← Blog Pricing

SIEM cost per gigabyte: why the unit makes your team argue for less visibility

SIEM cost is usually metered per gigabyte, so every new log source becomes a budget argument — and vendor lock-in is the fear underneath it. What a per-deployment unit changes, and what it honestly does not.

Most SIEM cost is priced against a meter: gigabytes ingested per day, events per second, or a data tier committed a year in advance. That one design decision shapes how a security team behaves more than any feature on the datasheet, because it puts a price on visibility itself. Every new log source becomes a budget conversation, and the sources that lose those conversations tend to be the verbose, low-signal, occasionally decisive ones.

This is a piece about the unit rather than the vendor. Per-gigabyte billing is not dishonest — somebody is operating storage and query compute on your behalf, and metering it is a defensible way to charge for that. The problem is what the meter teaches your team to do between renewals.

Why the unit is the whole design

A price is an instruction. If you are billed by volume, the cheapest version of your SOC is the one that collects the least, and any detection engineer proposing a new source is implicitly proposing a cost increase they will have to defend in front of someone who does not read alerts for a living.

Worse, the three things that move the bill are three things you do not control: how big your estate grows, how noisy a bad week gets, and how long your regulator makes you keep the evidence. Gartner has described SIEM buyers as having grown increasingly frustrated by SIEM cost bloat, and that frustration is rational rather than sentimental — the meter charges you most in exactly the weeks you can least afford a conversation about it.

Different units reward different behaviour, and it is worth seeing them side by side:

What you are billed for What grows the bill What the team learns to do
Gigabytes ingested Onboarding a source Drop the verbose ones
Events per second A noisy week Filter at the collector
Endpoints or agents Protecting more of the estate Leave segments unwatched
Named seats Letting more people look Share a login
Months of retention Meeting a retention obligation Keep less, for less time
A deployment, per year Nothing you do Collect what you need

Only the last row describes a security decision. Every other row is a procurement decision wearing a security decision's clothes, and it gets made once a year by people who will never see the case it quietly closed off.

The sources you drop first are the ones you needed

Ask a SOC lead which logs get cut when a renewal comes in high and the answer is consistent: DNS, proxy, verbose authentication, endpoint process telemetry. High volume, low average value per line — and precisely the data that turns three unremarkable alerts into one intrusion you can actually prove.

The awkward part is that collecting them is not the same as detecting on them. CardinalOps, in its 2025 State of SIEM Detection Risk, read live production SIEM configuration metadata and found deployments carrying detections for about 21% of MITRE ATT&CK techniques while the data they were already ingesting could support roughly 90% of them. It also found that around 13% of the rules already in place were silently broken.

Set that beside a per-gigabyte invoice and it is uncomfortable in both directions. You are already paying to store far more than you detect on, so buying more ingestion is not the lever anyone hopes it is. But trimming ingestion to shrink the bill removes detection coverage you had already paid for and simply never switched on. The meter pushes you towards the second move, and the second move is the one you cannot see the consequences of until an incident goes unexplained.

SIEM cost has two halves, and only one arrives as an invoice

The other half is the week. Microsoft and Omdia's vendor-commissioned State of the SOC 2026 reports that around two thirds of SOC teams lose about a fifth of their weekly capacity to manual correlation — joining alerts across separate tools by hand to work out whether four of them are one incident. The SANS SOC Survey 2025 puts the typical fully staffed SOC at two to ten people, with 79% running around the clock.

A fifth of a small team's week is a standing cost no procurement exercise ever prices. It appears on no renewal, nobody signs it off, and it is paid in tier 1 hours that grow with the same estate that grows the invoice. For most teams it is the larger of the two numbers.

That is the half a verdict layer addresses. It is worth being exact about which half, because the two are routinely conflated in a pitch.

A different unit: one deployment, one year

Seculogik is a verdict layer that sits above the detection stack you already run — Splunk, Microsoft Sentinel, CrowdStrike, Microsoft Defender, Cortex XDR, Elastic, OpenSearch, ClickHouse, Wazuh, or a connector we build when your source is not on the list. It reads the alerts those tools produce, puts each one through nine independent checks that must agree on one answer, and returns a short triage queue: each case carries a verdict, a confidence score, a readable decision trace, a clock and an owner.

It is licensed per deployment, per year. Two things move the number: the edition you deploy and the modules you switch on. That is the entire model. Not the gigabytes that land on the box, not the endpoints behind them, not how many analysts log in, not how long you keep your own data.

For a managed SOC serving several customers, the MSSP edition is one flat price per deployment. Serve one customer or fifty for the same fee. Nearly every platform an MSSP compares us against bills by asset, endpoint or ingested volume, so their invoice grows on the day a new customer is signed. Ours does not: your growth is not our revenue event.

Self-hosted, so there is nothing for us to meter

This is architecture rather than restraint. Seculogik runs on one box you own — Debian or Ubuntu, Docker or bare metal, no GPU — inside your own network. The alerts, the cases and the evidence stay on your infrastructure, and we hold none of it.

To bill you per gigabyte we would have to measure what crosses that box, which means telemetry leaving your estate and arriving at ours. Self-hosted and metered do not go together. It also settles the vendor lock-in question in the only way that matters: your data was never ours to hold back. The licence is a file you install, and when the term ends the platform says so plainly instead of quietly degrading.

What this does not do to your SIEM bill

It does not reduce it. Your logs stay in your own store, we never ask you to move them, and nothing here re-platforms your ingestion. If a vendor tells you their layer will cut your SIEM cost by some headline percentage, the honest follow-up question is: which sources are you expecting me to stop collecting, and who signs off the detection coverage that leaves with them?

We publish no figures of our own either — no rate card, no accuracy claim, no false-positive-reduction number. And we are early: no customers yet, no ANSSI or CSPN qualification, no third-party penetration test report, no SLA. Those are the terms on offer, stated up front, because a claim you have to walk back later costs more than the deal it won. Hold us to the shape of the model instead, which is checkable today.

Five questions to ask about SIEM cost before you sign

  1. What exactly is metered, and what does the worst week of last year cost under it?
  2. Which of my sources would you advise me not to collect, and what detection coverage goes with them?
  3. Does the price move when I add an analyst, a site, or a customer I protect?
  4. If I retain data for the period my regulator requires, what does the retention itself cost?
  5. At the end of the term, what do I still hold — the data, the cases, the evidence trail?

The last one is the one people forget, and it is the one that decides how free you are at the next renewal. Vendor lock-in is rarely a clause anyone can point to; it is a team that cannot leave, and a team that cannot leave has no negotiating position, whatever the unit says.

Where to go next

If per-gigabyte pricing is the reason your own team argues about visibility, the unit is the first thing to change — not the volume, and not the vendor. Read how a Seculogik quote is built: one deployment, one year, two variables, no meter. For the argument behind the layer itself, the SOC as a decision system sets out why a SOC should be judged on the decisions it produces rather than the alerts it displays.

When you want the number, tell us who you protect and we will come back with it in one conversation.