SIEM pricing models: per-GB vs per-EPS vs per-employee vs flat-rate
The four billing structures every SIEM uses, the trade-offs of each, the vendors behind each, and a side-by-side comparison of the same environment priced under all four. Worked examples, no hand-waving.
Model comparison matrix
| Model | Vendors | Best for | Worst for | Predictability |
|---|---|---|---|---|
| Per GB ingested | Splunk, Sentinel, Datadog | High-value, low-volume telemetry | Verbose firewall and NetFlow | Low (volatile with noise) |
| Per EPS | QRadar, ArcSight | Quiet, predictable sources | Spiky bursts that breach peak | Medium (peak governs) |
| Per employee / seat | Blumira | Small headcount, SMB | Large headcount, high log volume | High (linear with headcount) |
| Flat-rate / volume tiers | Panther | Predictable budgets, SMB | Volume crossing tier ceilings | High within tier; cliffs between |
Per-GB ingested
The dominant SIEM pricing model in 2026. The vendor meters every log byte that crosses the ingest boundary. Compression at rest does not reduce the bill. Splunk, Sentinel, Datadog, and most newer cloud SIEMs use this model.
Wins when security data is high-value (authentication logs, EDR alerts, threat detections) and low volume. Per-GB lines up cost with detection value.
Loses when verbose, low-value sources dominate. Firewall syslog, NetFlow, and DNS query logs can quickly consume 80 percent of GB billing while contributing 10 percent of detection value.
Worked example. 50 GB per day at $4.30/GB Sentinel PAYG = $78,475 per year. Filter 30 percent of low-value logs at the agent and the same environment costs $54,933. Filtering pays back faster than negotiation.
Per-EPS (events per second)
QRadar and ArcSight bill on event rate, not data volume. The metric is sustained events per second across all log sources, with a separate peak ceiling. EPS billing flatters quiet sources and penalises spiky ones.
Wins when log sources are predictable and balanced. Compliance environments with steady audit logging benefit.
Loses when bursty sources push the peak EPS ceiling. Web traffic spikes, batch jobs, or attack waves can force a tier upgrade based on bursts that don't reflect sustained value.
Worked example. 50 GB per day with mixed sources averages roughly 3,500 EPS sustained. QRadar on Cloud at this tier is an estimated $110K-$140K per year on licence (IBM publishes no list price). Equivalent per-GB billing runs roughly $60K-$100K depending on vendor: about $59K-$78K on Sentinel, and roughly $100K all-in on Splunk Cloud with Enterprise Security.
Per employee / per seat
A per-employee meter sizes the subscription by headcount rather than log volume. Blumira is the clearest 2026 example, billing from $12 per employee per month (Detect) up to $21 (Automate), so the invoice tracks seats and stays flat regardless of how much you ingest. Google SecOps (Chronicle) is often filed here by mistake: earlier Chronicle deals were sized relative to seat count, but its contractual meter is a GB data cap, so it belongs with the volume-priced vendors.
Wins when headcount is small and log volume is unpredictable: because the bill tracks seats rather than bytes, a noisy month costs nothing extra, which suits SMBs with lean teams and verbose telemetry.
Loses when headcount is large relative to log volume, because you pay per seat for log infrastructure a per-GB meter would bill far less for.
Worked example. 300 employees on Blumira Automate at $21 per employee per month is about $75,600 per year, flat whether you ingest 5 GB or 50 GB per day. Contrast Google SecOps, once the canonical per-employee example but now metered on a GB data cap (about £2,000 per terabyte per year on the only published listing): a firm ingesting 200 GB per day pays Chronicle roughly £146K on that rate, a bill that moves with data, not headcount. The meter you are on decides whether seats or data growth drive the invoice.
Flat-rate tiers
Panther sells tiered subscriptions: a fixed monthly fee covers a defined ingest ceiling, log retention period, and feature set. Cross the ceiling and you either upgrade tier or pay overage rates. Sumo Logic used to fit here too but has moved to its Flex credit model.
Wins when volume is predictable and growth is slow. The bill is genuinely flat for budgeting.
Loses when volume crosses the ceiling. Overage rates are typically 1.5-2x the in-tier per-GB equivalent. Tier upgrades create cliffs.
Worked example. Sumo Logic now sells Flex, which bills on data scanned and stored rather than ingest (ingest itself is free), so there is no clean per-GB-per-day headline and a 50 GB-per-day cost swings widely with query volume. Panther still sells true fixed volume tiers where the bill genuinely flattens inside the ceiling. For comparison, Splunk Cloud plus Enterprise Security at 50 GB per day runs roughly $100K all-in, and a fitting flat tier can sit noticeably lower. The discipline is monitoring usage against the ceiling before overage rates bite.
Same environment, four pricing models
Annual licensing only (no staffing or storage). Same log volume; different billing structure.
| Model and vendor | Small (10 GB/day) | Mid (50 GB/day) | Enterprise (200 GB/day) |
|---|---|---|---|
| Per GB (Splunk Cloud + ES, all-in) | $25K | $100K | $340K |
| Per GB (Sentinel) | $16K | $59K-$78K | $200K |
| Per EPS (QRadar Cloud, est.) | $28K | $110K-$140K | $440K-$560K |
| Resource-based (Elastic Platinum) | $25K | $95K | $320K |
| Credit-based (Sumo Logic Flex, est.) | $22K | $80K | $280K |
Comparison assumes mixed log source profile, 365-day retention, and no negotiated discount. Splunk figures are all-in (base ingest plus Enterprise Security, which roughly doubles the base; mid-tier base ingest alone is ~$50K). QRadar publishes no list price, so those cells are modelled estimates. Sumo Logic Flex bills on data scanned and stored rather than ingest, so its figures are rough scan-dependent estimates, not a per-GB headline. Real-world deals routinely vary 20-40 percent either direction.