SIEM pricing in 2026 cannot be compared by headline number alone. Vendors charge by ingested data, retained data, event rate, employees, active agents, compute, credits, or a negotiated subscription. A useful SIEM cost comparison converts every proposal into the same scope and adds the people required to keep the platform working.
Published examples show why the meter matters. Elastic Security Serverless lists per-GB rates. Blumira charges per employee. Wazuh Cloud packages active agents and retention. Microsoft Sentinel, Splunk, IBM QRadar, FortiSIEM, and Google Security Operations use consumption, capacity, or quote-based models with different cost triggers.
This SIEM pricing comparison uses official vendor information checked on August 12, 2026. Public rates are snapshots rather than offers. Taxes, currencies, regions, discounts, minimum commitments, support, onboarding, and contract scope can change the final price.
Compare European SIEM proposals on the same worksheet
Review current European service benchmarks, ingestion and retention cost drivers, a provider comparison worksheet, and a pricing warning-sign checklist.
Download the Managed SIEM pricing guidePublic entry prices in this comparison start at $571 per month for Wazuh Cloud or $12 per employee per month for Blumira, while several enterprise SIEM platforms require a configured quote.
Those figures describe different products and meters. Wazuh's smallest cloud tier covers up to 100 active agents with defined retention. Blumira's Detect edition prices knowledge workers and includes one year of log retention. Elastic publishes ingestion and retention rates. A direct ranking would compare apples, servers, and a small invoice-shaped cabbage.
Managed SIEM adds people and operating scope to the platform. Q-Sec's current European Managed SIEM pricing resource reports a typical range of EUR 3,000 to EUR 10,000+ per month, depending on log volume, retention, cloud visibility, tuning, reporting, and support. Treat that as a contextual service benchmark, not a software price or universal market average.
Current public sources show the billing unit and a few starting prices, but only three vendors in this comparison publish straightforward list amounts for the selected offer.
| Platform | Published billing basis | Public price signal | What the buyer must verify |
| Microsoft Sentinel | Pay-as-you-go or daily commitment; separate data-lake meters | Commitment tiers start at 100 GB/day; rate varies by region | Analytics versus lake data, retention, queries, automation, AI, eligible free data |
| Elastic Security Serverless | Ingested GB + retained GB/month + egress and optional add-ons | Essentials: from $0.09 ingest and $0.017 retention; Complete: from $0.11 and $0.019 | Normalized volume, retention curve, egress, support, cloud and automation add-ons |
| Blumira | Knowledge workers per month | Detect $12; Respond $16; Automate $21 per employee/month | Employee definition, onboarding fee, edition scope, region, support hours, discounts |
| Wazuh Cloud | Active-agent tier with indexed and archive retention | $571 up to 100; $923 up to 250; $1,467 up to 500 active agents/month | Retention tier, support, extra services, regional hosting, usage above tier |
| Splunk | Ingest pricing or workload capacity measured in SVCs | Quote-based for Splunk Enterprise Security | Data volume, search concurrency, storage, apps, support, SVC sizing |
| IBM QRadar SIEM | EPS/FPM usage model or managed virtual servers | Quote-based; subscription or perpetual on-premises options | Burst rate, flows, server count, appliances, support, retention, services |
| FortiSIEM | Events per second or GB used per day | Official documentation gives the meters; public list rate not disclosed | License type, sustained and burst volume, nodes, retention, support, deployment |
| Google Security Operations | Subscription credits for ingestion with metered usage | Quote-based; overage uses the negotiated rate | Region-specific SKU, committed GB, overage, retention beyond 12 months, add-ons |
Elastic's listed rates are in US dollars and marked "as low as". Its page says the current base rates took effect November 1, 2025, and per-endpoint fees stopped applying on March 23, 2026. Blumira and Wazuh also publish US-dollar prices. None of these numbers should be copied into a European budget without region, tax, support, and contract checks.
COMPARISON LIMIT: This table compares published commercial structures. It does not compare detection quality, platform fit, implementation work, negotiated discounts, or total ownership cost. A lower unit rate can still produce a higher annual bill when the billed volume or retained scope is wider.
SIEM pricing models differ mainly in which unit grows the bill: data, events, entities, compute, credits, a fixed tier, or a managed-service scope.
| Pricing model | Main meter | Works well when | Cost risk |
| Ingestion-based | GB ingested per day or month | Security data volume is measured and governed | New sources, verbose logs, or duplicates raise cost immediately |
| Event-rate | EPS, messages, or flows | Event patterns are stable and burst behavior is understood | Short peaks and many small events can defeat a GB-based estimate |
| Entity-based | Employee, user, endpoint, agent, server, or asset | The entity definition matches how the company grows | High-volume entities or ambiguous counting rules distort the estimate |
| Workload-based | Compute capacity, searches, or analysis workload | Search demand and concurrent work can be tested | Poor searches, broad hunts, and busy dashboards consume capacity |
| Credit-based | Credits consumed by one or more platform functions | Credit conversion and usage reporting are clear | A simple invoice can hide several changing consumption ratios |
| Fixed tier | Bundled scope up to a threshold | The included data, retention, support, and overage rules are explicit | Growth crosses a tier boundary or an excluded source becomes necessary |
| Managed service | Monthly base, data, assets, or a blended scope | Human coverage and platform work are specified together | Similar labels hide different tuning, investigation, reporting, and response work |
The billing unit also shapes technical decisions. An ingestion meter encourages filtering and tiering. An entity meter rewards stable counting rules. A workload meter puts query design and concurrency under the microscope. A credit model is workable only when the buyer can trace activity to credit consumption.
Calculate SIEM cost by normalizing every quote to the same data, retention, capabilities, service hours, and contract period before comparing totals.
12-MONTH SIEM COST EQUATION: Platform license and usage + retention, query, egress, and infrastructure + onboarding and integrations + support and training + detection engineering + analyst coverage + incident response and exit work.
Use one source list and one service boundary for every bidder. Record endpoints, identities, firewalls, cloud accounts, SaaS services, business applications, daily volume, event peaks, retention tiers, search needs, users, reports, and response actions.
Use at least 30 days of source-level measurements and keep peak days visible. Estimate 12- and 36-month growth by source. A single average can hide month-end batch jobs, incident bursts, seasonal traffic, and a cloud project arriving mid-contract.
Split real-time analytics, searchable retention, archive, rehydration, queries, exports, and egress. Microsoft Sentinel, Elastic Security Serverless, and Google Security Operations expose different meters around these activities. One retention number cannot describe them all.
Add platform engineering, connector maintenance, detection tuning, triage, investigation, reporting, management, training, and on-call coverage. If a provider performs the work, price its contract. If the internal team performs it, use loaded labor and realistic coverage rather than salary alone.
Model a new cloud workload, a 30 percent log increase, longer retention, an incident month, a merger, and contract exit. Record which changes trigger overage, a new tier, professional services, or a fresh commercial review.
Read also SIEM platform economics and total ownership cost, which explains how data classes, staffing, retention, and the operating model affect the budget after onboarding.
A useful quote workbook records the meter, quantity, unit rate, included work, overage rule, evidence, owner, and contract term for every cost line.
| Cost line | Quantity and unit | Inclusions to record | Change or overage rule |
| Platform | Edition, tier, entities, EPS, GB, SVCs, or credits | Core SIEM, users, detections, dashboards, cases | Threshold, minimum, burst, and true-up |
| Data | Ingested, retained, scanned, restored, and exported volume | Hot, searchable, archive, compression, rehydration | Rate by tier, region, and retention age |
| Implementation | Sources, parsers, use cases, sites, and hours | Onboarding, migration, testing, documentation | New-source rate and parser ownership |
| Operations | Service hours, alerts, cases, reports, and meetings | Tuning, triage, investigation, reporting, governance | Volume cap, severity rule, and out-of-scope rate |
| Response | Hours, incidents, actions, and retainers | Containment support, forensics, communications, recovery | Approval, callout, travel, and emergency rates |
| Contract | Term, currency, tax, and indexation | Support, audit rights, data access, deletion, export | Renewal, termination, transition, and price review |
Cloud SIEM pricing removes much of the hardware bill but adds meters for ingestion, retention, queries, egress, automation, AI features, and regional service use.
Microsoft Sentinel bills analytics ingestion through pay-as-you-go or commitment tiers, with commitment starting at 100 GB per day. Its data lake can add separate charges for ingestion, processing, storage, queries, and advanced analysis. Rates depend on region and plan, so use the current Microsoft pricing page for the actual environment.
Elastic Security Serverless publishes separate rates for ingested and retained data. Its page also lists egress after a free allowance and optional charges for cloud protection, workflow executions, agent features, and a managed language model. The visible base rate is only the first row of the budget.
Google Security Operations uses subscription credits for core data ingestion. Usage draws down the committed GB balance, overage uses the negotiated rate, and retention beyond 12 months creates an additional charge. Google also documents region-specific SKUs, which makes the selected provisioning region part of the commercial model.
Managed SIEM pricing combines platform use with agreed engineering and analyst work, but the included work varies from one contract to another.
A provider can manage data-source onboarding, connector health, parser work, detection content, tuning, alert monitoring, triage, investigations, reports, and selected response support. The phrase "managed SIEM" does not prove that every task or every hour is included. Q-Sec's guide to who maintains SIEM after onboarding explains the ongoing work in more detail.
| Quote says | Write into the scope | Cost question |
| Onboarding included | Named sources, parser limits, validation, timeline, documentation | What happens when a new source appears? |
| 24/7 monitoring | Alert generation, human triage, investigation, notification, service hours | Which activities run overnight? |
| Detection tuning | Rule owners, review cadence, customer changes, noisy-rule handling | Is tuning capped or billable? |
| Incident response | Approved actions, included hours, severity, activation, handoff | Which actions and specialist hours cost extra? |
| Compliance reporting | Named reports, evidence fields, cadence, owner, audit support | Are custom mappings and audit meetings included? |
| Fixed monthly price | Data, assets, users, sources, retention, support, and overage | Which change reopens the price? |
For the benchmark ranges, comparison worksheet, hidden-cost framework, and warning-sign checklist, use the Managed SIEM pricing guide for Europe. This article keeps the commercial structure visible; the downloadable asset carries the detailed procurement tool.
Decide who operates the SIEM before comparing service prices
Compare in-house, hybrid managed, and fully managed SIEM across responsibilities, cost shape, staffing, tuning, monitoring, and response.
Download the SIEM deployment-model guideEuropean buyers should verify currency, tax, indexation, processing regions, remote access, retention, service hours, contract duties, and exit terms before accepting the total.
EUROPEAN PRICE BOUNDARY: A US-dollar public rate is evidence of a commercial meter, not a European offer. Ask for the regional SKU, tax treatment, data and support locations, service hours, and binding contract scope before putting it into the budget.
Reduce SIEM cost by removing low-value duplication, assigning data to the right tier, fixing broken sources, and matching capacity to measured use without dropping required detection or evidence.
Cost control is a security decision. Removing a noisy source can improve both budget and analyst focus. Removing the only record of privileged access saves money until the investigation needs it. Document the use case before changing the route.
Choose a meter that remains understandable as data, searches, entities, and response work grow. A quote is ready for decision when every data class, retention tier, service hour, human role, overage rule, and exit obligation has an owner and a price.
That discipline makes negotiation easier. It also prevents a low platform line from hiding a large operations bill or a managed-service fee from hiding the work that still stays with the customer.
Bring the quote, source list, and operating model
Q-Sec helps European teams assess log coverage, retention, detection tuning, monitoring, reporting, and response responsibilities. We can review what a proposal includes and which assumptions need evidence before a decision.
Discuss your SIEM proposal with Q-SecCost ranges from public cloud tiers under $1,000 monthly to custom enterprise contracts. The total depends on data, retention, platform meter, implementation, support, detection work, analyst coverage, and response scope.
There is no single standard. Cloud SIEM commonly uses ingestion, retention, workload, or credit meters. Other platforms price by events, servers, employees, agents, or a negotiated subscription.
Cloud SIEM can charge for ingestion, retained data, queries, egress, compute, automation, and AI features. The region, data tier, commitment, and overage rule also affect the bill.
It can cover platform use, onboarding, maintenance, tuning, monitoring, investigation, reporting, and response support. Buyers should name each activity, service window, limit, owner, and extra charge in the contract.
Some platforms use employees, users, agents, endpoints, servers, or other entities. Others charge by data, event rate, compute, or credits. Verify the counting definition and exclusions.
As checked on August 12, 2026, Blumira listed Detect at $12, Respond at $16, and Automate at $21 per knowledge worker monthly, in US dollars, with edition-specific onboarding terms.
Fortinet documentation describes FortiSIEM licensing based on events per second or GB used per day. A dependable public list rate was not available, so buyers need a configured quote.
Use the same source list, volumes, retention, users, capabilities, service hours, support, response scope, growth scenario, currency, and contract term. Then compare 12- and 36-month totals.