Independent reference. Not affiliated with any vendor mentioned on this site.
Compare / Sentinel vs Chronicle

Microsoft Sentinel vs Google Chronicle cost: 2026 comparison

Independent head-to-head cost comparison. Per-GB Sentinel versus Chronicle's GB data-cap pricing at five log-volume bands, five-year TCO model, and where Microsoft 365 free ingest and bundled Mandiant intelligence decide the winner. Chronicle pricing corrected to its GB data-cap basis; Sentinel rates verified against the Azure retail price list. Updated July 2026.

Sentinel
Per-GB
Plus free MS365 ingest
Chronicle
GB data cap
~£2,000/TB/yr (~$46K at 50 GB/day)
Both meter volume
Near parity
Close across all volume bands
Decider
MS365 vs Mandiant
Free ingest vs bundled intel

Per-GB versus GB data cap: how the meters collide

Sentinel and Chronicle both price on data volume, though through different mechanisms. Sentinel meters per gigabyte ingested with commitment-tier discounts, plus structural free ingest of Microsoft 365 and Azure native log sources. Chronicle (now Google SecOps) prices on a GB data cap sold in annual packages (Standard, Enterprise, Enterprise Plus), effectively about £2,000 per terabyte per year, which works out to roughly $46K at 50 GB per day. Chronicle is not metered per employee: the data-cap package is the meter, though Google sizes the bundled cap generously relative to a customer's seat count, which is why organisations with high log volume per employee find Chronicle cheap. Because both vendors ultimately track data volume, their costs land close together across most volume bands.

The old rule of thumb that a per-employee meter beats per-GB above some log-volume threshold no longer holds, because Chronicle's cost also rises with data volume. At 50 GB per day Chronicle is about $46K against Sentinel's $55K to $78K; at 200 GB per day Chronicle is about $184K against Sentinel's $200K; at 500 GB per day both sit near $460K. The gaps are small and driven by two real factors rather than by headcount: Sentinel's free Microsoft 365 ingest, and Chronicle's bundled Mandiant threat intelligence.

The first tie-breaker is Microsoft 365 share of total log volume. In Microsoft-heavy estates where 30 to 60 percent of ingest is Microsoft 365, Sentinel does not pay for that portion at all, which can pull Sentinel below Chronicle even where the raw volume comparison favours Chronicle. The second is the Mandiant bundle: Chronicle Enterprise includes Mandiant threat intelligence and Enterprise Plus adds Mandiant Hunt, capabilities that cost Sentinel customers a separate Mandiant Advantage subscription. The third is data-cap sizing: because Chronicle packages a fixed annual data cap, an organisation whose log volume runs high relative to its licensed cap extracts strong value, while an organisation that under-uses its cap overpays. The buying decision turns on these factors and on platform ecosystem, not on employee count.

Same environment, both vendors

ProfileSentinel (30% free share to PAYG)Chronicle data capWinnerNote
5 GB/day$6K-$8K$5K-$8KRoughly evenPackage minimums set Chronicle's floor at small scale
50 GB/day$55K-$78K~$46KChronicle narrowlySentinel MS365 free ingest can close or flip this
200 GB/day$200K~$184KRoughly evenBoth track volume; Mandiant bundle can tip Chronicle
500 GB/day$462K~$460KRoughly evenEffectively line-ball on data volume alone
1,000 GB/day$905K~$920KRoughly evenSentinel EA discounts and Chronicle package sizing set the real number

Annual ranges, before negotiated multi-year discounts. Sentinel ranges run from a 30 percent Microsoft 365 free-ingest share (low end) to zero free share at PAYG (high end). Chronicle figures convert the UK G-Cloud published price of about £2,000 per terabyte per year at roughly $1.26 per pound; that G-Cloud listing is the only published Chronicle price anywhere, and US pricing is quote-only, so treat the dollar figures as indicative rather than a US rate card.

Five-year TCO at 200 GB per day

YearSentinelChronicle data cap
Year 1 (200 GB/day)$200K$184K (Enterprise)
Year 2$196K$178K (renewal discount)
Year 3$200K (commit-tier hold)$184K
Year 4$210K$193K (5% inflation)
Year 5$221K$203K
5-year total$1.03M$942K

At 200 GB per day the two land within roughly 10 percent. Because Chronicle meters a GB data cap rather than headcount, the comparison tracks volume across the board; the tie-breakers are Microsoft 365 free ingest and Chronicle's bundled Mandiant intelligence. Excludes one-time migration costs.

When Sentinel genuinely wins

When Chronicle genuinely wins

FAQ

Common questions

Which is cheaper for a mid-market organisation, Sentinel or Chronicle?

It depends on log volume and Microsoft 365 share, not headcount. Chronicle meters a GB data cap (about £2,000 per terabyte per year), so its cost tracks volume just as Sentinel's does. At 50 GB per day Chronicle is about $46K against Sentinel's $55K to $78K, and with 30 percent Microsoft 365 free ingest Sentinel can fall to roughly $55K, making the two essentially even. At 200 GB per day Chronicle is about $184K and Sentinel about $200K, again close. The decision turns on Microsoft 365 share (which lowers Sentinel) and whether the Mandiant bundle in Chronicle Enterprise is valued, not on employee count.

Does Chronicle price per employee or per GB?

Chronicle (Google SecOps) prices on a GB data cap sold in annual packages (Standard, Enterprise, Enterprise Plus), roughly £2,000 per terabyte per year, not on a per-employee meter. Earlier Chronicle pricing was sometimes described as per-employee because Google sized the bundled data cap relative to a customer's seat count, but the billable meter is the data volume cap. The practical consequence is that Chronicle's cost rises with log volume much as Sentinel's does; the two do not diverge the way a genuine per-employee meter would. Google's data plane runs on internal infrastructure (Borg, BigQuery, Spanner) where storage and indexing are cheap at customer scale, which is why Chronicle can package generous data caps at competitive per-terabyte rates.

Does Microsoft 365 free ingest give Sentinel the edge?

Often, yes, in Microsoft-heavy estates. Sentinel ingests Microsoft 365 audit logs and Microsoft Defender alerts at no charge above the licence (raw Entra ID sign-in and audit logs are billed at standard rates). For organisations where Microsoft sources are 50 to 70 percent of total ingest, Sentinel's billable volume drops sharply and it can undercut Chronicle's data-cap price even where raw volume looks similar. At 60 GB per day of which 40 GB is Microsoft 365, Sentinel effectively pays for 20 GB (around $31K at PAYG) against Chronicle at roughly $55K for that 60 GB per day data cap. Chronicle's advantage appears where non-Microsoft log volume dominates (network appliances, SaaS and non-Azure cloud audit, EDR telemetry), which Sentinel bills at full per-GB rate.

How does Chronicle's bundled Mandiant intelligence factor into the comparison?

Chronicle Enterprise tier bundles Mandiant threat intelligence feed integration; Enterprise Plus tier bundles Mandiant Hunt managed threat hunting service. Sentinel customers needing equivalent capabilities license Mandiant Advantage as a separate Microsoft offering or Google Mandiant Advantage directly, typically adding $50K-$200K per year depending on coverage scope. For organisations where Mandiant capability is the binding requirement, Chronicle Enterprise's bundle is structurally cheaper than Sentinel plus Mandiant Advantage at most scale points.

What about migration cost from Sentinel to Chronicle?

Sentinel-to-Chronicle migration is moderately complex because the detection content models differ. Sentinel uses KQL (Kusto Query Language) for detections; Chronicle uses YARA-L 2.0. Migration of 100-200 detections runs $100K-$200K in professional services plus 4-6 months calendar time. For organisations where the Chronicle licence saving is $150K-plus per year, payback under 18 months makes migration a clear positive ROI. For organisations where the saving is smaller, the migration is rarely the right call without a separate consolidation or strategic driver. The reverse migration (Chronicle to Sentinel) is similarly complex and rarely the right call without strategic driver.

Updated 13 July 2026