SIEM Sizing Calculator: Ingest, Retention, and Hot vs Cold Storage Cost
This free SIEM sizing calculator estimates annual license and storage cost from your events-per-second rate, daily log ingest volume, and retention requirement, split across hot (searchable) and cold (archive) storage tiers. It is built for security engineers and IT directors scoping a new SIEM deployment or re-evaluating an existing one before a contract renewal. Enter your current or projected ingest volume and retention window, and the tool returns annual license cost, storage cost by tier, and total annual spend, the exact numbers vendors rarely make easy to estimate up front.
Your numbers
Peak sustained event rate across all log sources; many vendors still price partly on EPS tiers.
Raw log volume ingested per day before compression, across all connected sources.
Total days logs must be retained; many compliance frameworks require 1-7 years.
Days kept in fast, immediately searchable storage; the remainder moves to cheaper cold/archive tiers.
Blended per-GB ingest license cost; enterprise SIEM platforms commonly run $2-$6/GB depending on volume tier.
Cost of fast, searchable storage per GB per month.
Cost of cold or archive-tier storage per GB per month for data beyond the hot retention window.
Your results
Planning estimate only. Actual SIEM pricing varies widely by vendor (ingest-based, EPS-based, or user-based) and by negotiated enterprise agreement discounts. Confirm against a specific vendor quote before budgeting.
Get your SIEM sizing benchmark
We will email you a detailed license and storage cost projection across a 3-year growth curve, plus a hot/cold tier configuration checklist, and a Netray security architect will follow up with a 30-minute review.
No spam. Your results stay private. Unsubscribe anytime.
Why SIEM cost surprises so many teams
SIEM pricing models vary by vendor, ingest-based (per GB), EPS-based, or per-user, and ingest volume tends to grow faster than teams expect as new log sources (cloud infrastructure, SaaS applications, endpoint telemetry) get onboarded. A SIEM sized correctly at go-live frequently costs 40 to 60 percent more by year two simply from added log sources, not because the original sizing was wrong.
- Cloud infrastructure logging (especially detailed VPC flow logs) is the most common source of unplanned ingest growth.
- EPS-based pricing tiers can create sudden cost jumps at tier boundaries; model your growth curve, not just current state.
- Retention requirements are often set by compliance (PCI, HIPAA, CMMC) rather than security preference, so confirm the true minimum before sizing.
Hot vs cold storage: the lever most teams underuse
Not all retained data needs to be instantly searchable. Most investigations and threat hunting queries target the last 30 to 90 days; older data is retained primarily for compliance and forensic purposes and can sit in cheaper archive-tier storage that takes longer to rehydrate for search. Splitting retention into a hot tier for active investigation and a cold tier for compliance archival typically cuts total storage cost by 60 to 80 percent versus keeping everything hot for the full retention period.
- A 90-day hot window covers the vast majority of real-world investigation and threat hunting needs.
- Cold storage costs 80 to 95 percent less per GB than hot, searchable storage.
- Confirm your SIEM platform's cold-tier rehydration time before committing to a tier split; some archival options take hours to search.
EPS is a sizing signal, not a cost driver by itself
Events per second matters for real-time correlation and alerting performance, not directly for storage cost, which is driven by ingest volume in GB. Use EPS to validate that your SIEM's processing tier can keep up with peak load without alert delay, and use GB/day ingest for the actual license and storage cost math. Vendors that price purely on EPS tiers can create cost cliffs at specific thresholds; know your peak EPS precisely before signing a contract.
How Netray helps you size and deploy
Netray helps manufacturers and defense contractors right-size SIEM deployments against actual log source growth, including on-prem and air-gapped SIEM architectures where cloud-hosted platforms are not an option for classified or ITAR-controlled environments. We benchmark your ingest projections against a 2-3 year growth curve before you sign a contract sized only for today.
Frequently Asked Questions
How much does an enterprise SIEM cost per year?
For a mid-size enterprise ingesting 200-500 GB per day with a 1-year hot retention window, total annual cost including license and storage typically runs $400,000 to $1.2 million depending on vendor and negotiated pricing. Ingest-based pricing at $2-$6 per GB is the dominant model; EPS-based and per-user pricing exist but are less common for larger deployments.
What is a reasonable SIEM retention period?
Most compliance frameworks require 1 year minimum (PCI DSS), with some requiring longer: CMMC and defense contracts commonly require 1-3 years, and certain financial and healthcare regulations require up to 7 years. Set retention based on your specific compliance obligations first, then layer hot versus cold storage strategy on top to control cost.
Should I keep all retained logs in hot, searchable storage?
No, for most organizations. The majority of investigation queries target the last 30-90 days of data; older data retained for compliance rarely needs instant search. Splitting retention into a 90-day hot tier and a cold archive tier for the remainder typically cuts total storage cost by 60-80 percent with minimal impact on real-world investigation speed.
How do I estimate my daily log ingest volume before deploying a SIEM?
Run a discovery or trial ingest for 1-2 weeks across your planned log sources (firewalls, endpoints, cloud infrastructure, applications) using your SIEM vendor's sizing tool or a temporary log collector, then extrapolate to a full day and add 20-30 percent headroom for sources you plan to onboard later. Cloud infrastructure and endpoint telemetry are the most common sources teams underestimate.
Get a SIEM sizing benchmark that accounts for your log source growth over the next 24 months.
Related Tools
Security Operations Center Cost Calculator
Estimate in-house SOC staffing and tooling cost by analyst tier and coverage model, then compare it directly against an MDR (managed detection and response) monthly fee.
ERP OperationsVulnerability Remediation SLA Calculator
Estimate how many weeks it will take to burn down your priority vulnerability backlog given current findings volume, engineer capacity, and new findings arriving each week.
ERP OperationsIdentity Access Management ROI Calculator
Estimate the annual ROI of an IAM platform from automated provisioning time saved, password reset ticket reduction, and estimated breach risk reduction.
Go Deeper
ERP Data Warehouse Architecture
ERP data warehouse architecture: landing, staging, and star schema layers, CDC extraction from SyteLine and Infor LN, plus governance for manufacturers.
ERP Cloud Security: Best Practices for Manufacturers
Secure your cloud ERP deployment. Access controls, data encryption, compliance frameworks, and monitoring strategies for Infor CloudSuite environments.
Audit Trails for AI Decisions: A Compliance Guide
Build audit trails for AI decisions that satisfy internal and external auditors: what to log, how long to retain it, and how to prove provenance.