Datadog Cloud SIEM pricing in 2026: per-host, per-GB, and the real total
The independent Datadog Cloud SIEM pricing reference. Per-host infrastructure base, per-GB log ingest, indexing tiers, Flex Logs, and the per-analyzed-event Cloud SIEM rate, with five real cost scenarios from startup to enterprise. Cloud SIEM pricing corrected to Datadog's per-million-analyzed-event model, July 2026.
List rates verified against the Datadog published price list, July 2026. Cloud SIEM meters per million analyzed events (annual rate shown). Negotiated discounts are commonplace above $250K committed annual spend.
How Datadog Cloud SIEM pricing actually works
Datadog packages Cloud SIEM as an add-on layered on top of Datadog Logs. That structural decision has the largest single effect on what your real bill becomes. Cloud SIEM meters on analyzed-event volume, listing at $5 per million analyzed events per month (annual billing) rather than a flat per-GB rate. The other line item that swallows budgets is the underlying Logs product, where indexed retention runs $1.70 per million events at 15 days and $2.50 per million events at 30. Most enterprise log mixes average roughly 6 to 10 million events per GB, which means a 50 GB-per-day environment moves on the order of 9 to 15 billion events per month, generating an indexed-log bill of $15K to $40K per month before any Cloud SIEM charge appears.
Datadog also charges separately for the host telemetry that originates many of those logs. Infrastructure Pro lists at $15 per host per month, Enterprise at $23. For a 200-host environment, that base alone is $36K to $55K per year before any log spend at all. Customers who arrived at Datadog through Application Performance Monitoring or Infrastructure Monitoring already absorb this cost; customers buying Datadog as a standalone SIEM see it as a Cloud SIEM line item even though it lives on a different product.
Because Cloud SIEM meters per analyzed event, its cost tracks how many events you route through detection, not how many gigabytes you ingest. That makes it highly sensitive to log source mix and to how selectively you send logs to Cloud SIEM: compact, high-frequency sources like firewall and NetFlow generate far more analyzed events per GB than verbose JSON cloud logs. Model this line on your own analyzed-event count using Datadog's pricing calculator rather than a per-GB rule of thumb. The broader point holds regardless: single-line-item rate comparisons against Splunk or Sentinel mislead, because Datadog's real bill is the sum of infrastructure hosts, per-GB and per-event Logs charges, and the analyzed-event Cloud SIEM line together.
Datadog launched Flex Logs in 2024 to address the indexing tax. Flex Logs combines ingestion ($0.05 per GB) with long-term storage ($0.0017 per GB per month) and removes the per-event indexing line. Queries against Flex Logs run in minutes rather than seconds and are not interactive, which suits compliance retention but not real-time investigation. Cloud SIEM detections work against Flex Logs data, so security signal generation continues even when you have moved 90-day-plus retention out of the indexed tier. For organisations where most logs are written once and read rarely, Flex Logs cuts the long-tail retention bill by roughly an order of magnitude.
Discounts are routine. Datadog's quarter-end pressure produces 20-30 percent off list at committed annual spend above $250K, and multi-year commitments push that towards 35 percent. List pricing is genuinely the worst price you should pay on any meaningful deployment.
Datadog SKU reference for Cloud SIEM deployments
| SKU | List rate | What it actually buys |
|---|---|---|
| Infrastructure (Pro) | $15 / host / month | Required base for any Datadog deployment that originates host telemetry |
| Cloud SIEM | $5 / 1M analyzed events / mo | Layered on top of Logs. Billed on analyzed-event volume (annual rate); pays for detection rules, signals, and threat intelligence |
| Logs (ingestion only) | $0.10 / GB | Base ingestion charge. Logs sit in Datadog but are not indexed or queryable yet |
| Logs (15-day retention) | $1.70 / million events | Indexed for fast search. The line item that actually surprises customers |
| Logs (30-day retention) | $2.50 / million events | Indexing scales linearly with retention |
| Flex Logs storage | $0.05 / 1M events stored / mo | Cheap long-term tier; ingestion stays $0.10/GB. Slower queries, no indexing, replaces archive workflows |
Real-world Datadog Cloud SIEM cost scenarios
| Scenario | Profile | Infra | Logs | Cloud SIEM | Total |
|---|---|---|---|---|---|
| Startup | 30 hosts, 8 GB/day logs, Cloud SIEM, 15-day retention | $5,400/yr | $8,500/yr | Event-metered | $14K+/yr |
| Mid-market | 200 hosts, 50 GB/day logs, Cloud SIEM, 30-day retention | $36K/yr | $74K/yr | Event-metered | $110K+/yr |
| Enterprise | 1,200 hosts, 250 GB/day logs, Cloud SIEM, 30-day retention | $216K/yr | $370K/yr | Event-metered | $586K+/yr |
| Logs-only adopters | 0 hosts, 100 GB/day logs into Cloud SIEM, Flex Logs for 90+ days | $0 | $15K/yr (Flex) | Event-metered | $15K+ Flex/yr |
| High-host / low-log | 800 hosts, 20 GB/day logs, Cloud SIEM, 15-day retention | $144K/yr | $22K/yr | Event-metered | $166K+/yr |
Totals show the infrastructure-plus-Logs base, triangulated from public list pricing and engineer write-ups sampled Q1 2026 and re-checked against Datadog's price list July 2026. Cloud SIEM is metered separately per million analyzed events ($5/million, annual) and is additive on top of the base; because analyzed-event volume varies widely with log source mix, model that line on your own routed-event count. Negotiated discounts of 20-30 percent are routine at $250K-plus committed spend.
Datadog Cloud SIEM vs Splunk and Sentinel at 50 GB per day
Same ingest, three vendors, all-in licence and platform spend. Excludes analyst staffing, professional services, and storage beyond standard tiers. The Datadog figure is the infrastructure-plus-Logs base; its per-million-analyzed-event Cloud SIEM line is additive and depends on routed-event volume.
Sentinel wins on raw price at this size. Datadog wins where you already buy infrastructure monitoring and want to consolidate. Splunk wins where investigation depth and the ES content library are the binding constraint.
Five Datadog Cloud SIEM cost optimisations that genuinely work
Drop debug logs at the agent
30-50% on log spendDatadog's agent supports include / exclude filters per source. Most teams ship debug-level traces by default. Filtering them at the agent before they hit the ingest API is the single highest-leverage move on the bill.
Move long-retention logs to Flex Logs
70-90% on storage tierIndexed logs cost roughly $1.70 per million events at 15 days. Flex Logs replaces that: standard $0.10/GB ingestion plus $0.05 per million events stored per month, with no indexing charge. For compliance retention with rare query needs, Flex Logs is roughly an order of magnitude cheaper.
Sample APM and trace volume aggressively
20-40% on indexed spansDatadog charges per indexed span as a separate line. Defaulting to head-based sampling at 5-10% on high-throughput services typically holds detection signal while cutting span spend by half or more.
Right-size Cloud SIEM detection rules
10-15% on Cloud SIEMCloud SIEM bills per million analyzed events, not per signal. Out-of-the-box rule packs scan everything; pruning packs that target log sources you do not ingest, and routing only security-relevant logs through detection, reduces analyzed-event volume without losing real coverage.
Negotiate EA at $250K-plus committed spend
20-30% listDatadog's quarter-end list discount band sits at 20-30 percent for committed annual spend above roughly $250K. Multi-year commits push this towards 35 percent. The lever exists; ask for it.
When Datadog Cloud SIEM is the right SIEM
Datadog Cloud SIEM is unambiguously the right pick in three buyer profiles. First, organisations already on Datadog for application performance monitoring or infrastructure monitoring who want to consolidate security on the same data plane. The marginal cost of adding Cloud SIEM is genuinely small once the underlying Logs spend is sunk. Second, cloud-native engineering teams who value the API-first product and the one-vendor billing model over best-of-breed depth. Third, security teams whose detection content is built around application telemetry rather than network and endpoint correlation, where Datadog's APM and trace data is a real edge.
Datadog is the wrong pick for compliance-heavy regulated industries that need long-running investigations across 24-month data sets. The indexed-retention bill at that profile is brutal, and even Flex Logs has interactive-query limitations that workflow-heavy SOCs find frustrating. It is also wrong for environments where logs originate primarily from network appliances and endpoints rather than hosts: the per-host base inverts the unit-economics argument, and Sentinel or QRadar typically win cleanly.
Pricing model evolution worth watching: Datadog has been adding bundled Cloud SIEM allowances to enterprise contracts since late 2024. If your renewal comes up in 2026, push hard for a bundle that absorbs Cloud SIEM into committed Logs spend rather than billing it separately. The negotiation lever exists and is being used.