out-of-the-box detection content.
The real answer: at scale, the cheapest SIEM is whichever one receives the least unnecessary data. A well-filtered 10 TB/day Splunk deployment costs less than an unfiltered 30 TB/day Sentinel deployment.
Can I reduce SIEM costs without switching vendors?
Yes. The most effective approach is reducing data volume before it reaches your SIEM. Upstream filtering removes noise (debug logs, health checks, duplicates, informational events) at the collection layer. Organizations typically find that 50-70% of their SIEM ingest is low-value data that no detection rule matches and no analyst queries. Removing that noise cuts costs by 40-80% and often improves SIEM performance because the platform processes less data overall.
What is a managed SIEM and what does it cost?
A managed SIEM is a security monitoring service where an MSSP (Managed Security Service Provider) operates the SIEM on your behalf. This includes platform management, rule tuning, alert triage, and reporting. Managed SIEM costs include the platform licensing (same pricing models described above) plus service fees. Expect $5,000-$15,000/month for small environments and $20,000-$50,000+/month for enterprise deployments.
Managed SIEM doesn’t change the underlying cost equation. If your data volume grows, the managed SIEM bill grows too. Upstream filtering reduces managed SIEM costs the same way it reduces self-managed costs.
How long does it take to see SIEM cost savings from upstream filtering?
Most organizations see measurable ingest reduction within 2-4 weeks of deploying an upstream data control plane. The first phase typically targets the highest-volume, lowest-value log sources (health checks, verbose application logs, duplicate events). This alone can reduce ingest by 30-40%. Full optimization, including telemetry routing, aggregation, and format normalization, typically reaches 50-70% reduction within 60-90 days. The cost savings appear on the next billing cycle after ingest drops.
Stop Paying to Store Noise
Upstream data filtering is the only SIEM cost optimization strategy that compounds in your favor. As data volumes grow, the filter removes more noise, and the gap between your unfiltered and filtered cost widens over time. Instead of bills growing 30-40% per year, they stay flat or grow in single digits.
If you want to see what that looks like for your environment, book a data consultation with Expanso to walk through your top sourcetypes and model the savings.
