Independent reference. Not affiliated with any vendor mentioned on this site.
Vendor / Datadog

Datadog Cloud SIEM pricing in 2026: per-host, per-GB, and the real total

The independent Datadog Cloud SIEM pricing reference. Per-host infrastructure base, per-GB log ingest, indexing tiers, Flex Logs, and the per-analyzed-event Cloud SIEM rate, with five real cost scenarios from startup to enterprise. Cloud SIEM pricing corrected to Datadog's per-million-analyzed-event model, July 2026.

Cloud SIEM
$5 / 1M events
Per million analyzed events, monthly
Logs (indexed)
$1.70 / Mevt
At 15-day retention
Infrastructure
$15 / host
Pro tier, monthly
EA discount
20-30%
Above ~$250K commit

List rates verified against the Datadog published price list, July 2026. Cloud SIEM meters per million analyzed events (annual rate shown). Negotiated discounts are commonplace above $250K committed annual spend.

How Datadog Cloud SIEM pricing actually works

Datadog packages Cloud SIEM as an add-on layered on top of Datadog Logs. That structural decision has the largest single effect on what your real bill becomes. Cloud SIEM meters on analyzed-event volume, listing at $5 per million analyzed events per month (annual billing) rather than a flat per-GB rate. The other line item that swallows budgets is the underlying Logs product, where indexed retention runs $1.70 per million events at 15 days and $2.50 per million events at 30. Most enterprise log mixes average roughly 6 to 10 million events per GB, which means a 50 GB-per-day environment moves on the order of 9 to 15 billion events per month, generating an indexed-log bill of $15K to $40K per month before any Cloud SIEM charge appears.

Datadog also charges separately for the host telemetry that originates many of those logs. Infrastructure Pro lists at $15 per host per month, Enterprise at $23. For a 200-host environment, that base alone is $36K to $55K per year before any log spend at all. Customers who arrived at Datadog through Application Performance Monitoring or Infrastructure Monitoring already absorb this cost; customers buying Datadog as a standalone SIEM see it as a Cloud SIEM line item even though it lives on a different product.

Because Cloud SIEM meters per analyzed event, its cost tracks how many events you route through detection, not how many gigabytes you ingest. That makes it highly sensitive to log source mix and to how selectively you send logs to Cloud SIEM: compact, high-frequency sources like firewall and NetFlow generate far more analyzed events per GB than verbose JSON cloud logs. Model this line on your own analyzed-event count using Datadog's pricing calculator rather than a per-GB rule of thumb. The broader point holds regardless: single-line-item rate comparisons against Splunk or Sentinel mislead, because Datadog's real bill is the sum of infrastructure hosts, per-GB and per-event Logs charges, and the analyzed-event Cloud SIEM line together.

Datadog launched Flex Logs in 2024 to address the indexing tax. Flex Logs combines ingestion ($0.05 per GB) with long-term storage ($0.0017 per GB per month) and removes the per-event indexing line. Queries against Flex Logs run in minutes rather than seconds and are not interactive, which suits compliance retention but not real-time investigation. Cloud SIEM detections work against Flex Logs data, so security signal generation continues even when you have moved 90-day-plus retention out of the indexed tier. For organisations where most logs are written once and read rarely, Flex Logs cuts the long-tail retention bill by roughly an order of magnitude.

Discounts are routine. Datadog's quarter-end pressure produces 20-30 percent off list at committed annual spend above $250K, and multi-year commitments push that towards 35 percent. List pricing is genuinely the worst price you should pay on any meaningful deployment.

Datadog SKU reference for Cloud SIEM deployments

SKUList rateWhat it actually buys
Infrastructure (Pro)$15 / host / monthRequired base for any Datadog deployment that originates host telemetry
Cloud SIEM$5 / 1M analyzed events / moLayered on top of Logs. Billed on analyzed-event volume (annual rate); pays for detection rules, signals, and threat intelligence
Logs (ingestion only)$0.10 / GBBase ingestion charge. Logs sit in Datadog but are not indexed or queryable yet
Logs (15-day retention)$1.70 / million eventsIndexed for fast search. The line item that actually surprises customers
Logs (30-day retention)$2.50 / million eventsIndexing scales linearly with retention
Flex Logs storage$0.05 / 1M events stored / moCheap long-term tier; ingestion stays $0.10/GB. Slower queries, no indexing, replaces archive workflows

Real-world Datadog Cloud SIEM cost scenarios

ScenarioProfileInfraLogsCloud SIEMTotal
Startup30 hosts, 8 GB/day logs, Cloud SIEM, 15-day retention$5,400/yr$8,500/yrEvent-metered$14K+/yr
Mid-market200 hosts, 50 GB/day logs, Cloud SIEM, 30-day retention$36K/yr$74K/yrEvent-metered$110K+/yr
Enterprise1,200 hosts, 250 GB/day logs, Cloud SIEM, 30-day retention$216K/yr$370K/yrEvent-metered$586K+/yr
Logs-only adopters0 hosts, 100 GB/day logs into Cloud SIEM, Flex Logs for 90+ days$0$15K/yr (Flex)Event-metered$15K+ Flex/yr
High-host / low-log800 hosts, 20 GB/day logs, Cloud SIEM, 15-day retention$144K/yr$22K/yrEvent-metered$166K+/yr

Totals show the infrastructure-plus-Logs base, triangulated from public list pricing and engineer write-ups sampled Q1 2026 and re-checked against Datadog's price list July 2026. Cloud SIEM is metered separately per million analyzed events ($5/million, annual) and is additive on top of the base; because analyzed-event volume varies widely with log source mix, model that line on your own routed-event count. Negotiated discounts of 20-30 percent are routine at $250K-plus committed spend.

Datadog Cloud SIEM vs Splunk and Sentinel at 50 GB per day

Same ingest, three vendors, all-in licence and platform spend. Excludes analyst staffing, professional services, and storage beyond standard tiers. The Datadog figure is the infrastructure-plus-Logs base; its per-million-analyzed-event Cloud SIEM line is additive and depends on routed-event volume.

Datadog Cloud SIEM
$110K+ base
200 hosts, 50 GB/day, 30-day indexed; plus event-metered Cloud SIEM
Splunk Cloud + ES
~$90K-$130K
~$50K Cloud base + $40K-$80K ES
Microsoft Sentinel
$59K-$78K
50 GB promo commit vs $4.30/GB PAYG

Sentinel wins on raw price at this size. Datadog wins where you already buy infrastructure monitoring and want to consolidate. Splunk wins where investigation depth and the ES content library are the binding constraint.

Five Datadog Cloud SIEM cost optimisations that genuinely work

Drop debug logs at the agent

30-50% on log spend

Datadog's agent supports include / exclude filters per source. Most teams ship debug-level traces by default. Filtering them at the agent before they hit the ingest API is the single highest-leverage move on the bill.

Move long-retention logs to Flex Logs

70-90% on storage tier

Indexed logs cost roughly $1.70 per million events at 15 days. Flex Logs replaces that: standard $0.10/GB ingestion plus $0.05 per million events stored per month, with no indexing charge. For compliance retention with rare query needs, Flex Logs is roughly an order of magnitude cheaper.

Sample APM and trace volume aggressively

20-40% on indexed spans

Datadog charges per indexed span as a separate line. Defaulting to head-based sampling at 5-10% on high-throughput services typically holds detection signal while cutting span spend by half or more.

Right-size Cloud SIEM detection rules

10-15% on Cloud SIEM

Cloud SIEM bills per million analyzed events, not per signal. Out-of-the-box rule packs scan everything; pruning packs that target log sources you do not ingest, and routing only security-relevant logs through detection, reduces analyzed-event volume without losing real coverage.

Negotiate EA at $250K-plus committed spend

20-30% list

Datadog's quarter-end list discount band sits at 20-30 percent for committed annual spend above roughly $250K. Multi-year commits push this towards 35 percent. The lever exists; ask for it.

When Datadog Cloud SIEM is the right SIEM

Datadog Cloud SIEM is unambiguously the right pick in three buyer profiles. First, organisations already on Datadog for application performance monitoring or infrastructure monitoring who want to consolidate security on the same data plane. The marginal cost of adding Cloud SIEM is genuinely small once the underlying Logs spend is sunk. Second, cloud-native engineering teams who value the API-first product and the one-vendor billing model over best-of-breed depth. Third, security teams whose detection content is built around application telemetry rather than network and endpoint correlation, where Datadog's APM and trace data is a real edge.

Datadog is the wrong pick for compliance-heavy regulated industries that need long-running investigations across 24-month data sets. The indexed-retention bill at that profile is brutal, and even Flex Logs has interactive-query limitations that workflow-heavy SOCs find frustrating. It is also wrong for environments where logs originate primarily from network appliances and endpoints rather than hosts: the per-host base inverts the unit-economics argument, and Sentinel or QRadar typically win cleanly.

Pricing model evolution worth watching: Datadog has been adding bundled Cloud SIEM allowances to enterprise contracts since late 2024. If your renewal comes up in 2026, push hard for a bundle that absorbs Cloud SIEM into committed Logs spend rather than billing it separately. The negotiation lever exists and is being used.

FAQ

Common questions

How much does Datadog Cloud SIEM cost in 2026?

Cloud SIEM lists at $5 per million analyzed events per month (annual billing) on top of standard Datadog log ingestion, so its cost depends on your analyzed-event volume rather than a flat per-GB rate. The larger story is the underlying Datadog spend: infrastructure hosts, per-GB log ingestion, and per-million-event indexed retention. For a 200-host, 50 GB-per-day deployment on 30-day indexed retention, the infrastructure and Logs base alone runs into six figures per year before discounts; the Cloud SIEM analyzed-event line sits on top of that and should be modeled on your own routed-event count. The surrounding Datadog spend, not the Cloud SIEM rate, is what you actually pay for.

Is Datadog Cloud SIEM cheaper than Splunk?

Comparing single line items understates Datadog's true bill, because Datadog charges separately for ingestion (per GB), indexing (per million events), and Cloud SIEM (per million analyzed events). At 50 GB per day with 30-day retention, Datadog's infrastructure and Logs base runs into six figures per year before the analyzed-event Cloud SIEM line, against Splunk Cloud at roughly $50K base ingest plus Enterprise Security (which roughly doubles it) for about $100K all-in. Datadog tends to win where you already pay for hosts and can consolidate; Splunk wins where SIEM is the only Datadog spend. Model the Cloud SIEM analyzed-event line into the Datadog side before concluding either way.

What is the difference between Datadog Logs and Datadog Cloud SIEM?

Logs is the data plane: ingest, index, search, archive, retain. Cloud SIEM sits on top: detection rules, signals, threat intelligence enrichment, security investigation workflow, and compliance content packs. You cannot run Cloud SIEM without paying for Logs underneath, and you can buy Logs without Cloud SIEM if you only need an audit trail without security tooling.

Does Datadog charge per host or per GB?

Both, on different products. Datadog Infrastructure bills per host (Pro at $15/host/month, Enterprise at $23). Datadog Logs bills per GB ingested plus per million events retained. Datadog Cloud SIEM bills per million analyzed events. The hybrid model is intentional: Datadog wants every product to scale with the customer dimension that drives its own cost. The complexity is real, and modelling spend before you sign matters more than for a single-meter vendor.

What is Flex Logs and when does it make sense for Cloud SIEM?

Flex Logs is Datadog's tier for long-term storage without indexing. Released in 2024, it lists at $0.05 per million events stored per month, on top of standard $0.10/GB ingestion (there is no separate per-GB storage rate). Queries are slower (minutes versus seconds) and not interactive. For compliance retention beyond 30 days where queries are rare, Flex Logs replaces archive workflows at roughly an order of magnitude lower cost than the standard indexing tier. Cloud SIEM works on Flex Logs, so security signal generation continues without the indexing tax.

Updated 13 July 2026