Guide

How Much Does a SIEM Cost? Real 2026 Pricing Models Explained

SIEM pricing explained: the four billing models, what drives the bill, why quotes vary tenfold, and how to estimate your cost before talking to sales.

Almost nobody publishes SIEM pricing, which is why this question gets asked constantly and answered badly. The honest answer is that the licence is rarely the number that hurts. What determines your bill is how much data you send the thing, and most teams get that estimate wrong by a factor of two or more in their first year.

This guide explains the four billing models, what actually drives cost, and how to produce a defensible estimate before you take a single sales call.

The four pricing models

Every SIEM on the market bills one of these four ways, and the model matters more than the headline rate.

Model How it bills Best when Watch out for
Per GB ingested Volume of log data per day or month Predictable, modest log volume Cost scales with a chatty new log source you did not plan for
Per event (EPS) Events per second, or per day Consistent event rates Bursts during an incident, exactly when you need it most
Per device or node Number of monitored assets Stable estate, verbose logs Cost per device stays flat even if logging is light
Per user Identities monitored Identity-centric detection Contractors and service accounts inflating the count

Per-GB is by far the most common, and it is the model that produces the horror stories. The reason is simple: you decide how much data to send, and every new integration silently raises the bill.

What actually drives the cost

The licence model is the multiplier. These are the inputs.

Log volume, and specifically which sources you enable. This is the dominant factor. A firewall or a cloud audit trail can generate more data than every server you own. Teams routinely start with a sensible estimate, then connect one verbose source and double their ingestion in a week.

Retention period. Storing 90 days costs a fraction of storing a year, and the difference compounds with volume. Many frameworks require 12 months of retention but not 12 months of hot, searchable data, which is the distinction that saves money.

Number of data sources. Not just for volume: each integration has a parsing and maintenance cost, and some vendors charge per connector.

Whether you buy detection or just storage. A log lake with search is much cheaper than a platform with maintained detection content, threat intelligence and case management. Decide which you are actually buying.

People. The cost nobody puts in the spreadsheet. A SIEM that nobody tunes produces alerts nobody reads. Budget for the analyst time or buy a managed service, but do not pretend the tool runs itself.

A rough way to estimate your volume

You can get within striking distance before talking to any vendor. Take your main log sources and estimate daily volume:

  • Firewall or network devices: often the largest single source, easily several GB a day even in a small estate
  • Endpoints: roughly tens of MB per device per day for standard security logging, far more with detailed process telemetry
  • Cloud audit logs: highly variable, and the source that most often surprises people
  • Servers and applications: depends entirely on log level, and turning on debug logging in production is the classic accidental cost event
  • Identity provider: modest volume, high detection value, one of the best ratios you can buy

Add them up, add 40 percent headroom for growth and incident bursts, and that is your planning number. The 40 percent is not padding. Log volume grows as you add sources, and it spikes exactly when you are under attack.

Why quotes vary so wildly

Two vendors can quote the same organisation figures that differ by an order of magnitude, and it is usually not a negotiation game. The causes:

Different retention assumptions. One quote is 90 days hot, another is 12 months. Always normalise this before comparing.

Hot versus cold storage. Modern platforms tier data: recent logs searchable instantly, older logs archived cheaply and slower to query. A quote that puts everything in hot storage will look far more expensive than one that tiers properly, for the same security outcome.

Detection content included or extra. Some vendors bundle maintained detection rules and threat intelligence; others sell them separately or expect you to write your own.

Commit versus on-demand. Annual commitment tiers are substantially cheaper per GB than pay-as-you-go, which is why the first quote often assumes a commit you have not agreed to.

The cost-control levers that actually work

Filter at the source, not at ingestion. Most SIEM bills contain a large share of data with no detection value: debug logs, health checks, verbose informational events. Filtering before ingestion is the single most effective lever available, and it routinely cuts volume by a third.

Tier your storage deliberately. Keep 30 to 90 days hot for investigation, archive the rest cheaply for compliance. Most requirements are about retention, not instant searchability.

Start with high-value sources. Identity, endpoint and cloud audit logs produce the most detections per GB. Chatty network logs produce the most volume per detection. Connect in that order, and add the verbose sources only when you have a reason.

Negotiate the overage clause, not just the rate. Ask what happens when you exceed your commit: is it a fair pro-rata rate, or a punitive one? That clause matters more than the headline price on any year where you grow.

Re-baseline annually. Volume drifts upward continuously. An annual review of what you are ingesting and why typically finds sources nobody has looked at since onboarding.

Open source is cheaper on licence, not on total cost

The Elastic and OpenSearch route removes the licence line entirely, and for teams with the right skills it is a legitimate answer. Be honest about what replaces it: infrastructure, storage, and engineering time to build and maintain detection content that commercial vendors ship and update.

The rule of thumb is that open source wins when you have dedicated security engineering capacity, and loses when you do not. A self-hosted stack with nobody tuning it is more expensive than a commercial tool in the only currency that counts, which is detections you actually act on.

Before you take the sales call

Do these four things and you will get a better quote and a much better comparison:

  1. Estimate your daily GB from your real log sources, with 40 percent headroom.
  2. Decide your hot retention separately from your compliance retention. They are different numbers.
  3. List which sources you will connect in year one, in priority order, rather than everything at once.
  4. Ask every vendor for the same three figures: cost at your estimated volume, cost at 1.5x that volume, and the overage rate.

That last one is the question that reveals the real cost of the platform.

Our comparison of the best SIEM tools covers which platforms suit which environment, and if you are still deciding whether you need a SIEM at all rather than endpoint detection first, the EDR and endpoint protection guide is the better starting point. For most small teams, endpoint and device management deliver more security per euro than a SIEM does.

The short version

SIEM cost is driven by data volume and retention, not by the licence line. Estimate your GB honestly, add headroom, filter aggressively at the source, tier your storage, and normalise every quote to the same retention assumption before comparing. Then budget for the analyst time, because a SIEM that nobody tunes is the most expensive option of all.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free