SIEM Pricing in 2026: What Six Platforms Cost for the Same 50 GB a Day

SIEM pricing worked out on one workload: 50 GB a day, 200 sources, 12 months retention, across Microsoft Sentinel, Splunk, QRadar, Elastic, Graylog and Wazuh. Every list price verified on the vendor's page, with the arithmetic shown.
- Defense
- Siem
- Detection
- Growth
Key facts
- Microsoft Sentinel lists pay-as-you-go analysis at $4.30 per GB and a 50 GB per day commitment tier at $161.25 per day (East US 2, promotional price valid to 31 December 2026), which is $58,856 a year for 50 GB a day (microsoft.com, 4 September 2026).
- Sentinel data lake storage is $0.026 per GB per month billed at a fixed 6:1 compression, so 275 days of cold retention on 50 GB a day costs about $715 a year, against $16,500 for the same data in interactive retention at $0.10 per GB per month (Microsoft pricing pages, 4 September 2026).
- Splunk publishes no SIEM price on splunk.com; the only public dated figure is a reseller term licence on AWS Marketplace at $961.40 per GB per day per year for the 50 to 99 GB tier, which is $48,070 a year for 50 GB a day of Splunk Enterprise, before Enterprise Security (AWS Marketplace, 4 September 2026).
- IBM's own AWS Marketplace listing prices QRadar SIEM at $12,074.40 per year per unit of 500 EPS and 10,000 flows per minute; 50 GB a day at 500 bytes per event is about 1,157 EPS, so three units cost $36,223 a year (AWS Marketplace, 4 September 2026).
- Elastic Security Serverless charges as low as $0.11 per GB ingested and $0.019 per GB retained per month on the Complete tier, which is $6,169 a year for 50 GB a day with 12 months retained; per-endpoint fees were removed on 23 March 2026 (elastic.co, 4 September 2026).
- Graylog Security starts at $18,000 a year from 10 GB a day; Graylog does not publish a 50 GB a day price, and a straight-line extrapolation gives $90,000 before the volume discounts Graylog says apply at each tier (graylog.org, 4 September 2026).
- The US median wage for information security analysts was $129,180 in May 2025 (US Bureau of Labor Statistics), which is the single largest line in a self-hosted Wazuh deployment.
TL;DR
Priced on one workload, 50 GB a day, 200 log sources, 12 months retention, the 2026 annual vendor bill is about $6,185 on Elastic Security Serverless, $10,172 on self-hosted Wazuh (hardware only), $46,395 on IBM QRadar, $58,242 on Splunk Enterprise before the unpublished Enterprise Security add-on, $60,475 on Microsoft Sentinel, and up to $100,172 on Graylog Security. Count the engineer who runs it and the order changes. Sentinel and Elastic stay cheapest. Wazuh climbs to about $139,000 because it needs a full-time person. Splunk and IBM do not publish SIEM prices on their own sites, so the figures here come from their dated AWS Marketplace listings. Every price was read from the vendor on 4 September 2026 and every step of the arithmetic is on this page.
Most articles about SIEM pricing are a list of per-GB rates copied from other articles. A per-GB rate tells a budget holder nothing until it is multiplied by volume, retention, hardware and the person who keeps the thing alive. So this article does the multiplication. One workload, six platforms, the same assumptions for all.
Two things before the numbers. We sell cybersecurity training, not SIEM: no platform here is a client, partner or sponsor, and none reviewed the text. And where a vendor does not publish a price, I say so instead of inventing one. Two of the six do not.
The Annual Cost of 50 GB a Day on Six SIEM Platforms
The table is the article. Everything below it explains how each cell was calculated.
| Platform | Licence | Infrastructure | Egress and metered extras | Vendor bill per year | Engineer share | Total with people |
|---|---|---|---|---|---|---|
| Elastic Security Serverless | $6,169 | $0 (SaaS) | $16 | $6,185 | 0.25 FTE, $32,295 | $38,480 |
| Wazuh, self-hosted | $0 | $10,172 | $0 | $10,172 | 1.0 FTE, $129,180 | $139,352 |
| IBM QRadar SIEM | $36,223 | $10,172 | $0 | $46,395 | 0.5 FTE, $64,590 | $110,985 |
| Splunk Enterprise + ES | $48,070 + ES quote | $10,172 | $0 | $58,242 + ES | 0.5 FTE, $64,590 | $122,832 + ES |
| Microsoft Sentinel | $58,856 | $0 (SaaS) | $1,619 | $60,475 | 0.25 FTE, $32,295 | $92,770 |
| Graylog Security | up to $90,000 | $10,172 | $0 | up to $100,172 | 0.5 FTE, $64,590 | up to $164,762 |
Prices read from vendor pages and vendor-owned AWS Marketplace listings on 4 September 2026. USD. Engineer cost is the US median wage for information security analysts, $129,180, from the Bureau of Labor Statistics. The FTE shares are my assumptions and I explain them below.
Read the table with two caveats. The Splunk row is a floor, because Enterprise Security has no public price. The Graylog row is a ceiling, because Graylog publishes only its 10 GB a day starting price and says discounts apply at every tier above it. Everything else is list price times volume.
The Four SIEM Licensing Models
Every SIEM bills on one of four meters, and the meter decides which of your numbers matters.
Per GB ingested. Sentinel, Splunk ingest licences, Elastic and Graylog. You pay for bytes in, so verbose sources (firewalls, proxies, Windows audit logs) are the expensive ones and filtering at the collector is the lever.
Per event per second. IBM QRadar. You pay for a sustained event rate whatever the size, so tiny firewall events cost more here than per GB and large JSON events cost less. The conversion depends on average event size; the QRadar section shows it.
Per node or per host. Splunk workload pricing (compute units), Wazuh Cloud (agents), and the hardware bill of any self-hosted deployment.
Per user. Rare for the SIEM itself in 2026, common for the SOAR next to it. IBM prices QRadar SOAR by authorized users, not by data.
Underneath all four sits retention. Hot and cold data are priced 5 to 25 times apart on the same platform, and 12 months is where the gap shows.
The Benchmark: 50 GB a Day, 200 Sources, 12 Months
The workload is a mid-sized company, not a bank: 140 servers, 40 workstations with endpoint logs, 20 network devices, producing 50 GB of raw logs a day. That is 18,250 GB a year. Retention is 12 months, split as 90 days hot and 275 days cold, which is what most compliance frameworks and most incident timelines ask for.
Assumptions that apply to every row:
- Prices are US dollars from the vendor's US list, read on 4 September 2026. Hetzner prices in euros are converted at the ECB reference rate of that day, 1 EUR = 1.1615 USD.
- Self-hosted platforms (Splunk, QRadar, Graylog, Wazuh) run on the same four dedicated servers: two AX102 data nodes (16 cores, 128 GB, 3.84 TB NVMe each), one AX42 manager, one SX65 with 64 TB of disk for the cold tier. Hetzner lists them at €259, €259, €99 and €84 a month plus €346 of setup, which is €8,758 in year one, or $10,172. The point of one shared bill of materials is that only the licence changes between rows.
- Egress is 5% of ingest leaving the platform for a ticketing system or SOAR. On Hetzner it is included in the port; on Azure and Elastic it is metered.
- Engineer share: 0.25 FTE for a fully managed SaaS, 0.5 FTE for a vendor-supported self-managed product, 1.0 FTE for a community-supported one. This part is opinion. I have run two of these and I think the ratios are generous to the self-hosted side.
The full model, with every source URL, is refreshed quarterly.
SIEM Cost by Platform
Microsoft Sentinel Pricing
Microsoft publishes everything, which is why the Sentinel pricing page is the only vendor page in this article you can rebuild the row from without help.

The analytics tier has one meter: $4.30 per GB pay-as-you-go. Commitment tiers replace it with a daily fee. The 50 GB tier is $161.25 a day, an effective $3.23 per GB; the page marks it as a public preview with promotional pricing to 31 December 2026, locked until March 2027 for anyone who signs up in the window. The 100 GB tier is $296 a day.
Analysis at 50 GB a day: 161.25 × 365 = $58,856. If the preview tier goes away, pay-as-you-go is 4.30 × 50 × 365 = $78,475. Budget the higher number if your renewal lands after March 2027.
Retention is where Sentinel got cheap. The billing documentation says the first 90 days are free and older data can sit in the Sentinel data lake at $0.026 per GB per month, billed at a fixed 6:1 compression. Our 275 cold days hold 13,750 GB raw, billed as 2,292 GB: 2,292 × 0.026 × 12 = $715 a year. The same data in Azure Monitor interactive retention at $0.10 per GB per month would be $16,500. One setting, a 23 to 1 difference.
Lake queries cost $0.005 per GB scanned; twelve full-lake investigations a year is $825. Egress of 912 GB from Azure at $0.087 per GB is $79.
Vendor bill: 58,856 + 715 + 825 + 79 = $60,475. Microsoft Learn is free and the SC-200 exam is $165, so three analysts cost $495. With a quarter of an engineer the total is $92,770.
Microsoft 365 Defender alerts, some Entra ID tables and other Microsoft sources ingest free, so a Microsoft-heavy shop starts the meter below 50 GB. That, more than the list price, is why Sentinel wins deals.
Splunk Enterprise Security Pricing
Splunk does not publish a price for Splunk Cloud, Splunk Enterprise or Enterprise Security. The pricing page names the models (activity-based, workload, ingest, entity) and puts «Get a quote» under every SIEM tile; only the Observability products carry numbers. Splunk's own AWS Marketplace listing for Splunk Cloud is private-offer only.
The one dated public figure comes from a reseller. Bynet's Splunk Enterprise term licence listing on AWS Marketplace prices a 12-month licence with a Standard Success Plan at $1,138.50 per GB per day for 20 to 49 GB, $961.40 for 50 to 99 GB, and $759 for 100 to 199 GB. At 50 GB a day that is 50 × 961.40 = $48,070 a year.
That buys the platform. Enterprise Security, the app with the correlation searches, risk-based alerting and content packs, is a separate licence with no public price from Splunk or any reseller I could find. The row reads $48,070 plus ES because a floor is better than a number I cannot source.
Vendor bill with the shared hardware: 48,070 + 10,172 = $58,242 plus ES. Splunk does publish training, and it is the priciest of the six: Administering and Using Splunk Enterprise Security are $1,500 each for three 4.5-hour days, exams $130 an attempt, so one admin, two analysts and three exams is $4,890. With half an engineer the total is $122,832 plus ES.
For features rather than money, the Splunk vs QRadar vs Sentinel comparison covers detection, query languages and hiring demand.
IBM QRadar Pricing
IBM's QRadar SIEM pricing page explains two models, usage (events per second plus flows per minute) and enterprise (managed virtual servers, unlimited events), then asks you to book a meeting. Its footnote says «Prices shown are indicative». No price is shown.
IBM Security's own AWS Marketplace listing does show one: QRadar SIEM at $12,074.40 per 12 months per unit of 500 events per second and 10,000 flows per minute. QRadar SOAR is listed next to it at $22,704 per two authorized users, which this benchmark does not include.
Converting bytes to events is the whole QRadar question. At 500 bytes per event, 50 GB a day is 100 million events, or 1,157 EPS sustained over 86,400 seconds. Three 500 EPS units with burst headroom: 3 × 12,074.40 = $36,223. At 300-byte firewall events the same 50 GB is 1,929 EPS and four units, $48,298; at 800-byte Windows or JSON events it is 723 EPS and two units, $24,149. Measure your event size before you believe any QRadar quote, including this one.
Vendor bill with the shared hardware: 36,223 + 10,172 = $46,395. IBM does not publish training prices, so the model counts $0 and flags it. With half an engineer the total is $110,985.
Elastic Security Pricing
Elastic prices its serverless SIEM the way a cloud provider prices storage, in cents. The Elastic Security Serverless page lists two tiers, Security Analytics Essentials and Complete, and three meters each: ingest per GB, retention per GB per month, and egress per GB. The Complete tier used here is $0.11 per GB ingested, $0.019 per GB retained per month, and $0.05 per GB egress after 50 GB free. All three are «as low as», meaning the cheapest region and cloud; other regions cost more. The page also notes that per-endpoint fees were removed on 23 March 2026, which matters if you were quoted on the old model.
Ingest: 18,250 × 0.11 = $2,008. Retention at steady state, the whole year retained: 18,250 GB × 0.019 = $347 a month, $4,161 a year. Egress: 912 GB minus 600 free, × 0.05 = $16. Vendor bill: $6,185.
Year one is cheaper because retention ramps from zero; I report steady state so the number does not flatter Elastic. Even so it is a tenth of Sentinel on the same bytes, and the reason is structural: Elastic bills retained GB at cents, Sentinel bills ingested GB at dollars. Heavy query loads cut the other way, since compute is bundled into those rates and can push a project onto a bigger footprint. Elastic does not publish training prices. With a quarter of an engineer the total is $38,480.
Self-managed Elastic, under the licence that went back to OSI-approved AGPLv3 in 2024, is covered in the open source SIEM guide. It moves you to the Wazuh cost structure: no ingest fee, but hardware and a person.
Graylog Enterprise and Security Pricing
Graylog publishes a floor and a licensing FAQ, and the FAQ is unusually clear.

Per the Graylog pricing page, Graylog Open is free under SSPL with no volume cap. Graylog Enterprise (log management) starts at $15,000 a year and Graylog Security (the SIEM edition, with maintained detection rules, Sigma support and anomaly detection) at $18,000 a year, both «from 10 GB/day on daily volume or 100 GCUs on annual consumption». A GCU buys 20 GB of Security. Only processed data in the active tier counts, data routed to the data lake is free until retrieved, and «the per-unit rate decreases at each licensing tier».
Fifty GB a day is five times the entry point, or 913 GCUs a year, and Graylog does not publish that price. A straight line from the floor gives 18,000 / 10 × 50 = $90,000, which by Graylog's own statement is a ceiling. The real quote sits between $18,000, which does not cover this volume, and $90,000. The chart shows the ceiling and labels it.
With the shared hardware the vendor bill is up to 90,000 + 10,172 = $100,172. Two things pull it down: the discounts, and routing the noisy 60% to the lake so you license only the 40% you alert on. Training is free (on-demand academy, plus Graylog Accelerator onboarding with every paid licence). With half an engineer the total is up to $164,762.
Wazuh: Free Software, Paid Everything Else
Wazuh costs nothing to license and the Wazuh Cloud page prices the managed version by agents: Small (up to 100 agents, 1 month indexed) from $571 a month, Medium (up to 250 agents, 3 months indexed, 1 year archive) from $923 a month, Large (up to 500 agents) from $1,467 a month. The Medium plan fits 200 sources at $11,076 a year, but no published plan offers 12 months of indexed retention, so the benchmark row is self-hosted.
Self-hosted, the only vendor line is hardware. The Wazuh indexer documentation recommends 16 GB of RAM and 8 cores per indexer node and sizes disk by alerts: 3.7 GB per server, 1.5 GB per workstation, 7.4 GB per network device for 90 days. That is alerts only. Holding 50 GB a day of raw events for a year means archives on, and then you need the same build as everyone else: $10,172, licence $0, egress $0.
Then the bill Wazuh's page cannot show. Someone owns the upgrades, the ruleset tuning that stops 200 agents producing 200,000 daily alerts, the index lifecycle from NVMe to the cold node, certificate rotation, and the 3 a.m. page when the indexer fills its disk. With community support only, that is one engineer. At the BLS median of $129,180 the total with people is $139,352, above Splunk's floor and above Sentinel.
Wazuh is still the platform I tell students to install first, because a year of running it teaches SIEM economics better than buying one. The argument is only against calling it free in a budget meeting.
Every SIEM is priced twice: once by the vendor, once by the payroll. Only the second price is honest, and it is the one nobody puts on a pricing page.
The Costs Nobody Quotes You
Four lines that never appear on a pricing page and always appear on the invoice.
Egress. If logs start in one cloud and end in another, the first cloud charges you to let them leave. AWS lists data transfer out at $0.09 per GB after 100 GB free a month; Azure lists $0.087 in North America and Europe. Ship all 50 GB a day out of AWS to a SIEM elsewhere and that is 17,050 billable GB, about $1,535 a year, before the SIEM has done anything. Small next to a licence, a quarter of Elastic's whole bill, and invisible until the cloud invoice arrives. Keep the SIEM where most logs are born, or filter before the boundary.
Hot versus cold retention. The 12 months in this benchmark cost $715 or $16,500 on Sentinel depending on one dropdown. Elastic's retention meter is two thirds of its total. Graylog charges nothing for data parked in its lake and everything for data you retrieve. Self-hosted, the cold tier is an €84 a month server with 64 TB of disk. Decide which 90 days you need at query speed and which 275 you need for the auditor, and price them separately. One retention setting for everything means paying hot prices for cold data.
Training. The vendor that publishes it fully is the one whose product needs it most: Splunk's two Enterprise Security courses are $1,500 each, the exams $130, so three people cost $4,890 before travel. Microsoft's SC-200 is $165 with a free learning path. Graylog's academy is free. IBM, Elastic and Wazuh do not publish instructor-led prices, so the model counts zero and says so. The larger cost is on no list: the quarter your analysts spend slower because the query language changed. SPL, Kusto and Lucene are not interchangeable, and a team fluent in one is worth more than a discount on another. If you are choosing a SIEM to learn rather than to buy, the SOC analyst roadmap shows which appears most in job postings.
The engineer. This line reorders the table. A SaaS SIEM still needs someone to own connectors, analytics rules and cost alerts: a quarter of a person. A self-managed commercial SIEM with vendor support needs half a person for upgrades, capacity and the vendor relationship. A community-supported SIEM needs a whole one. At the $129,180 median (more with overhead, more in London or Zurich, less in Madrid or Lisbon) the gap between 0.25 and 1.0 FTE is $96,885 a year, more than the licence gap between the cheapest and dearest commercial platform here.
Which SIEM Pricing Model Fits You
Decide by meter, not by brand. Mostly Microsoft logs: Sentinel, with the free-ingest tables and the $0.026 lake, and lock the 50 GB tier before the promotional window closes at the end of 2026. High volume, small budget: Elastic Serverless, the only bill here that stays in four figures, after checking the regional rate and your query load. Large events and spiky volume: QRadar's EPS meter, with IBM's Marketplace price as the number to negotiate from. Splunk skills already in the building: Splunk, because not retraining is worth more than the licence gap, and get the ES quote in writing. Engineering time and no budget: Wazuh or self-managed Elastic, with the engineer on the same slide as the servers.
FAQ: SIEM Pricing in 2026
How much does a SIEM cost per year? For a mid-sized workload of 50 GB a day with 12 months retention, the 2026 vendor bill ranges from about $6,000 on Elastic Security Serverless to $60,000 on Microsoft Sentinel and up to $100,000 on Graylog Security, with Splunk and QRadar in between at $46,000 to $58,000 plus hardware. Add a quarter to a full engineer and the real annual cost sits between $38,000 and $165,000. The licence is rarely the largest line once people are counted.
How much does Microsoft Sentinel cost per GB? As of September 2026, Microsoft lists pay-as-you-go analysis at $4.30 per GB in East US 2. Commitment tiers cut that: the 50 GB a day tier is $161.25 a day, an effective $3.23 per GB, and the 100 GB tier is $296 a day, or $2.96 per GB. The first 90 days of retention are included. Beyond that, data lake storage is $0.026 per GB per month at 6:1 compression, and Microsoft 365 Defender alerts and some Entra ID tables ingest free.
Does Splunk publish its pricing? No. Splunk's pricing page offers a quote for Splunk Cloud, Splunk Enterprise and Enterprise Security, and its own AWS Marketplace listing is private-offer only. The only dated public price is a reseller term licence on AWS Marketplace, which lists Splunk Enterprise at $961.40 per GB per day per year for 50 to 99 GB a day. Enterprise Security, the SIEM application, has no public price anywhere, so any Splunk SIEM figure you read is a floor or a guess.
Is Wazuh really free? The software is free and open source with no licence fee and no volume cap. Running it is not free. Fifty GB a day for a year needs three or four servers, about $10,000 a year on dedicated hardware, and someone to own upgrades, rule tuning, index lifecycle and on-call. With community support only, that is closer to a full-time engineer than a quarter of one, which puts a realistic annual cost near $139,000 at US median wages. Wazuh Cloud starts at $571 a month but does not offer 12 months of indexed retention on its published plans.
What is the cheapest SIEM for 50 GB a day? On the vendor bill alone, Elastic Security Serverless at roughly $6,185 a year, because it bills ingest and retention by the GB at cents rather than dollars. On total cost including the people who run it, Elastic and Microsoft Sentinel are the two cheapest, at about $38,000 and $93,000 respectively, because both are fully managed. The cheapest platform for your team is the one whose query language your analysts already know, since retraining costs more than the licence difference.
Every figure here carries a date because every one of them will change: the Sentinel preview tier expires, Elastic's regional rates move, resellers relist. The model is reviewed quarterly and the arithmetic is public so you can rerun it with your own volume. The self-hosted half of the conversation continues in the open source SIEM guide.
Daute built Unihackers after a decade defending airlines, managed SOCs and international organisations. He is an Associate C|CISO and a regular voice on AI and cybersecurity in international media. Silver Winner at the 2021 Cyber Security Excellence Awards. He teaches the way he wishes someone had taught him: skip the noise, train on what attackers actually do, and graduate people who are useful from day one.
View ProfileReady to Start Your Cybersecurity Career?
Join hundreds of professionals who've transitioned into cybersecurity with our hands-on bootcamp.

