Independent reference. Not affiliated with any vendor mentioned on this site.
Vendor / CrowdStrike

CrowdStrike Falcon LogScale (Humio) pricing in 2026: indexing-free per-GB

The independent Falcon LogScale pricing reference. The verified $5.95/GB PAYG rate, the 10 GB/day free third-party tier, indexing-free ingest model, retention economics, real cost scenarios, and an honest read on where LogScale actually wins versus Splunk. Updated July 2026.

Pricing model
Indexing-free per-GB
Ingest covers query
PAYG rate
$5.95 / GB
AWS Marketplace, 13-mo retention
100 GB/day
~$217K
Annual PAYG list
Free ingest
10 GB/day
Falcon Insight XDR customers

PAYG rate from the CrowdStrike Falcon Next-Gen SIEM AWS Marketplace listing ($0.00595/MB) and the free third-party ingest program, as of Q3 2026.

How Falcon LogScale pricing actually works

CrowdStrike Falcon LogScale (formerly Humio, acquired March 2021) prices on a per-GB ingested meter without the indexing surcharges that define Splunk Enterprise pricing. The architectural decision that produces this pricing model is the indexing-free design: LogScale's data plane uses an inverted-index-free schema-on-read approach that eliminates the index-build cost that Splunk amortises into its per-GB rate. The verified public anchor is the AWS Marketplace pay-as-you-go listing for Falcon Next-Gen SIEM at $0.00595 per MB, which is $5.95 per GB of third-party data. That single rate covers ingest, storage, and query with 13-month retention included, and Falcon-native telemetry is ingested at no additional charge. The indexing-free architecture means there is no separate indexing tier on top, but the per-GB rate itself is not cheap: at $5.95 per GB, log economics are driven almost entirely by how much third-party data you route in.

Retention default depends on the SKU. The 10 GB/day free third-party ingest tier for Falcon Insight XDR customers defaults to 7-day retention; the AWS Marketplace PAYG listing bundles 13-month retention; and retention is extendable to 36 months on committed contracts. Because retention is bundled into the ingest rate rather than billed as a separate per-GB-per-month archive tier, budget forecasting is simpler than the hot-warm-cold tiering that complicates Splunk Cloud, Datadog, and Sumo Logic comparisons. For compliance-driven customers, retention should be negotiated as part of the initial commit rather than added later: mid-term retention extensions land at list pricing.

The bundling with the broader Falcon platform is the second structural pricing dynamic. Falcon Next-Gen SIEM combines LogScale (data plane) with the existing Falcon Insight XDR (detection, response, investigation) and the Falcon agent (already deployed in any Falcon EDR customer environment). For existing Falcon EDR/XDR customers, the marginal cost of adding LogScale via Next-Gen SIEM is typically 20-30 percent below standalone LogScale plus standalone Falcon Insight, and the operational simplification (single agent, single console, single threat intelligence pipeline) is genuine.

The largest cost-discipline lever remains source-side filtering. LogScale's parser framework supports drop rules that prevent low-value events from counting against the per-GB meter at all. Aggressive use of drop rules on debug logs, routine NetFlow, verbose Windows event spam (Service Control Manager noise, routine logon successes), and similar low-fidelity sources typically removes 20-30 percent of metered ingest without affecting detection coverage. Customers who do not invest in source-side filtering pay for log volume that yields no security signal.

EA discounting at multi-year commits above $250K committed annual spend produces 25-30 percent off list as a routine outcome. Quarter-end pressure (particularly Q4 and end of CrowdStrike's fiscal year) carries the deepest discount band. Single-year transactional commits at scale leave value on the table; the discount math materially favours multi-year buyers.

The 2026 competitive position for LogScale is unusually strong. CrowdStrike's broader Falcon platform momentum is producing favourable bundling math against Splunk-plus-Microsoft-Defender or Sentinel-plus-Defender consolidation pitches, and the indexing-free per-GB rate is genuinely structural rather than promotional. For organisations evaluating Splunk consolidation in 2026, LogScale plus Falcon Next-Gen SIEM is the realistic alternative shortlist with Sentinel and Sumo Logic.

LogScale pricing by daily ingest band

Daily ingestProfileAnnual licence
10 GB/dayFree tier (Falcon Insight XDR)$0 (7-day retention)
25 GB/dayMid-market entry$43K-$54K/yr
100 GB/dayMid-market$174K-$217K/yr
500 GB/dayEnterprise$870K-$1.09M/yr
1,000 GB/dayLarge enterprise$1.74M-$2.17M/yr
5,000+ GB/dayGlobal enterpriseQuote-only, ~$8M-$11M/yr

Based on the $5.95/GB AWS Marketplace PAYG rate (13-month retention). Upper figure is PAYG list; lower figure reflects a typical committed multi-year discount off PAYG. Falcon-native telemetry is ingested at no charge; these bands count third-party data only.

Falcon LogScale SKU reference

SKUPricingNotes
Free third-party ingest10 GB/day at $0Included for Falcon Insight XDR customers with a dedicated CID; 7-day retention, premium correlation and SOAR features gated
Falcon Next-Gen SIEM (PAYG)$5.95 / GB ingestedAWS Marketplace pay-as-you-go for non-Falcon (third-party) data; 13-month retention included; Falcon-native data ingested at no charge
Falcon Next-Gen SIEM (committed)Volume/committed quoteAnnual and multi-year commits discount off the PAYG rate; retention extendable to 36 months
Falcon LogScale (log management)Per-GB, quote-basedStandalone indexing-free log platform without the full SIEM detection content set
Falcon Complete Next-Gen SIEMManaged, per-endpoint + ingestCo-managed SOC service layered on Next-Gen SIEM

Six Falcon LogScale cost optimisations that genuinely work

Use the indexing-free advantage

Architectural

LogScale's indexing-free architecture means you do not pay an indexing premium for data you might query later. Versus Splunk Enterprise where indexing is the line item that explodes, LogScale's per-GB rate covers ingest plus query without surcharge. The buying argument is structural, not promotional.

Bundle with existing Falcon platform

20-30% on combined

Existing CrowdStrike Falcon EDR/XDR customers buying LogScale standalone routinely leave bundle savings on the table. Falcon Next-Gen SIEM combines LogScale into the broader platform at 20-30 percent below standalone LogScale plus standalone Falcon Insight.

Start on the 10 GB/day free tier

Up to $22K/yr

Falcon Insight XDR customers get 10 GB/day of third-party ingest at no charge on a dedicated CID, capped at 7-day retention with premium correlation and SOAR features gated. For a security-signal-focused source mix that fits inside 10 GB/day, this covers the SIEM at zero ingest cost; 10 GB/day metered at the $5.95 PAYG rate would otherwise be roughly $22K/yr.

Negotiate retention as a buying axis

Variable

Default retention is 7 days on the free tier and 13 months on the AWS Marketplace PAYG listing, extendable to 36 months. Customers needing long retention should negotiate the retention period as part of the initial deal rather than upgrading mid-term, which lands at list pricing.

Use parsers to drop debug at ingest

20-30% on ingest

LogScale's parser framework supports drop rules that prevent low-value events from counting against the per-GB meter. Aggressive use of drop rules on debug logs, routine NetFlow, and verbose Windows event noise typically removes 20-30 percent of metered ingest.

Multi-year EA at $250K+ committed

25-30% list

LogScale enterprise EA discounting at multi-year commits above $250K committed annual spend produces 25-30 percent off list. Quarter-end is the credible negotiation pressure point. The deeper discount band requires multi-year; single-year commits at scale leave value on the table.

When Falcon LogScale is the right SIEM

LogScale wins for existing CrowdStrike Falcon EDR/XDR customers who are evaluating SIEM consolidation. The consolidation math is the real argument: single agent, single console, single threat-intelligence pipeline, and Falcon-native telemetry ingested at no ingest charge. The 10 GB/day free third-party tier lets a Falcon customer stand up a working SIEM at zero ingest cost for a signal-focused source mix. The indexing-free architecture also avoids the index-build cost embedded in Splunk's per-GB rate. What it does not do is undercut Splunk on the headline per-GB rate: at $5.95 per GB PAYG, high-volume third-party ingest is expensive. The case is consolidation and bundled 13-month retention, not a cheaper meter.

For high-volume log analytics, the honest framing is a trade rather than a straight saving. Organisations ingesting 500 GB-plus per day of third-party data pay well into seven figures at the PAYG rate, so the win is not automatic cost reduction; it is avoiding the index-build overhead embedded in Splunk's rate, folding in 13-month retention, and consolidating onto the Falcon agent already deployed. Committed multi-year contracts discount off PAYG, and aggressive source-side filtering matters more here than at any other volume band.

LogScale is the wrong pick for organisations whose detection content is built around Splunk Enterprise Security depth, where the content library and search performance are the binding constraints rather than raw log analytics cost. It is also wrong for Microsoft-heavy shops whose log mix is dominated by Microsoft 365 and Azure sources, where Sentinel's bundled Microsoft ingest is structurally cheaper. And it is wrong for organisations not on the Falcon platform whose marginal cost of evaluation includes the broader Falcon agent rollout, which is a meaningful operational lift even when the SIEM economics are favourable.

FAQ

Common questions

How is CrowdStrike Falcon LogScale priced in 2026?

Falcon LogScale (formerly Humio) prices per GB ingested without separate indexing surcharges. The public anchor is the AWS Marketplace pay-as-you-go listing for Falcon Next-Gen SIEM: $0.00595 per MB, which is $5.95 per GB of non-Falcon (third-party) data, with 13-month retention included and Falcon-native telemetry ingested at no ingest charge. A 100 GB-per-day third-party deployment lands at roughly $217K per year at that PAYG rate, before the discount that committed annual or multi-year contracts carry. Falcon Insight XDR customers also get 10 GB/day of third-party ingest free on a dedicated CID (7-day retention). The indexing-free architecture is the largest structural difference from Splunk Enterprise, whose per-GB rate amortises the index-build cost, but LogScale's per-GB rate itself is not low.

What is the difference between Humio and Falcon LogScale?

Falcon LogScale is CrowdStrike's rebrand of Humio, which CrowdStrike acquired in March 2021; the rename to Falcon LogScale followed in 2022 and the platform was integrated into Falcon from 2023 onward. The underlying technology is the same: an indexing-free log analytics platform with sub-second query performance across multi-petabyte data sets. The branding evolution reflects CrowdStrike's positioning of LogScale as the data plane for Falcon Next-Gen SIEM, the broader XDR consolidation play. Standalone LogScale (sold to customers not on the Falcon platform) remains available; bundled Falcon Next-Gen SIEM is the more common 2026 deal shape.

Is LogScale cheaper than Splunk?

Not on raw per-GB cost. At the $5.95 PAYG rate, 100 GB/day of third-party ingest is roughly $217K per year, which is comparable to or above a Splunk deployment at similar volume; Splunk Cloud at 50 GB/day runs around $50K base and roughly $100K all-in with Enterprise Security, and doubling to 100 GB/day lands in the same $200K-ish territory. The fair caveat in LogScale's favour is that its PAYG price bundles 13-month retention, where Splunk retention beyond the default is a separate cost, and the indexing-free architecture avoids the index-build overhead that Splunk's rate embeds. But the older claim that LogScale is dramatically cheaper does not hold at verified list prices. Where LogScale genuinely wins is consolidation for existing Falcon customers and bundled long retention, not a lower per-GB rate. LogScale loses ground where Splunk's content library (Enterprise Security, ITSI, premium content packs) is the binding constraint rather than raw log analytics.

What is Falcon Next-Gen SIEM?

Falcon Next-Gen SIEM is CrowdStrike's bundled SIEM offering that combines Falcon LogScale (data plane) with the broader Falcon platform's detection, response, and investigation capabilities. For existing Falcon EDR/XDR customers, Next-Gen SIEM is the natural consolidation play: same agent, same console, same threat intelligence, with LogScale providing the SIEM-grade log retention and search. The bundling typically produces meaningful savings versus standalone LogScale plus standalone Falcon Insight (CrowdStrike publishes no bundle rate; estimates run around 20-30 percent), and the operational simplification is genuine rather than marketing.

Does Falcon LogScale include UEBA?

LogScale includes basic UEBA via the Falcon platform's identity protection and behavioural analytics modules. The depth is moderate: comparable to Splunk Enterprise Security with the basic UEBA app or to Sentinel's built-in UEBA, but not matching Exabeam or Securonix specialist depth. For organisations whose detection content is built around Falcon's EDR signal as the primary input rather than UEBA-driven insider-threat detection, the LogScale UEBA capability is genuinely sufficient. For deep insider-threat or privileged-access-monitoring use cases, the specialist UEBA vendors maintain a depth advantage.

Updated 13 July 2026