{
  "slug": "siem-log-ingestion-cost",
  "title": "SIEM Log Ingestion Cost Calculator",
  "heading": "SIEM Log Ingestion Cost Calculator",
  "category": "financial",
  "url": "https://www.revenuelab.fyi/toolbox/siem-log-ingestion-cost",
  "summary": "Estimate monthly SIEM cost from log volume, sources, and retention period.",
  "description": "SIEM pricing is dominated by ingestion volume, and volume is dominated by a handful of noisy log sources: firewalls, DNS, endpoint telemetry, and cloud audit logs routinely account for 60-80% of total daily GB in a typical enterprise environment. This calculator estimates total daily and monthly log volume across your major sources, applies a per-GB ingestion rate common to consumption-priced platforms (Splunk, Sentinel, Chronicle-style pricing), and adds a retention cost multiplier since most platforms charge separately or at reduced rates for storing hot data beyond 30-90 days versus cold/archive storage. The output is meant for budget conversations and vendor negotiation prep: knowing your actual daily GB by source lets you push back on quotes, identify candidates for filtering or sampling before ingestion (like verbose DNS query logs), and decide what really needs 12 months of hot retention for compliance versus what can move to cheap cold storage after 90 days.",
  "formula": "Monthly cost = daily GB × 30.4 × price per GB × retention multiplier, summed across log sources; archive tier applied to data beyond hot retention window.",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=siem-log-ingestion-cost",
  "inputs": [
    {
      "id": "firewallGb",
      "label": "Firewall/network logs",
      "kind": "number",
      "hint": null,
      "default": 40,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "endpointGb",
      "label": "Endpoint/EDR telemetry",
      "kind": "number",
      "hint": null,
      "default": 25,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "cloudGb",
      "label": "Cloud/app audit logs",
      "kind": "number",
      "hint": null,
      "default": 15,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "otherGb",
      "label": "Other sources (DNS, proxy, identity)",
      "kind": "number",
      "hint": null,
      "default": 20,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "pricePerGb",
      "label": "Ingestion price per GB",
      "kind": "number",
      "hint": null,
      "default": 2.3,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "hotRetentionDays",
      "label": "Hot retention window",
      "kind": "number",
      "hint": null,
      "default": 90,
      "unit": null,
      "min": 1,
      "max": 730
    },
    {
      "id": "archiveMultiplier",
      "label": "Cold/archive price as % of hot price",
      "kind": "number",
      "hint": null,
      "default": 15,
      "unit": null,
      "min": 0,
      "max": 100
    }
  ],
  "outputs": [
    {
      "id": "monthlyTotal",
      "label": "Estimated monthly SIEM cost",
      "format": "currency",
      "hint": null,
      "primary": true
    },
    {
      "id": "annualTotal",
      "label": "Estimated annual cost",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "dailyGb",
      "label": "Total daily ingestion",
      "format": "decimal",
      "hint": null,
      "primary": false
    },
    {
      "id": "monthlyGb",
      "label": "Total monthly ingestion",
      "format": "decimal",
      "hint": null,
      "primary": false
    },
    {
      "id": "hotIngestCost",
      "label": "Hot-tier ingestion cost (monthly)",
      "format": "currency",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Firewall/network logs: 40",
      "Endpoint/EDR telemetry: 25",
      "Cloud/app audit logs: 15",
      "Other sources (DNS, proxy, identity): 20",
      "Ingestion price per GB: 2.3",
      "Hot retention window: 90",
      "Cold/archive price as % of hot price: 15"
    ],
    "outputs": [
      "Estimated monthly SIEM cost: $7,783",
      "Estimated annual cost: $93,391",
      "Total daily ingestion: 100",
      "Total monthly ingestion: 3,040",
      "Hot-tier ingestion cost (monthly): $6,992"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter firewall/network logs.",
      "Enter endpoint/edr telemetry.",
      "Enter cloud/app audit logs.",
      "Enter other sources (dns, proxy, identity).",
      "Enter ingestion price per gb.",
      "Enter hot retention window.",
      "Enter cold/archive price as % of hot price.",
      "Read your estimated monthly siem cost on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "firewallGb": 24,
        "endpointGb": 15,
        "cloudGb": 9,
        "otherGb": 12,
        "pricePerGb": 1.38,
        "hotRetentionDays": 54,
        "archiveMultiplier": 10
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "firewallGb": 40,
        "endpointGb": 25,
        "cloudGb": 15,
        "otherGb": 20,
        "pricePerGb": 2.3,
        "hotRetentionDays": 90,
        "archiveMultiplier": 15
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "firewallGb": 64,
        "endpointGb": 40,
        "cloudGb": 24,
        "otherGb": 32,
        "pricePerGb": 3.6799999999999997,
        "hotRetentionDays": 144,
        "archiveMultiplier": 25
      }
    }
  ],
  "limitations": [
    "Results are estimates before tax, fees, and inflation unless an input explicitly covers them.",
    "Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.",
    "This is educational maths, not financial advice. Check anything contractual with the lender or your accountant."
  ],
  "faq": [
    {
      "q": "Which log sources should I look at first to cut cost?",
      "a": "Firewall and DNS logs are usually the biggest and least valuable per-GB source since a huge share is routine allowed traffic; applying filtering to drop known-benign, high-volume, low-signal events (health checks, internal chatter) before ingestion commonly cuts 20-40% of total volume with minimal detection impact."
    },
    {
      "q": "Why do vendors charge so much less for archive/cold storage?",
      "a": "Cold storage tiers trade query speed and immediate searchability for cost, data sits in cheaper storage and takes minutes to hours to rehydrate before you can search it, which is fine for satisfying a compliance retention requirement but not for active investigation, hence the split pricing model most platforms use."
    },
    {
      "q": "How long do I actually need to keep logs hot?",
      "a": "Most active investigations and threat hunting reference the last 30-90 days; keep that window hot and searchable, then move older data to archive tier if you have a compliance requirement (PCI DSS requires 1 year, with 3 months immediately available) or your cyber insurance policy specifies a retention minimum."
    },
    {
      "q": "Is per-GB pricing better or worse than per-node/per-user pricing?",
      "a": "It depends on your environment. Log-heavy but low-headcount environments (industrial, IoT-heavy, high-transaction-volume) often do better on per-node or flat-tier pricing, while typical office environments with moderate per-user log generation usually find per-GB more predictable and easier to control through filtering."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/soc-staffing-coverage",
    "https://www.revenuelab.fyi/toolbox/mttd-mttr-cost-impact"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — SIEM Log Ingestion Cost Calculator (https://www.revenuelab.fyi/toolbox/siem-log-ingestion-cost)"
}