Tenzir pricing in 2026: Community, Enterprise and Sovereign
The independent Tenzir pricing reference. The free Community tier and its limits, what each paid tier actually unlocks, where Tenzir sits in the security data lifecycle, and an honest account of what is and is not publicly listed. Built from Tenzir's published pricing and product material, re-verified against the relaunched tenzir.com. Updated July 2026.
What Tenzir is, and why it matters for SIEM cost
Tenzir is a security data pipeline. It sits between your log sources (servers, firewalls, applications, endpoints) and your SIEM (Splunk, Sentinel, QRadar, Elastic). Telemetry flows into Tenzir, gets shaped and reduced, then routes to one or many destinations. The expensive SIEM only receives the data that matters for detection. The verbose noise goes to cheap storage or gets dropped before it is ever metered at SIEM rates.
This matters because SIEM pricing is overwhelmingly ingest-metered. Splunk Cloud lists at $1,800 to $3,500 per GB/day per year. Microsoft Sentinel runs $2.96 to $4.30 per GB. At those rates, every gigabyte of debug chatter, DNS noise or verbose Windows event you do not actually use for detection is taxed at SIEM list prices.
Tenzir's lineage is part of why buyers take it seriously. It grew out of VAST (Visibility Across Space and Time), a research engine for security telemetry with roots in the Zeek lineage, and its pipeline language TQL handles parsing, reshaping and routing of events. Tenzir's own material frames the goal as slashing SIEM, cloud and data costs; in practice most environments find 30 to 50 percent of their ingest is detection-irrelevant, which is the headroom a pipeline reclaims before the SIEM ever meters it.
How Tenzir fits, in three parts
Tenzir is a security data pipeline. It sits upstream of the SIEM, between your log sources and Splunk, Sentinel, QRadar or Elastic. Telemetry flows into Tenzir, gets shaped, reduced and routed, and only the data that matters for detection reaches the expensive SIEM.
Tenzir grew out of VAST (Visibility Across Space and Time), an open research engine for security telemetry with roots in the Zeek/Bro lineage. The pipeline language is TQL (Tenzir Query Language), which handles parsing, reshaping and routing of events.
SIEM pricing is overwhelmingly ingest-metered. Splunk Cloud lists at $1,800 to $3,500 per GB/day per year; Microsoft Sentinel runs $2.96 to $4.30 per GB. Every gigabyte of low-value telemetry is taxed at those rates once it lands in the SIEM.
The three Tenzir tiers
- · Unlimited nodes
- · 1 TB/day ingress + 1 TB edge storage
- · Nodes in your environment, Tenzir-hosted Platform
- · Platform API, community support
- · Licensed volume, annual contract
- · Multi-tenancy (workspaces), external secrets, RBAC, audit logs
- · Nodes in your environment, Tenzir-hosted Platform
- · 24x7 support and SLAs
- · Quoted separately, not volume-only
- · Custom identity provider
- · Self-hosted Platform, air-gapped capable
- · Dedicated support
Source: tenzir.com/pricing. Nodes run in your own environment in every edition. Community and Enterprise use the Tenzir-hosted Platform; Sovereign self-hosts the Platform, including air-gapped deployments. A fully cloud-hosted option is targeted for Q4 2026 and is not available today. Enterprise is priced per licensed volume on annual contracts. Sovereign is quoted separately for the self-hosted Platform and dedicated support, not as another volume-only tier. Community tier limits are published; the paid tiers publish feature sets and support levels but not prices, so this page does not invent dollar figures for them.
The SIEM savings math, worked
Illustrative. The filter ratio (40 percent) sits inside the typical 30 to 50 percent of ingest that most environments find detection-irrelevant (verbose Windows events, DNS chatter, debug streams). That 30 to 50 percent is our own neutral market figure for ingest reduction. Tenzir separately publishes a 30 to 80 percent SIEM cost reduction figure (tenzir.com/solutions/use-cases/siem-cost-optimization), cited here as their claim rather than adopted as ours. Net saving depends on Tenzir's volume-based quote, which is not publicly listed, so the licence line is left as a quote rather than a fabricated number.
When a pipeline like Tenzir is the right call, and when it is not
- + SIEM bill above $300K/yr and ingest-metered
- + 30%+ of ingest is detection-irrelevant noise
- + Multiple destinations needed (SIEM + data lake + analytics)
- + Migrating SIEMs and need to reshape data in flight
- + On-premise deployment requirements (Sovereign tier)
- - SIEM bill is under $100K/yr (the math does not work)
- - Single destination, simple log flow
- - Already on Sentinel with free Microsoft 365 source data
- - No engineering capacity to design pipelines properly
- - Below 200 GB/day total ingest (Community tier may be enough)