Most SIEM vendors publish no list price. Cost is assembled from five things: what you ingest, how long you keep it and in which tier, the engineers who run the platform, the detection content someone has to write and maintain, and the analyst hours spent on the alerts it produces. Licence is usually the smallest of the five once a deployment is real.
That is the honest answer to "how much does a SIEM cost", and it is why quotes from two vendors are rarely comparable. This article sets out what actually drives the bill, how to build a total cost of ownership model you can defend to a finance director, and how to cut licensing spend without cutting visibility.
Why nobody publishes a SIEM price list
Start with an observable fact rather than a claim. Microsoft's own Microsoft Sentinel pricing page names the shape of the model: an analytics tier with pay-as-you-go and commitment options from 100 GB to 50,000 GB per day, a lower-cost data lake tier for long-term storage, up to 5 MB of free daily ingestion per user for key security logs, and promotional pricing on the 50 GB commitment tier running from 1 October 2025 to 31 December 2026. But it prints no fixed rate card. It sends you to a pricing calculator and a sales specialist, and states that actual pricing varies with agreement type, purchase date, currency and tax.
Elastic is the exception that proves the rule, because its serverless tiers are published. On the Elastic serverless security pricing page, Security Analytics Essentials is listed at "as low as" $0.09 per GB ingested and $0.017 per GB per month retained; Security Analytics Complete at "as low as" $0.11 per GB ingested and $0.019 per GB per month retained. Egress is 50 GB free, then $0.05 per GB. Add-ons are priced separately: cloud security posture management from $0.65 per billable asset per month, workload protection from $0.41 per asset per month, and the Elastic Managed LLM at $4.50 per million input tokens and $21 per million output tokens.
Two lessons fall out of those numbers before you compare any vendors.
First, ingest and retention are priced on completely different scales. In Elastic's published Complete tier, a gigabyte costs roughly six times more to bring in once than to hold for a month. Any model that treats "SIEM cost" as one per-GB number is wrong by construction.
Second, the platform fee is not the product. Posture management, workload protection and AI features are all metered on their own units: assets, executions, tokens. A quote that covers only log ingestion is quoting a fraction of what the security team will end up using.
Where a vendor publishes nothing, the correct move is not to guess. It is to demand the meter definitions, then model your own volumes against them.
Factors driving SIEM costs in enterprise deployments
Enterprise deployments diverge from mid-market ones on five drivers.
Ingest volume, and its growth rate. Every new SaaS application, cloud account, identity provider and endpoint adds telemetry. The rate matters more than today's number, because a three-year commitment is priced against year-one volume and consumed at year-three volume. Ask for your own last twelve months of daily GB, then extrapolate honestly.
Log source mix. Firewall, proxy, DNS and cloud audit logs are high volume and low information density. Identity, EDR and email logs are lower volume and higher density. Two organisations with identical GB per day can have very different detection value from the same spend, so measure detections per GB by source, not just GB.
Retention tier and duration. Regulatory retention is not a security requirement. Keeping a year of firewall logs in a hot searchable tier because a policy says "retain twelve months" is one of the most common avoidable costs in the estate. Separate the tier you investigate in from the tier you retain in.
Engineering to run the platform. Someone maintains collectors, parsers, field mappings and upgrades. In an enterprise this is a standing team, not a project. It does not appear on the vendor quote and it does not go away.
Detection content. Rules do not maintain themselves. Log formats change, cloud services change, and every false positive is a tuning ticket. Whether the content ships with the platform, is written by your team, or comes from a managed provider changes the cost profile more than the licence line does. Our detection engineering principles post covers what that workload looks like in practice.
Analyst time. This is the largest hidden item and the hardest to see, because it sits in a headcount budget rather than a software one. The number to watch is not alerts closed. It is how many alerts a human had to open at all.
How to calculate the total cost of ownership for different SIEM solutions
Build the model in units you control, then price each vendor's meters against it. The order matters: volumes first, prices second. If you start from a quote you will only ever validate the vendor's assumptions.
- Measure current daily ingest by source, in GB, over at least ninety days. Record peak as well as mean; commitments are sized on sustained volume but overages hit on peaks.
- Assign each source a retention requirement and split it into hot (investigate), warm (search occasionally) and archive (produce on request). Most estates find that under a third of the volume genuinely needs a hot tier.
- Project three-year growth per source. Cloud and identity sources typically grow fastest.
- Count the engineering. Full-time equivalents on platform operations, at your own loaded cost. Use your real salary bands; do not import a benchmark.
- Count the detection content. FTE days per month writing and tuning rules, plus any content subscription.
- Count the analyst hours consumed by the alert queue the platform produces, again at your own loaded cost.
- Add migration and exit. Parser rework, dual running during cutover, and the cost of getting your data out at the end. Our SIEM migration guide sets out what that programme involves.
Then price each candidate against the same seven rows. Any vendor that cannot be modelled this way has not given you enough meter detail to be compared.
A TCO worked example, line by line
The table below is a modelling frame, not a quote. Where a public price exists it is cited; where it does not, the row says what drives the cost and what to ask for.
| Line item | What drives it | Published price evidence | What to ask the vendor |
|---|---|---|---|
| Ingest licence | GB per day, committed or pay-as-you-go; overage rate | Elastic serverless publishes "as low as" $0.09/GB (Essentials) and $0.11/GB (Complete); Microsoft publishes no fixed rate for Sentinel and directs buyers to a calculator | The exact overage rate, the true-up mechanism, and whether the commitment can be reduced at renewal |
| Storage tiers | Hot versus warm versus archive GB-months, and the cost to rehydrate | Elastic serverless publishes retention at "as low as" $0.017–$0.019 per GB per month, roughly a fifth to a sixth of the matching ingest rate | Price per GB-month per tier, search latency in each tier, and the charge to restore archived data |
| Egress and export | GB moved out for another tool, an audit, or an exit | Elastic serverless publishes 50 GB free egress, then $0.05/GB | Whether raw data export is chargeable, and at what rate on exit |
| Platform engineering | FTEs maintaining collectors, parsers, mappings, upgrades | None: internal cost | Reference customers' FTE counts at your ingest volume |
| Detection content | Rules written and tuned per month; content subscription fees | None: internal or subscription cost | What ships out of the box, update cadence, and who owns tuning after go-live |
| Analyst time | Alerts a human must open per day × minutes per alert × loaded cost | None: internal cost | Measured true-positive rate and the share of cases closed without human touch |
| Add-on modules | Posture, workload protection, AI features, metered on their own units | Elastic serverless publishes CSPM from $0.65 per asset per month and its managed LLM at $4.50 per million input tokens | Which capabilities in the demo are inside the base tier |
The rows without a published price are the ones that usually dominate. That is the point of the exercise: a TCO model that only contains vendor-quotable lines will always understate the real number, and will always flatter whichever vendor has the lowest per-GB rate.
The data tax: what paying by volume does to detection
A per-GB meter creates a standing incentive to collect less. That incentive lands precisely where security needs the opposite.
The pattern is familiar. Budget pressure arrives, the highest-volume sources are the obvious target, and firewall or DNS logs get dropped or sampled. The bill falls. The blind spot is invisible, because you cannot alert on what you never collected. Nobody writes an incident report saying the detection failed for want of a log source that was cut two years earlier.
Raising alert thresholds does the same thing more quietly. It trades a visible workload problem for an invisible miss rate.
There is a third option, which is to change what handles the first pass. Across more than 30 million investigated cases on the SenseOn platform over a rolling twelve-month window, confirmed true positives run at 0.68%. Roughly 99 in every 100 things worth a look are not worth a human's look. Headcount cannot close that gap; a machine first pass that shows its working can. We cover the queue side of this in how to reduce alert fatigue.
How to reduce SIEM licensing costs without losing functionality
Five moves, in the order that usually pays best.
Tier by investigation value, not by policy. Split each source into what you search weekly, what you search during an incident, and what you keep only to satisfy a regulator. Move the third group to the cheapest compliant tier. This is the single largest saving in most estates and it costs no visibility, because those logs were not being searched.
Filter and shape at the edge. Drop duplicate fields, debug verbosity and heartbeat records before they cross a metered boundary. SenseOn removes ~40% of data at the edge before the pipeline starts, pre versus post processing. Whatever platform you run, the edge is the cheapest place to make volume decisions.
Route noisy, low-value sources away from the metered path. Not every log needs to sit in the detection platform. Some belong in object storage, queryable when required.
Consolidate overlapping licences. Estates that have accumulated a SIEM, an EDR, an NDR, a UEBA product and a SOAR are often paying several vendors to see the same event. Security tool consolidation is a licensing exercise as much as an architectural one, and SIEM alternatives sets out which platform categories can absorb which functions.
Negotiate the meter, not the discount. A discount applies to this term. The overage rate, the true-up mechanism and the right to reduce a commitment apply to every year that follows. More detail in 4 SIEM price reduction tactics examined.
What none of these five requires is collecting less security-relevant telemetry. That distinction is the whole game.
What a credit model changes
SenseOn prices outcomes rather than raw ingest. Data is not billed by volume, so the per-GB ingest charge is £0. A committed annual credit pool covers detection, investigation, compliance and AI-accelerated resolution across network, endpoint, cloud and identity.
The effect on the model above is specific rather than general. It removes the ingest licence line and the incentive it creates, and it moves the analyst-time line, because 92.5% of incidents are resolved under human governance with a detect-and-respond time of <20 min. Every one of those actions carries a Decision Trace with 100% audit coverage, which matters when a regulator under DORA or NIS2 asks who decided what. It does not remove platform engineering, and it does not remove the need to model your own volumes; you should still do steps 1 to 7.
Our numbers are on our platform, published with methodology on proof points, and you should ask any vendor including us for the same four measures defined identically: alerts a human had to open, detect-and-respond time, true positives as a share of investigated cases, and spend for the visibility you want.
If you are weighing platform categories rather than vendors, XDR vs SIEM explains where the architectures differ, and AI in threat detection covers what the first-pass machine layer can and cannot do. Current pricing is on the pricing page.
Frequently asked questions
How much does a SIEM cost?
Most SIEM vendors publish no list price. Cost is assembled from ingest volume, retention tier and duration, platform engineering, detection content and analyst time. Elastic publishes serverless rates from $0.09 per GB ingested; Microsoft publishes no fixed Sentinel rate and directs buyers to a calculator. Model your own volumes first, then price each vendor's meters against them.
How do I calculate the total cost of ownership for different SIEM solutions?
Measure ninety days of daily ingest by source, assign each source a hot, warm or archive retention tier, project three-year growth, then add platform engineering FTEs, detection content effort, analyst hours on the alert queue, and migration and exit costs. Price every candidate against those same rows. A model containing only vendor-quotable lines will understate the real number.
What factors drive SIEM costs in enterprise deployments?
Six: daily ingest volume and its growth rate; log source mix, since high-volume sources are often low in information density; retention tier and duration; the engineering team maintaining collectors and parsers; detection content written and tuned every month; and analyst hours spent on the alert queue. The last three rarely appear on a vendor quote.
How can I reduce SIEM licensing costs without losing functionality?
Tier data by investigation value rather than by retention policy, filter and shape at the edge before data crosses a metered boundary, route noisy low-value sources to cheaper storage, consolidate overlapping product licences, and negotiate the overage rate and true-up mechanism rather than the headline discount. None of those five means collecting less security-relevant telemetry.
Is a cheaper per-GB rate always cheaper overall?
No. Ingest and retention are metered on different scales, and add-on capabilities such as posture management, workload protection and AI features are metered on their own units. A platform with a low ingest rate and expensive hot retention can cost more than a dearer one at the same volume. Compare full three-year models, never single rates.
What should I ask a SIEM vendor about price?
Six questions: the exact overage rate and true-up mechanism; price per GB-month in every retention tier; the charge to rehydrate archived data; whether raw data export is chargeable on exit; which demonstrated capabilities sit outside the base tier; and the measured true-positive rate, so you can estimate the analyst hours the platform will consume.