Ask AI
VirtualMetric is heading to Gartner Security & Risk Management Summit

News overview

SIEM Pricing 2026: Major Providers Compared (& How to Lower Your Bill)

siem pricing

Every major security information and event management (SIEM) platform prices on the volume of data you send it. Microsoft Sentinel meters per gigabyte across two tiers. Splunk charges per gigabyte indexed or per compute unit. Google SecOps draws down a prepaid gigabyte credit balance. Elastic Security bills ingest plus retention, or the resources your cluster consumes.

Three of the four keep their real rates quote-only. Budgeting starts with the meter.

Key takeaways

  • Ingestion is one meter among several. Microsoft Sentinel alone bills lake ingestion, data processing, storage, query volume scanned, and notebook compute hours.
  • The SIEM layer is often priced separately. Splunk Enterprise Security adds roughly 50 to 100 percent on top of the base platform.
  • Retention is a standing line item. Splunk Cloud includes 90 days, Google SecOps includes 12 months, and Sentinel and Elastic meter it apart.
  • Reducing volume before ingestion is the only lever that acts before billing starts. Every other lever works on data you already paid for.

This guide compares the pricing models and names every meter. It does not recommend a SIEM.

SIEM vendors charge in five different ways

Five pricing models cover the market in 2026. Each meters a different thing, which is why two teams sending identical volume can pay very different amounts.

Pricing modelWhat it metersTrade-offPlatforms using it
Ingestion-meteredGigabytes arrivingSimple to forecast, and noisy sources are expensiveSplunk on ingest pricing
Multi-meter tieredIngestion, processing, storage, query, computeCheaper per gigabyte, harder to modelMicrosoft Sentinel
Workload or computeCompute units consumed by indexing, search, alertingLight search against heavy volume can cost lessSplunk on workload pricing
Ingest plus retentionGigabytes in, gigabytes kept per monthRetention becomes a permanent line itemElastic Security on Serverless
Allowance or credit basedDrawdown against a prepaid balancePredictable until the balance runs outGoogle SecOps

SIEM pricing compared: what each platform bills for in 2026

PlatformPrimary meterSecondary metersRetention billingWhat surprises buyers
Microsoft SentinelPer GB into the analytics tierLake ingestion, data processing, lake storage, query GB scanned, notebook compute hoursAnalytics retention beyond the default, then lake storage per GB per monthFive separate lake meters underneath one headline rate
SplunkPer GB indexed per day, or Splunk Virtual Compute unitsEnterprise Security license, premium apps, infrastructure on self-hostedSplunk Cloud includes 90 days, and longer adds an estimated 30 to 50 percentEnterprise Security is a separate license on top
Google SecOpsDrawdown against a prepaid GB credit balanceSecurity Tokens, Assured Workloads uplift, extended retention12 months hot retention included in all three packagesOverage bills in arrears, so you notice after the balance is gone
Elastic SecurityPer GB ingested on Serverless, or provisioned resources on HostedRetention per GB per month, support as a percentage of consumption, add-onsRetention meters monthly on Serverless, and via storage tiers on HostedMetering runs on uncompressed, enriched volume

Microsoft Sentinel bills across two tiers and five lake meters

Microsoft Sentinel splits security data into an analytics tier and a data lake tier. The analytics tier supports all log types with full detection, alerting, and query. The data lake tier holds high-volume data for investigation and compliance at a lower rate.

Commitment tiers cover the analytics tier. Microsoft publishes reserved capacity from 100 GB to 50,000 GB per day, with savings up to 52 percent against pay-as-you-go. You can raise a commitment at any time. Lowering it takes 31 days. Usage above your commitment bills at the same discounted rate. A 50 GB tier is in public preview. Sign-up runs to 31 December 2026, and promotional pricing holds to 31 March 2027.

The lake carries its own meters. Microsoft documents five. Ingestion per gigabyte. Data processing per gigabyte. Storage per gigabyte per month on a 6:1 compression ratio. Query charges per gigabyte of uncompressed data scanned. Advanced data insights per compute hour. These replace the archive, search, and auxiliary logs meters once a workspace is onboarded.

Two preview exemptions apply today. The lake includes 30 days of free storage, and data processing in the lake is free during preview.

Microsoft publishes no flat per-gigabyte figure, and rates vary by region. Use the Microsoft Sentinel pricing page and the Azure pricing calculator for your own region. Full breakdown in our Microsoft Sentinel pricing guide.

Splunk charges twice: once for the platform, once for the SIEM

Splunk offers two pricing models. Ingest pricing charges a rate per gigabyte indexed per day. Workload pricing charges for compute in units called Splunk Virtual Compute, or SVCs, consumed by indexing, searching, alerting, and dashboards.

Neither includes SIEM functionality. Splunk Enterprise Security adds correlation searches, threat intelligence, and risk-based alerting. It is licensed on top of the base platform. Independent estimates put the added cost at roughly 50 to 100 percent above base.

Splunk publishes no price list. One verified customer paid under $100,000 a year for 200 GB per day on ingest pricing. That works out close to $500 per gigabyte per day per year after enterprise discounting. Add Enterprise Security and the same volume lands between $150,000 and $200,000 a year.

One rule governs everything here. The ingest meter charges the moment a log line is indexed. Compression and tiered storage afterwards change nothing about what you already paid. Full breakdown in our Splunk SIEM pricing guide.

Google SecOps meters against a prepaid credit balance

Google SecOps, formerly Chronicle, sells three packages priced on ingestion volume: Standard, Enterprise, and Enterprise Plus. Company publishes no list price. Buying a package gives your account a prepaid credit balance measured in gigabytes.

Every gigabyte you send draws down that balance. Exceed it and you move into overage, billed monthly in arrears at your negotiated rate. All three packages include 12 months of hot retention, and data kept longer bills separately.

Three meters sit outside ingestion. Security Tokens cover the Agentic SOC features, with a daily complimentary allotment for Enterprise Plus and none for Enterprise. The Assured Workloads uplift adds a percentage to every Google Cloud service in a premium control workload. Extended retention bills on its own line.

The Data Benefit Program is worth planning around. It applies to contracts signed on or after 1 February 2026. Enterprise and Enterprise Plus subscriptions above a minimum annual contract value qualify. Specific Google-native sources are then exempted from the ingestion credit cap.

One real figure exists. A Forrester Total Economic Impact study commissioned by Google modeled a composite enterprise. The profile: $8 billion in revenue and 20,000 employees. Licensing came to $575,000 a year after a 15 percent risk adjustment. Google commissioned the study, and Forrester states it should not be read as competitive analysis. Full breakdown in our Google SecOps pricing guide.

Elastic Security meters the enriched payload, so billed volume runs higher

Elastic Security runs three ways. Cloud Serverless bills a per-gigabyte rate for ingest and a second rate for retention. Cloud Hosted bills the compute and storage you provision. Self-managed Elasticsearch is license-based, tied to node count and memory.

Serverless publishes real numbers. Security Analytics Essentials bills $0.09 per gigabyte ingested and $0.017 per gigabyte retained per month. The Complete tier bills $0.11 and $0.019.

One documented detail changes the math on all three models. Elastic meters ingest and retention on the uncompressed, normalized, fully enriched volume. Whatever your log shipper measures on the wire, Elastic bills a larger number after its own enrichment inflates it.

Support bills as a percentage of total consumption. Gold adds 5 percent, Platinum 10 percent, and Enterprise 15 percent.

Elastic’s pricing page states that per-endpoint fees stopped applying on 23 March 2026. Endpoint protection is now included in the tier rate. Full breakdown in our Elastic SIEM pricing guide.

Five levers lower the bill on any provider

Volume growth, retention past the included window, premium add-ons, and analyst time all push the same numbers up. Five levers push back.

Match the pricing model to your usage pattern. Heavy search against modest volume favors compute pricing. Stable volume with light search favors ingestion pricing. Revisit at renewal.

Size the commitment honestly. Reserved capacity discounts are real, and an oversized commitment locks the spend. Microsoft Sentinel enforces a 31-day minimum before you can reduce one.

Claim the free ingestion. Several sources ingest free or at reduced rates depending on your licensing. Connect those first, so paid capacity covers telemetry that needs it.

Tier retention to the actual obligation. Long-term data belongs in the cheapest searchable tier your platform offers. Default settings rarely match what compliance requires.

Reduce the data before it arrives. Filtering, deduplication, and field-level trimming shrink what every meter counts. Firewall, proxy, domain name system (DNS), NetFlow, and raw Windows event logs are the usual candidates. They generate high volume and drive few detections.

Deeper treatment of each lever sits in our guide to reducing SIEM costs.

What VirtualMetric DataStream does

The last lever is the one teams put off, because doing it by hand is real work. Someone writes the filter rules in each platform’s own syntax. Someone updates them when a detection changes. Someone rebuilds the whole set when a second SIEM arrives, because the rules do not transfer between platforms.

Moving that work off the SIEM and into a dedicated layer is what a security data pipeline is for. The pipeline sits between your log sources and your destinations. It collects telemetry, normalizes it, enriches it, filters it, and routes it. The rules live in one place, in one syntax, and adding a destination does not mean writing them again.

VirtualMetric DataStream is that layer. It decides what reaches each destination, and in what shape, before any meter counts it. Five capabilities carry that work:

  • Collection. Agentless-first ingestion from a wide range of sources, live in under 30 minutes. Agents are available where deeper visibility is needed.
  • Normalization. Native mapping to ASIM, Common Information Model, Elastic Common Schema, Unified Data Model, Open Cybersecurity Schema Framework, and CommonSecurityLog.
  • Reduction. Noisy events and unnecessary fields are filtered before ingestion, with detection-relevant data intact.
  • Enrichment. Identity, geo-location, device, and policy context are attached upstream.
  • Routing. Detection-relevant data goes to the SIEM. Full-volume data goes to low-cost storage such as Amazon S3 or Azure Blob.

Reduction raises an obvious question: who decides what counts as noise. DataStream Smart Engine answers it by reading the detection rules you already run. Events that no registered rule would ever match are held back from the SIEM. The rules already in use define the filter, so reduction tracks live detection coverage.

Together those capabilities let you keep the SIEM you run and pay less to feed it. Routing sends the full raw logs to low-cost storage, so nothing held back from the SIEM is lost. Analysts still retrieve the original record for forensics and audits.

Managed security service providers get the same benefit per tenant. One pipeline routes each client’s telemetry to whichever platform that client runs. See our MSSP page.

Ready to see the numbers on your own data? Calculate your savings or start a free trial.

Frequently asked questions

Is there a free SIEM, and is open source really free?

Free tiers exist and they are limited. Splunk Enterprise offers a free license capped at 500 MB indexed per day, without authentication, alerting, or clustering. Elastic’s Basic tier is free and open, and it omits machine learning anomaly detection and prebuilt detection rules. Open-source deployments move the cost into infrastructure and engineering time.

What are the main SIEM pricing models?

Five models cover the market in 2026. Ingestion-metered, multi-meter tiered, workload or compute, ingest plus retention, and allowance or credit based. Splunk offers ingestion and workload. Microsoft Sentinel is multi-meter tiered. Elastic Security bills ingest plus retention on Serverless. Google SecOps meters against a prepaid credit balance.

Does filtering telemetry before ingestion reduce detection coverage?

Filtering reduces coverage only when the wrong data is dropped. Reduction rules should key off what detections actually query, and full raw logs should stay retrievable in low-cost storage. Measure a rule before enforcing it. Keep the reduced and complete copies linked, so an analyst can reach the original.

What is replacing SIEM?

Nothing has replaced the category. Detection, investigation, and compliance reporting still run on a SIEM in most security operations centers (SOCs). What has changed is the layer in front of it. Teams increasingly separate the decision about what to collect from the decision about what to pay a SIEM to hold.

See VirtualMetric DataStream in action

layer_1

Start your free trial to experience safer, smarter data routing with full visibility and control.

Start free