CrowdStrike Falcon LogScale (Humio) pricing in 2026: indexing-free per-GB
The independent Falcon LogScale pricing reference. The verified $5.95/GB PAYG rate, the 10 GB/day free third-party tier, indexing-free ingest model, retention economics, real cost scenarios, and an honest read on where LogScale actually wins versus Splunk. Updated July 2026.
PAYG rate from the CrowdStrike Falcon Next-Gen SIEM AWS Marketplace listing ($0.00595/MB) and the free third-party ingest program, as of Q3 2026.
How Falcon LogScale pricing actually works
CrowdStrike Falcon LogScale (formerly Humio, acquired March 2021) prices on a per-GB ingested meter without the indexing surcharges that define Splunk Enterprise pricing. The architectural decision that produces this pricing model is the indexing-free design: LogScale's data plane uses an inverted-index-free schema-on-read approach that eliminates the index-build cost that Splunk amortises into its per-GB rate. The verified public anchor is the AWS Marketplace pay-as-you-go listing for Falcon Next-Gen SIEM at $0.00595 per MB, which is $5.95 per GB of third-party data. That single rate covers ingest, storage, and query with 13-month retention included, and Falcon-native telemetry is ingested at no additional charge. The indexing-free architecture means there is no separate indexing tier on top, but the per-GB rate itself is not cheap: at $5.95 per GB, log economics are driven almost entirely by how much third-party data you route in.
Retention default depends on the SKU. The 10 GB/day free third-party ingest tier for Falcon Insight XDR customers defaults to 7-day retention; the AWS Marketplace PAYG listing bundles 13-month retention; and retention is extendable to 36 months on committed contracts. Because retention is bundled into the ingest rate rather than billed as a separate per-GB-per-month archive tier, budget forecasting is simpler than the hot-warm-cold tiering that complicates Splunk Cloud, Datadog, and Sumo Logic comparisons. For compliance-driven customers, retention should be negotiated as part of the initial commit rather than added later: mid-term retention extensions land at list pricing.
The bundling with the broader Falcon platform is the second structural pricing dynamic. Falcon Next-Gen SIEM combines LogScale (data plane) with the existing Falcon Insight XDR (detection, response, investigation) and the Falcon agent (already deployed in any Falcon EDR customer environment). For existing Falcon EDR/XDR customers, the marginal cost of adding LogScale via Next-Gen SIEM is typically 20-30 percent below standalone LogScale plus standalone Falcon Insight, and the operational simplification (single agent, single console, single threat intelligence pipeline) is genuine.
The largest cost-discipline lever remains source-side filtering. LogScale's parser framework supports drop rules that prevent low-value events from counting against the per-GB meter at all. Aggressive use of drop rules on debug logs, routine NetFlow, verbose Windows event spam (Service Control Manager noise, routine logon successes), and similar low-fidelity sources typically removes 20-30 percent of metered ingest without affecting detection coverage. Customers who do not invest in source-side filtering pay for log volume that yields no security signal.
EA discounting at multi-year commits above $250K committed annual spend produces 25-30 percent off list as a routine outcome. Quarter-end pressure (particularly Q4 and end of CrowdStrike's fiscal year) carries the deepest discount band. Single-year transactional commits at scale leave value on the table; the discount math materially favours multi-year buyers.
The 2026 competitive position for LogScale is unusually strong. CrowdStrike's broader Falcon platform momentum is producing favourable bundling math against Splunk-plus-Microsoft-Defender or Sentinel-plus-Defender consolidation pitches, and the indexing-free per-GB rate is genuinely structural rather than promotional. For organisations evaluating Splunk consolidation in 2026, LogScale plus Falcon Next-Gen SIEM is the realistic alternative shortlist with Sentinel and Sumo Logic.
LogScale pricing by daily ingest band
| Daily ingest | Profile | Annual licence |
|---|---|---|
| 10 GB/day | Free tier (Falcon Insight XDR) | $0 (7-day retention) |
| 25 GB/day | Mid-market entry | $43K-$54K/yr |
| 100 GB/day | Mid-market | $174K-$217K/yr |
| 500 GB/day | Enterprise | $870K-$1.09M/yr |
| 1,000 GB/day | Large enterprise | $1.74M-$2.17M/yr |
| 5,000+ GB/day | Global enterprise | Quote-only, ~$8M-$11M/yr |
Based on the $5.95/GB AWS Marketplace PAYG rate (13-month retention). Upper figure is PAYG list; lower figure reflects a typical committed multi-year discount off PAYG. Falcon-native telemetry is ingested at no charge; these bands count third-party data only.
Falcon LogScale SKU reference
| SKU | Pricing | Notes |
|---|---|---|
| Free third-party ingest | 10 GB/day at $0 | Included for Falcon Insight XDR customers with a dedicated CID; 7-day retention, premium correlation and SOAR features gated |
| Falcon Next-Gen SIEM (PAYG) | $5.95 / GB ingested | AWS Marketplace pay-as-you-go for non-Falcon (third-party) data; 13-month retention included; Falcon-native data ingested at no charge |
| Falcon Next-Gen SIEM (committed) | Volume/committed quote | Annual and multi-year commits discount off the PAYG rate; retention extendable to 36 months |
| Falcon LogScale (log management) | Per-GB, quote-based | Standalone indexing-free log platform without the full SIEM detection content set |
| Falcon Complete Next-Gen SIEM | Managed, per-endpoint + ingest | Co-managed SOC service layered on Next-Gen SIEM |
Six Falcon LogScale cost optimisations that genuinely work
Use the indexing-free advantage
ArchitecturalLogScale's indexing-free architecture means you do not pay an indexing premium for data you might query later. Versus Splunk Enterprise where indexing is the line item that explodes, LogScale's per-GB rate covers ingest plus query without surcharge. The buying argument is structural, not promotional.
Bundle with existing Falcon platform
20-30% on combinedExisting CrowdStrike Falcon EDR/XDR customers buying LogScale standalone routinely leave bundle savings on the table. Falcon Next-Gen SIEM combines LogScale into the broader platform at 20-30 percent below standalone LogScale plus standalone Falcon Insight.
Start on the 10 GB/day free tier
Up to $22K/yrFalcon Insight XDR customers get 10 GB/day of third-party ingest at no charge on a dedicated CID, capped at 7-day retention with premium correlation and SOAR features gated. For a security-signal-focused source mix that fits inside 10 GB/day, this covers the SIEM at zero ingest cost; 10 GB/day metered at the $5.95 PAYG rate would otherwise be roughly $22K/yr.
Negotiate retention as a buying axis
VariableDefault retention is 7 days on the free tier and 13 months on the AWS Marketplace PAYG listing, extendable to 36 months. Customers needing long retention should negotiate the retention period as part of the initial deal rather than upgrading mid-term, which lands at list pricing.
Use parsers to drop debug at ingest
20-30% on ingestLogScale's parser framework supports drop rules that prevent low-value events from counting against the per-GB meter. Aggressive use of drop rules on debug logs, routine NetFlow, and verbose Windows event noise typically removes 20-30 percent of metered ingest.
Multi-year EA at $250K+ committed
25-30% listLogScale enterprise EA discounting at multi-year commits above $250K committed annual spend produces 25-30 percent off list. Quarter-end is the credible negotiation pressure point. The deeper discount band requires multi-year; single-year commits at scale leave value on the table.
When Falcon LogScale is the right SIEM
LogScale wins for existing CrowdStrike Falcon EDR/XDR customers who are evaluating SIEM consolidation. The consolidation math is the real argument: single agent, single console, single threat-intelligence pipeline, and Falcon-native telemetry ingested at no ingest charge. The 10 GB/day free third-party tier lets a Falcon customer stand up a working SIEM at zero ingest cost for a signal-focused source mix. The indexing-free architecture also avoids the index-build cost embedded in Splunk's per-GB rate. What it does not do is undercut Splunk on the headline per-GB rate: at $5.95 per GB PAYG, high-volume third-party ingest is expensive. The case is consolidation and bundled 13-month retention, not a cheaper meter.
For high-volume log analytics, the honest framing is a trade rather than a straight saving. Organisations ingesting 500 GB-plus per day of third-party data pay well into seven figures at the PAYG rate, so the win is not automatic cost reduction; it is avoiding the index-build overhead embedded in Splunk's rate, folding in 13-month retention, and consolidating onto the Falcon agent already deployed. Committed multi-year contracts discount off PAYG, and aggressive source-side filtering matters more here than at any other volume band.
LogScale is the wrong pick for organisations whose detection content is built around Splunk Enterprise Security depth, where the content library and search performance are the binding constraints rather than raw log analytics cost. It is also wrong for Microsoft-heavy shops whose log mix is dominated by Microsoft 365 and Azure sources, where Sentinel's bundled Microsoft ingest is structurally cheaper. And it is wrong for organisations not on the Falcon platform whose marginal cost of evaluation includes the broader Falcon agent rollout, which is a meaningful operational lift even when the SIEM economics are favourable.