Independent reference. Not affiliated with any vendor mentioned on this site.
Reference / Normalised

SIEM cost per GB in 2026: every major vendor compared

Independent normalised cost-per-GB comparison across all twelve major SIEM vendors. Headline list rates, all-in math at 50 GB per day, and the honest cheapest-at-this-profile ranking. Updated July 2026.

Cheapest all-in
$36K-$55K
Exabeam SIEM, Devo, Chronicle
Splunk all-in
$50K-$100K
Base ingest to ES included
Highest priced
$109K-$140K
CrowdStrike LogScale, QRadar (est.)
Not per-GB
Sumo, Datadog
Credit / multi-line meters

Why a cost-per-GB comparison matters

Headline per-GB rates are the single most-cited number in SIEM evaluations and one of the most misleading. List rates from vendor pricing pages frequently bear little resemblance to actual paid prices, particularly at meaningful scale where multi-year EA discounts of 25 to 40 percent are routine. Per-GB rates also miss the structural cost dimensions that dominate real bills: separate licensing for SIEM analytics on top of base log retention (Splunk Enterprise Security, Datadog Cloud SIEM), bundled features that change effective per-GB economics (Microsoft 365 free ingest on Sentinel, included long retention on Devo), and meter-axis differences that require conversion (per-EPS QRadar, per-MPS LogRhythm, per-GB-day Securonix, data-cap Chronicle).

The honest comparison treats per-GB rate as a starting point and adjusts for the structural factors that materially change effective cost. Microsoft 365 share matters for Sentinel; existing Datadog spend matters for Datadog Cloud SIEM; existing Falcon platform spend matters for LogScale; the data-cap tier matters for Chronicle; retention requirement matters for Devo and Sumo Logic. The table below shows the headline per-GB list where one exists, the all-in math at 50 GB per day for a typical mid-market profile, and a brief note on what changes the effective rate for that vendor.

Two vendors price on an event-rate axis and are shown as estimates: IBM QRadar (per-EPS) and LogRhythm (per-MPS, self-hosted). IBM publishes no list price, so the QRadar figure is a typical-mix estimate at roughly 3,500 EPS, which maps to about 50 GB per day. Securonix EON prices per GB per day across tiers with no published list, and Google Chronicle uses a data-cap and credit model at roughly £2,000 per TB per year rather than a per-employee meter. Sumo Logic (Flex credits) and Datadog Cloud SIEM (multi-line) have no single per-GB headline and are shown as such rather than forced into a per-GB number.

All twelve vendors, normalised to per-GB equivalents where a rate exists

VendorPricing modelList $/GB/yrAll-in @ 50 GB/dayNote
ExabeamPer GB/day$720-$1,020$36K SIEM / $51K FusionGB/day pricing; the SIEM tier lands lowest at 50 GB/day
DevoDaily ingest tier$900-$1,100$45K-$55K400-day hot retention bundled; ~$90K at 100 GB/day
Google ChronicleGB data-cap / credit$920 (~£2,000/TB/yr)~$46KData-cap / credit model, not per-employee
Splunk CloudPer-GB ingested$665-$1,620$50K base / $100K + ESES roughly doubles base ingest; base sits near the low end at 50 GB/day
Microsoft SentinelPer-GB commit tier or PAYG$1,180-$1,560$59K-$78KCommitment vs PAYG ($4.30/GB East US); free MS365 ingest tilts lower
PantherPer-TB ingest$1,500-$1,800$75K-$90K$50K per TB per month; detection-as-code
CrowdStrike LogScalePer-GB PAYG$2,170 (from $5.95/GB)~$109K7-day default retention; higher than Splunk all-in at 50 GB/day
IBM QRadarPer-EPS (~3,500 EPS at 50 GB/day)$2,200-$2,800 equiv (est.)$110K-$140K (est.)IBM publishes no list price; estimate at typical mix
LogRhythmPer-MPS self-hosted~$65/MPS/yr (est.)MPS-based (est.)Self-hosted; Axon retired; priced per message per second, not per GB
Sumo Logic Cloud SIEMFlex credits (not per-GB)Not per-GBCredit-meteredFlex model: free ingest, credits on scan + storage (~$1.50/credit); no clean per-GB headline
Datadog Cloud SIEMMulti-line meterNot per-GBMulti-lineIngest $0.10/GB; indexing $1.70-$2.50 per 1M events; Cloud SIEM $5 per 1M analyzed events
Securonix EONGB/day tiersNo published listTiered (unpublished)Priced per GB/day, not EPS; tiers BASIC / STANDARD / ADVANCED / ALL-IN

List $/GB/yr ranges based on published vendor pricing pages, partner channel references, and customer write-ups in mid-2026, primary-sourced this quarter. All-in column at 50 GB per day represents a typical mid-market deployment; retention and add-on analytics change it materially. Figures marked estimate are converted from a non-per-GB meter and flagged as such. Negotiated multi-year EA discounts of 25 to 40 percent are routine at meaningful scale.

The honest cheapest-at-this-profile ranking

For a typical 50 GB per day, mid-market deployment with a moderate Microsoft footprint:

#1 Exabeam (SIEM tier)

GB/day pricing; the SIEM tier lands lowest at ~$36K at 50 GB per day

#2 Devo

Daily-ingest at ~$45K-$55K with 400-day hot retention bundled

#3 Google Chronicle

Data-cap / credit model at ~£2,000 per TB per year lands near ~$46K at 50 GB per day

#4 Splunk Cloud (base ingest)

Base ingest ~$50K sits near the low end; Enterprise Security roughly doubles it

#5 Microsoft Sentinel (commitment tier)

~$59K on commitment; free MS365 ingest tilts effective cost lower

What this ranking does not show

Cost-per-GB is one buying axis among several. The cheapest vendor at the per-GB rate is rarely the cheapest vendor on total spend, and is often not the right vendor for buying decisions where detection content depth, SOC familiarity, compliance content packs, or broader IT consolidation strategy matters more than raw licence cost. CrowdStrike LogScale at ~$109K (its $5.95 per GB pay-as-you-go rate) is not the cheapest option, but it is the right shape for organisations already on Falcon EDR/XDR where the bundle math changes; note its 7-day default retention. For organisations not on Falcon, the broader agent rollout cost makes the comparison less favourable than the raw per-GB number suggests.

Microsoft Sentinel at the cheapest effective rate (factoring free MS365 ingest) is the right shape for Microsoft-heavy environments; for organisations whose log mix is dominated by non-Microsoft sources, the per-GB rate is closer to the headline list and the comparison flips. Google Chronicle on its data-cap and credit model (~£2,000 per TB per year, ~$46K at 50 GB per day) is competitive for steady-volume environments; because the meter is a data cap rather than a straight per-GB rate, effective cost depends on how fully the tier is used rather than on headcount.

Always combine cost-per-GB with detection content fit, compliance content pack value, SOC retraining capacity, and broader IT consolidation context before making vendor decisions. Per-GB normalisation is a useful starting point, not a substitute for the broader buyer-fit analysis.

FAQ

Common questions

Which SIEM is cheapest per GB in 2026?

At 50 GB per day, the lowest all-in figures land with Exabeam's SIEM tier (~$36K), Devo (~$45K to $55K with 400-day retention bundled), and Google Chronicle (~$46K on its data-cap model). Splunk Cloud base ingest (~$50K) sits near the low end, with Enterprise Security roughly doubling it to ~$100K all-in. CrowdStrike Falcon LogScale is not the cheapest option: its $5.95 per GB pay-as-you-go rate works out to ~$109K at 50 GB per day. The honest answer depends on the specific environment shape, retention requirement, and existing-platform context; use the table above to compare against your own log volume.

Is Splunk the most expensive SIEM per GB?

Not at 50 GB per day. Splunk Cloud base ingest lands near ~$50K, and all-in with Enterprise Security is ~$100K. Two vendors sit higher: IBM QRadar at ~$110K to $140K (estimate; IBM publishes no list price) and CrowdStrike Falcon LogScale at ~$109K both exceed Splunk all-in, and Splunk base is near the low end of the priced set. Splunk's per-GB curve runs roughly $665 to $1,620 per GB per day per year depending on commit volume. The older reputation for Splunk as the headline most-expensive SIEM does not hold once current vendor pricing is reconciled.

How accurate are these figures for vendors that do not price per GB?

Several vendors do not publish a clean per-GB rate, and we represent that honestly rather than forcing a number. Sumo Logic uses a Flex model with free ingest and credits charged on scan and storage (~$1.50 per credit), so there is no headline per-GB rate. Datadog Cloud SIEM is a multi-line meter (ingest $0.10 per GB, indexing $1.70 to $2.50 per million events, Cloud SIEM $5 per million analyzed events). Securonix EON prices per GB per day across BASIC, STANDARD, ADVANCED, and ALL-IN tiers with no published list. Google Chronicle uses a data-cap and credit model at roughly £2,000 per TB per year. IBM QRadar (per-EPS) and LogRhythm (per-MPS, self-hosted) are estimates converted at a typical mix; specific environments vary by 30 to 50 percent.

Why isn't open-source SIEM (Wazuh, ELK, Graylog) in the comparison?

Open-source SIEMs have zero per-GB licence cost but meaningful operational cost (infrastructure, engineering hours, staff training). Realistic year-one TCO for a 50 GB-per-day Wazuh deployment runs $180K to $280K once you add infrastructure and an engineer who genuinely understands Elasticsearch, comparable to Microsoft Sentinel at the same volume but with substantially more operational risk. Per-GB licence comparisons against commercial SIEMs are misleading; see our open-source SIEM page for the honest TCO breakdown.

Do these per-GB rates include staffing and storage?

No. The per-GB rates in our table cover SIEM platform licensing only (and bundled Cloud SIEM analytics where applicable). Staffing (typically one analyst FTE per 50 to 75 GB per day at $170K to $250K loaded cost), storage and retention extension (typically 18 to 30 percent of licence at 365-day retention), integration and custom connectors (typically $75K to $300K in year one), and tuning and detection-rule development (typically $50K to $120K initial spend) are separate cost lines. Total Year 1 SIEM TCO reliably runs 2 to 3x the per-GB licence figure once staffing is included.

Updated 13 July 2026