Independent reference. Not affiliated with Splunk, Microsoft, IBM, Elastic, Sumo Logic, LogRhythm, or any SIEM vendor.
Vendor / Microsoft Sentinel

Microsoft Sentinel pricing in 2026: PAYG, commitment tiers, and real costs

Independent Sentinel pricing reference. Pay-as-you-go and commitment tier rates, free Microsoft 365 data sources, Basic Logs and archive pricing, and head-to-head comparisons against Splunk Cloud at every common volume. Updated April 2026.

PAYG rate
$5.22/GB
Standard log analytics ingest
Best commit tier
$2.79/GB
5,000 GB/day, 47% off PAYG
Basic Logs
$1.64/GB
Plus $0.013/GB search
Archive tier
$0.02/GB/mo
Long-term retention

Commitment tier pricing in full

Microsoft publishes commitment tiers from 100 GB per day up to 5,000 GB per day. The savings compound: every step up reduces the effective per-GB rate. The break- even from PAYG to a 100 GB commit is roughly 65 GB per day of consistent ingest.

Commitment tierDaily costEffective rateSaving vs PAYG
Pay-as-you-go-$5.22/GB0%
100 GB/day$343/day$3.43/GB34%
200 GB/day$662/day$3.31/GB37%
300 GB/day$971/day$3.24/GB38%
400 GB/day$1,272/day$3.18/GB39%
500 GB/day$1,575/day$3.15/GB40%
1,000 GB/day$3,055/day$3.06/GB41%
5,000 GB/day$13,955/day$2.79/GB47%

The free data sources that change the maths

Sentinel ingests certain Microsoft data sources free, regardless of commitment tier. For Microsoft 365 organisations on E5 licensing, free ingest can account for 30-50 percent of total log volume.

Microsoft 365 audit logs
With E5/A5/G5; otherwise paid
Azure Activity Logs
Free across all subscriptions
Office Activity logs
Free with E5 or G5
Microsoft Defender for Cloud alerts
Free across tiers
Microsoft Defender XDR alerts
Free with Defender XDR
Azure AD sign-in / audit logs
First 10 GB/day free per workspace

Third-party log sources (firewalls, SaaS apps, custom apps) always count towards paid ingest. Custom transform rules at the data collection rule (DCR) layer let you drop unwanted fields before billing.

Sentinel cost scenarios

ScenarioProfileLicenceTotal TCONotes
Startup5 GB/day, PAYG, 90-day retention$9.5K/yr$22K-$35KFree 31-day trial covers initial deployment
Mid-market50 GB/day, PAYG, 365-day retention$95K/yr$240K-$340KBelow 100 GB tier; PAYG remains cheapest
Enterprise200 GB/day, 200 GB commit, 365-day retention$242K/yr$680K-$1.0MCommitment tier locks 37 percent savings
Microsoft-first enterprise500 GB/day inclusive of free M365 logs~$140K/yr effective$420K-$580KFree M365 data drives effective rate well below PAYG
Large enterprise1 TB/day, 1,000 GB commit, 365-day retention$1.12M/yr$2.6M-$3.4MMicrosoft Copilot for Security adds 15-25 percent

Sentinel cost optimisation

Use Basic Logs for high-volume sources

Network firewall logs, NetFlow, and IIS logs ingest at $1.64 per GB instead of $5.22. Detection rules cannot fire from Basic Logs, so keep primary security telemetry in standard tier.

Apply DCR transformations early

Data Collection Rule transforms strip unused fields before they hit the billing meter. Cutting 20-30 percent of bytes per record is normal.

Right-size your commitment tier

Move up tiers as volume grows. Move down at term renewal if it dropped. Microsoft true-ups quarterly, not catastrophically.

Archive after 90 days

Sentinel archive tier costs $0.02 per GB per month. For 365-day retention with 90-day hot, archive saves 80-90 percent on long-tail storage.

Watch UEBA and Notebooks add-ons

Microsoft Sentinel UEBA and the Notebooks integration pull from the same workspace data and have their own consumption metrics.

Microsoft Copilot for Security

SCU-based pricing. Powerful, but easy to overspend on. Cap SCUs at the workspace level and review monthly.

FAQ

Common questions

Is Microsoft Sentinel free?

Sentinel is not free as a platform but ships with substantial free data sources for organisations on Microsoft licensing. Microsoft 365 audit logs ingest free with E5, A5, or G5 licences. Azure Activity Logs are free everywhere. Defender for Cloud and Defender XDR alerts are free. The first 10 GB per day of Azure AD sign-in and audit logs is free per workspace. For Microsoft-heavy environments, the effective per-GB rate often runs 40-60 percent lower than the headline $5.22 because so much primary data ingests free.

How much does Microsoft Sentinel cost per GB in 2026?

Pay-as-you-go is $5.22 per GB ingested. Commitment tiers reduce that progressively: 100 GB per day costs $3.43 effective per GB (34 percent saving), 500 GB per day reaches $3.15 (40 percent saving), and 5,000 GB per day reaches $2.79 (47 percent saving). Below 100 GB per day, PAYG is cheapest. Above 100 GB, the 100 GB tier almost always pays back. Switching tiers takes effect immediately and back-bills the differential.

What is Sentinel Basic Logs and when should I use it?

Basic Logs is a cheaper ingest tier ($1.64/GB) for high-volume sources where full-text search is not required. Searches against Basic Logs cost $0.013 per GB scanned. The model fits sources like network firewall logs, NetFlow, and IIS logs where volume is high and the value is mostly in archival or specific-query retrieval. Detection rules and Analytics rules cannot run against Basic Logs, so primary security telemetry stays in the standard tier.

How does Sentinel pricing compare to Splunk?

At 50 GB per day, Sentinel PAYG runs roughly $95K per year on licensing alone, against Splunk Cloud at approximately $135K for the equivalent. At 200 GB per day with commitment tiers, Sentinel sits around $242K against Splunk Cloud at $400K-plus. Sentinel's free Microsoft data widens the gap further for Microsoft 365 environments. Splunk wins on analyst experience and search depth; Sentinel wins on TCO for most mid-market and enterprise Microsoft-shop deployments.

Is Sentinel a true SIEM or just log analytics?

Sentinel is genuinely a SIEM. Built on Log Analytics workspaces, it adds Analytics rules, Workbooks, Hunting queries, Threat Intelligence integration, UEBA, automation playbooks via Logic Apps, and SOAR via Microsoft Sentinel Notebooks. The trade-off versus Splunk Enterprise Security is fewer pre-built risk-based detection content packs (though Microsoft and the community have closed much of the gap by 2026) and a steeper learning curve for KQL versus SPL.

Updated 2 May 2026