A SIEM is paid for by what you feed it — gigabytes a day, sources, or events per second — for as long as a regulator says you must keep it, and it only detects what someone tuned it to detect. The meter and the tuner decide the cost; the feature list does not.
Splunk Cloud is reported at roughly $1,000 per GB / day per year at 50 GB / day; ManageEngine Log360 starts at $300 a year priced by log sources. Same logs, two different bills — and the second does not grow with volume.
Already decided — before the PoC
Still yours to weigh
A place where the logs from everything — endpoints, firewalls, identity, cloud, mail, applications — land, are kept for as long as policy and the regulator require, and are searched and correlated: this login, from that country, after this alert, touching that server. The correlation rules are detections; the things they raise are cases; the team that reads them is the SOC. Log management is the first half (collect, keep, search); SIEM is the second (correlate, detect, investigate).
Three things cost money and the feature grid shows none of them: the meter (gigabytes a day, sources, events per second, or compute), the retention the regulator mandates, and the people who tune it. An untuned SIEM is an expensive log archive. A SOAR beside it automates whatever the detections raise — good or noise. The MDR guide is where the people come from if you do not have them.
The meter decides more than any feature
Ingest-based vs node-based vs flat pricing decides total cost more than any capability. Per-GB grows with volume forever; per-source and per-EPS flatten; workload compute sits in between. Estimate your daily volume and your retention before you read a datasheet.
Often confused withEndpoint Protection / XDR — both claim correlation, differently →·Managed Detection & Response — the people who read what the SIEM raises →·Cloud & Workload Security — where cloud logs join the picture →
Four terms this buyer confuses, and nothing more. They are adjacent and widening scopes — each one records more or acts more, costs more, and needs more people to run. None is a better version of another.
Log management
Collect, keep, search. The storage and the retention mandate live here; so does the first half of every meter. Splunk's platform, FortiAnalyzer, Log360's entry tiers. Not a SIEM until correlation, detections and cases sit on top.
SIEM
Log management plus correlation across sources, detection content, cases and compliance reporting. Vendor-neutral by design — it ingests everything you run. Splunk ES, Microsoft Sentinel, Log360, FortiSIEM, Falcon Next-Gen SIEM, SentinelOne AI SIEM, KUMA. Needs a tuner or it is an archive.
XDR
Correlation too — but from one vendor's sensors (endpoint, email, cloud, identity) inside their platform, pre-tuned by them. Narrower than a SIEM, far less work; the 'X' often means 'our stack'. Platform vendors sell XDR as the reason you do not need a SIEM; regulators and third-party logs often disagree. Cortex XSIAM is the most explicit version of that argument — it is sold as the SIEM replacement, not a companion.
SOAR
Automation and case management over whatever raises alerts: playbooks that enrich, contain, notify, close. Adjacent, not a SIEM — it acts on detections, it does not make them. Included at CrowdStrike and SentinelOne; separate at Splunk and Fortinet; workflow-grade inside Log360 and KUMA.
Six variables decide this purchase. The instrument tests the meter, deployment, automation and the India line; retention, content and who tunes it are prose because the honest answers are “your mandate”, “everyone ships content” and “your headcount”.
Ingest-based vs node-based vs flat pricing
Per GB / day grows with volume forever (Splunk, Microsoft Sentinel, CrowdStrike, SentinelOne, FortiSIEM's GB option); per source, device or EPS flattens (Log360, FortiSIEM, KUMA); workload compute (Splunk SVCs) sits between. Decides total cost more than any feature.
Log retention requirements
CERT-In's 180 days in India; RBI and SEBI CSCRF add theirs; your sector may add more. Retention × ingest is the cloud bill; retention × disk is the on-prem one.
Detection content out of the box vs built by you
Every SIEM ships content; the gap between a SIEM and an archive is who tunes it against your estate.
Who tunes it
The headcount that decides whether you bought a SIEM or a log archive. If nobody, the MDR guide — or a platform-native XDR — is the honest purchase.
SOAR and automation depth
Included (CrowdStrike Fusion, SentinelOne Hyperautomation), workflow-grade (Log360, FortiSIEM, KUMA) or a separate SKU (Splunk SOAR, FortiSOAR). Automation over untuned detections automates noise.
Deployment model and India residency
On-prem (Splunk Enterprise, Log360, FortiSIEM, FortiAnalyzer, KUMA) satisfies residency by definition; documented India cloud regions are FortiSIEM Cloud and SentinelOne (Mumbai) and Log360 Cloud; CrowdStrike is announced.
Set what holds for you. Products that fail a constraint fade with the reason on them; SOAR-only and log-only products fade when a chip is about the SIEM itself. Unset a chip and everything returns.
India
Pricing model
Deployment
What you are buying
Automation
Data volume
Retention mandates, detection content and India cloud regions are in the notes below, not chips — every product retains and ships content, and on-prem satisfies residency by definition.

per GB / day / year reported (platform $100–180 + ES $20–45) on Splunk Cloud or Enterprise; or workload pricing (SVCs ~$55–75k / yr each); ESCU detection content
SOCs that want the reference SIEM — the deepest search language, the largest content and integration ecosystem, on-prem or cloud — and have the engineers to run it.
The catch: The licence is the small number: ingest grows, SOAR is a separate product, and an untuned Splunk is the most expensive log archive there is; India cloud region not documented.

per GB / day / year reported; the data platform under ES, ITSI and Observability
Teams that need log search and analytics at scale without the SIEM application on top — yet.
The catch: Log management and analytics, not a SIEM until you add Enterprise Security (and its price); the same ingest economics apply.

per user / per action; playbooks and case management over ES or other SIEMs
SOCs automating triage and response around Splunk (or another SIEM).
The catch: A separate SKU from ES; automation only — it is not a SIEM; quote-only.

per GB ingested (East US): ~$4.30 pay-as-you-go, ~$2.96 effective at the 100 GB / day commitment, down to ~$2.05 at 50,000 GB / day; data lake tier ~$0.05 / GB ingest and ~$0.026 / GB / month storage at 6:1 compression; Azure Activity, Microsoft 365 audit logs and Defender XDR alerts ingest free; 90 days retention included; Central India, Jio India West and Jio India Central regions (data lake: Central India)
Microsoft 365 and Azure estates that want SIEM and XDR in one incident queue — where the first-party logs a SOC actually watches ingest free, and a data lake tier keeps the high-volume rest affordable.
The catch: The free ingest is Microsoft data only — noisy third-party sources (firewalls, proxies, NDR) pay full analytics rates and are where the bill escalates; SaaS on Azure only, so no on-prem or air-gapped option; SOAR is Logic Apps, billed separately; the Azure portal experience retires 31 March 2027, so the Defender portal migration is work you must scope; and note that while data is STORED in your workspace region, Microsoft documents that for workspaces outside Europe, Israel and China it PROCESSES customer data in a US region.

platform subscription priced by data ingested and scope; SOAR, threat intel and attack-surface management included rather than sold alongside; credits-style consumption
SOCs that have concluded the alert-triage model is the problem, and want AI-led detection and automated response to replace the SIEM rather than sit on top of it.
The catch: It is a platform bet, not a drop-in SIEM: the value depends on giving it your data and letting its automation act, which is a bigger operating change than a migration. Cloud-only, quote-only, and strongest inside a Palo Alto estate. Also the destination Palo Alto is migrating IBM QRadar SaaS customers to — useful if you are one, a consideration if you are not.

per-user / per-automation licensing; hundreds of product integrations; available as SaaS or self-hosted
SOCs automating repetitive investigation and response across a mixed security stack, over whichever SIEM they already run.
The catch: Automation only — it is not a SIEM and does not detect anything on its own; it acts on what your SIEM raises, so an untuned SIEM just gets its noise automated faster. Playbook engineering is real work and quote-only pricing.
a package (Standard / Enterprise / Enterprise Plus) bought against a data cap in GB; twelve months of hot retention included on every tier, longer billed separately; the older per-employee metering has been retired; no published US list price
Large or fast-growing log estates that want retention to stop being a budget argument — twelve months hot and searchable, with SOAR and Mandiant intelligence in the same platform rather than two more contracts.
The catch: SaaS on Google Cloud only — no on-premises or air-gapped option at all; YARA-L is a rule language your team must learn, with a smaller talent pool than SPL or KQL; and it asks for a platform commitment rather than slotting beside what you run. Quote-only, and any comparison written before 2026 describes the retired per-employee model.

reported ~$0.20 per GB of ANALYSED logs (also quoted as ~$5 per million analysed events, annual billing) on top of Log Management, which is billed separately by ingest and indexing; Flex Logs gives 3-15 months retention without rehydration and Cloud SIEM detections still run against it. Part of the Datadog Cloud Security platform, not a standalone SKU
Teams already running Datadog for observability who want threat detection on the logs they are collecting anyway — security signals correlated with the metrics and traces from the same incident, in one console.
The catch: It is a pillar of Datadog Cloud Security rather than a standalone SIEM, and it sits ON TOP of Log Management — so the Cloud SIEM line is the small half of the bill and the log ingestion and indexing underneath it is the real cost. Datadog’s per-module, per-unit billing is the thing buyers most often underestimate. Cloud-only, and weakest as a choice if you are not already a Datadog estate.
engine free and open source under AGPL; you pay for a subscription tier (Standard / Gold / Platinum / Enterprise). Self-managed on your own hardware including air-gapped; Elastic Cloud Hosted priced on provisioned resources (reported ~$99/mo Standard to ~$184/mo Enterprise at entry size, scaling with resources); Serverless from a reported ~$0.50/GB ingested. Not metered per GB/day on self-managed
Estates that need on-premises or air-gapped and find the cloud-only SIEMs are therefore not candidates at all — and teams already running Elasticsearch, for whom adopting it is closer to enabling than migrating.
The catch: Named a Visionary, not a Leader, in the 2025 Gartner MQ for SIEM: out-of-the-box detection content is narrower than Splunk’s and the security talent pool is smaller than for SPL or KQL, so expect to write more of your own rules. And the free tier is what makes teams underestimate the rest — running Elasticsearch well at scale is real engineering work unless you buy Elastic Cloud.

metered on MONITORED USERS plus sources plus modules rather than gigabytes ingested — quote-only, no published list. The cloud platform the July 2024 LogRhythm merger standardised on; LogRhythm’s competing Axon was retired in its favour
Estates where log volume is large relative to security headcount — the user-based meter is built for exactly that shape, and inverts the cost curve of ingest-priced SIEMs.
The catch: The meter cuts both ways: a large workforce generating modest logs pays more here than on an ingest-priced SIEM, so you must model both. Cloud-only (LogRhythm SIEM is the self-hosted half), the talent pool is smaller than for Splunk or Microsoft, and a two-platform portfolio after a merger deserves a written roadmap question.

self-hosted licensing, quote-only; you supply and run the infrastructure. Exclusively on-premises since the Exabeam merger — 1,100+ prebuilt correlation rules mapped to MITRE ATT&CK, with compliance reporting for ISO 27001, PCI DSS, HIPAA, SOX, NIST and CIS
Regulated estates where the mandate rules out SaaS entirely — self-hosting answers BOTH storage and processing residency by definition, because the data never leaves.
The catch: You buy, run, patch and capacity-plan the infrastructure, and under-sizing storage in year one is the commonest regret. It is also the self-hosted half of a two-platform portfolio after a merger, so ask for the roadmap in writing — Axon’s retirement shows this vendor consolidates where products overlap.

Per MONITORED ASSET rather than per GB ingested — a host with a workstation or server OS that reported data in the last 30 days — so a verbose log source does not move the licence. Three tiers: Essential (90-day log retention), Advanced and Ultimate (180 days); alert and audit data 13 months on all tiers. Rapid7’s own AWS Marketplace listings publish ~$21,479 / $33,682 / $46,149 for 12 months at up to 500 assets
Mid-market teams of roughly 500–5,000 endpoints with a security team in single figures and no detection-engineering function. Rapid7 writes and maintains the detection content itself, so the platform produces useful alerts in days rather than months — IDC named it a Leader for SIEM in the SMB segment specifically.
The catch: NO INDIA DATA REGION — five regions (US, Canada, Europe, Japan, Australia), so an Indian entity holds its logs in Tokyo or further. 13-month retention exceeds CERT-In’s 180 days on duration and fails on location. Cloud-only, so no air-gap at any price. Gartner rates it a CHALLENGER not a Leader, citing no supervised ML or custom deep-learning models; reports group by one field at a time; default cap of 200 custom detection rules.

A bespoke annual support contract on a platform whose licence stays free under GPLv2 — you are buying accountability, not software. Standard is 8/5 with an 8-hour response SLA and two health checks a year; Premium is 24/7 on critical issues with a 4-hour SLA and four health checks. Both include architecture guidance, upgrade planning, custom rules and decoders, and a named CSM. No published price
Organisations whose mandate rules out SaaS entirely — RBI, SEBI and IRDAI-regulated entities, government, and anyone contractually barred from sending security telemetry offshore — who have real platform-engineering capacity but need the vendor contractually accountable. Also estates above ~500 agents where per-agent cloud tiers stop making sense.
The catch: This is SUPPORT, not a managed service and definitively not MDR — you still run the cluster, own the upgrades and carry the pager, and nobody is watching your alerts. Conflating those three is the commonest disappointment here. The real cost is your infrastructure plus 0.3–0.5 FTE on top of the contract. And self-hosting lets you place the indexer in India — it does not do it for you.

Priced on monitored users and log sources rather than data volume, which is the structural difference from ingest-metered SIEM — your bill tracks headcount, not how chatty your firewall is. Sold as the behavioural analytics layer of New-Scale rather than a standalone SIEM
Teams whose threat model centres on credentials and people rather than malware — insider misuse and account takeover, where the attacker logs in correctly and does permitted things, so no rule fires. This is the gap rule-based detection structurally cannot close.
The catch: Not a SIEM on its own — it is the analytics layer and needs the platform underneath. Its output is bounded by your identity data: peer groups built on a stale directory mean little, and service accounts need owners before they need baselines. Models need 8–16 weeks observing normal before their output should be acted on, and teams that judge it in week two decide on bad evidence.

An agentic AI layer over the Exabeam platform rather than a separately deployable product; commercial terms are quoted with the platform
Existing Exabeam customers wanting AI-assisted triage and investigation summarisation on top of a platform they already run.
The catch: Emerging rather than proven — treat vendor productivity statistics as unaudited, and do not let an AI layer become the reason to buy the platform underneath it. It cannot analyse data the platform did not collect.

Included in the Unified Defense entitlement rather than metered separately, so the commercial question is the platform’s GB/day band rather than a per-user analytics licence
Organisations whose threat model centres on credentials and insiders, and who want behavioural scoring integrated with the SIEM rather than bolted alongside it — the analyst moves from a risk score to the raw events without switching tools.
The catch: Bounded by identity-data quality: peer groups are only as good as your directory, and service accounts need named owners first. Needs 8–16 weeks of baselining before its output is trustworthy. And it inherits the platform’s hard limit — no air-gapped or on-premises deployment in any configuration.

Included in the Unified Defense entitlement; retro-hunts historical data when new threat intelligence lands, which is why the platform’s 365 days of hot searchable data is the feature that makes it useful
Teams that want retrospective hunting automated rather than dependent on someone remembering to re-run a query after a disclosure — when an indicator becomes public, the sweep happens whether or not anyone thought of it.
The catch: It can only re-hunt data you actually ingested. Every source filtered out to control the GB/day bill is a source no future sweep can reach — and a blind sweep looks exactly like a clean one. That tension between cost control and retrospective coverage is real and deserves a deliberate decision rather than a default.

Quote-only. Gartner records the metering axes as all-inclusive per-asset and per-user pricing, ELAs, module-based, data-volume/EPS-based and platform-based. The per-asset and per-user axes break the dynamic where better logging costs more — but note the precision: they are offered AS AN ALTERNATIVE to per-GB, not instead of it, so which axis your order form specifies is the highest-value clause in the contract
The buyer a mandate has cornered. Gurucul was named a Leader in the 2025 Gartner MQ for SIEM (its first year, after three as a Visionary) AND — confirmed in Gartner’s own report text — runs SaaS, cloud or SELF-HOSTED. Of the six 2025 Leaders, the other five are cloud-only or cloud-only where the analytics run, so this is the only analyst-recognised Leader a regulated Indian buyer under an on-premises mandate can actually deploy. Behavioural analytics is the founding capability from 2010 rather than an acquisition, and Pune has been the engineering base since 2013.
The catch: A bootstrapped sub-$100M boutique competing with Microsoft, Google and Cisco — no investor pressure, but no war chest either, and vendor scale is a question your risk function should answer deliberately. Analyst strength is Gartner-SPECIFIC: absent from the June 2025 Forrester Wave where the other five Leaders all appear, and its KuppingerCole Leader award is the 2024 report. We found no evidence of a vendor-run India data region — the India answer is self-hosting. And a genuine AIR-GAP is marketed but UNVERIFIED; self-hosted is not the same thing, so get it in writing.

Part of the REVEAL platform entitlement rather than a separate meter, so the commercial question is the platform’s pricing axis rather than a per-user analytics licence
Threat models centred on credentials and people rather than malware. This is the capability Gurucul was founded on in 2010 — it built the analytics first and grew a SIEM around them, which is the reverse of how most of this market was assembled. The practical consequence is that a risk score and the events that produced it live on one platform, so an analyst investigating a borderline score clicks through rather than filing an export request.
The catch: Bounded by identity-data quality — peer groups built on a stale directory produce confident nonsense, and service accounts need named owners before they need baselines. Models also need WEEKS observing normal before their output should be acted on; teams judging alert quality in week two are deciding on bad evidence. Neither is a product fault and both are true of every UEBA product, but both are where deployments actually fail. Not sold standalone.

Part of the REVEAL platform rather than a separate purchase with its own meter — no second data lake sitting beside your SIEM, and one query surface rather than two
Heterogeneous estates assembled over a decade, where real telemetry sits across an EDR chosen three years ago, a firewall estate from a different decision and an identity provider nobody will migrate off. Open XDR ingests from what you already run rather than demanding its own agent everywhere — which is why so many XDR pilots stall — then layers identity and behavioural analytics on top.
The catch: Test the openness rather than believing it. Every XDR vendor claims it, and rich normalised telemetry and forwarded alerts are BOTH called integrations — only one supports an investigation. Check your two or three most depended-on tools during the PoC. Also: it is not MDR (nobody watches your alerts), not an EDR (it consumes endpoint telemetry, it does not prevent), and not sold standalone. Single-vendor stacks get deeper native integration from CrowdStrike or Microsoft.

Part of the REVEAL platform entitlement; shares one identity model with the SIEM and UEBA, so access risk and threat detection reason over the same picture of who your users are
BFSI buyers who can list who has access but cannot say which access is DANGEROUS. It scores entitlements and access patterns for risk rather than cataloguing them — excess privilege, dormant high-risk access, and the permissions that accumulate across a decade of role changes and never get removed. That last one is the real problem: no individual grant was wrong, and the aggregate is invisible to a review that examines grants one at a time. Maps onto RBI and SEBI access-review evidence.
The catch: This is ANALYTICS, NOT IDENTITY GOVERNANCE, and the categories are adjacent enough that vendors blur them. It tells you what access is risky and evidences it. It does not provision or deprovision accounts, does not run joiner-mover-leaver workflow, and does not own certification campaigns end to end. It complements SailPoint, Saviynt or One Identity rather than replacing one — and if you have no governance platform at all, fix provisioning first or you will get an accurate description of chaos.

The platform itself is free under GPLv2 — no agent cap, no ingestion metering, no feature paywall, and no enterprise edition holding detection back. What is sold is operation: Wazuh Cloud from a reported ~$571/mo for 100 agents (1 month indexed, 3 months archive), ~$923 for 250 (3 months indexed, 1 year archive), ~$1,467 for 500. Professional Support is a bespoke annual contract with no published price. Note that retention forces the tier more often than agent count does
Two quite different buyers. Estates where an ingestion meter is currently shaping what gets collected — removing that meter is the strongest single argument in the category. And regulated Indian buyers whose mandate rules out SaaS entirely: Wazuh self-hosts on-premises or fully air-gapped, with documented offline installation and offline CVE feeds, which is where the cloud-only SIEMs simply cannot go at any price.
The catch: The licence is free; the system is not. Infrastructure plus 0.3–0.5 FTE means self-hosting lands around ₹8–11 lakh a year at 250 agents — roughly LEVEL with the Cloud subscription, not the saving people assume. Also: no machine-learning-driven detections and a simpler query model than Elastic; real tuning effort in week one because collection is broad; and Wazuh does not sell MDR at all. Wazuh Cloud has no publicly documented India region — confirm in writing before trialling, or self-host.

GB/day in tiered bands, hybrid commitment plus pay-as-you-go with pre-negotiated overages — but note the licensing terms default overage to 120% of your GB/day rate where the order form specifies no rate. 365 days of hot searchable data included as standard; Data Pipeline Manager flexes one entitlement across Analytics 1.0x, Investigation 0.5x and Basic 0.25x tiers
Cloud-accepting estates that want retention solved rather than negotiated — a full year of hot data means the investigation reaching back eleven months is a query, not a restore ticket — and that value behavioural detection enough to build around it.
The catch: No air-gapped or on-premises deployment in ANY configuration. BYO-AWS and BYO-Snowflake let your own account hold the data lake, which can answer an India-residency obligation, but the analytics control plane is always Securonix’s cloud — so an air-gap mandate rules it out entirely. Also: three CEOs in two years, and the 120% default overage is the commonest avoidable cost in the contract.

per year entry tiers (Basic $300 · Standard $995 · Professional $1,995; MSSP $194 / mo); priced by log sources, unlimited users; Zoho-hosted cloud with India data centres
Mid-market and regulated Indian estates that want a SIEM with UEBA and compliance reports priced by sources, not gigabytes, from an India-built vendor.
The catch: Predictable and cheap until the source count climbs; SOAR is built-in workflows rather than a full automation platform; documented scale tops out below the hyperscale SIEMs.

per device / EPS or per GB / day subscription; appliance, VM or FortiSIEM Cloud (Mumbai region); FortiSOAR separate
Fortinet Security Fabric estates that want SIEM plus CMDB-style asset context, on appliances or in a Mumbai-hosted cloud.
The catch: Full SOAR is FortiSOAR (separate); strongest inside a Fortinet estate; quote-only across several meters.

appliance / VM / cloud licensed by devices and GB / day; Fortinet-centric logging, analytics and playbooks
Fortinet estates that need fabric logging, reporting and automation before (or instead of) a full SIEM.
The catch: Log analytics for the Fortinet fabric — third-party breadth and SIEM correlation are FortiSIEM's job.

AWS Marketplace pay-as-you-go $5.95 / GB (13-month retention); list reported ~$2,700 per GB / day / year for third-party data; 10 GB / day of third-party data included with Falcon Insight; Fusion SOAR included
Falcon estates that want SIEM on the data already in the platform, with third-party ingestion priced per GB and SOAR in the box.
The catch: Cloud-only; third-party ingest beyond the included 10 GB / day is where the bill lives; India in-country cloud announced, not yet documented live.

agentic automation over Falcon Next-Gen SIEM and Fusion workflows
Falcon SOCs pushing triage and response automation beyond playbooks.
The catch: Falcon-only; quote-only; not a SIEM on its own.

consumption per GB / day of ingested data (rates not published); Singularity Data Lake; Hyperautomation (SOAR) and Purple AI included in platform packages; Mumbai region
SentinelOne estates that want SIEM on the Singularity Data Lake with automation and an AI analyst in the same console, with a Mumbai data region.
The catch: Rates are not published — the per-GB consumption is a quote; cloud-only; strongest when SentinelOne is already the agent.

licensed by events per second (EPS); on-prem; documented 300,000+ EPS per correlation node
Estates that want a high-throughput on-prem SIEM priced by EPS rather than gigabytes, with Kaspersky's detection content.
The catch: Procurement-sensitive in some sectors and countries (check your regulator); automation is playbook-grade rather than a full SOAR; quote-only.
India-built vendorRules out Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Splunk SOAR, Microsoft Sentinel, Palo Alto Cortex XSIAM, Palo Alto Cortex XSOAR, Google Security Operations, Datadog Cloud SIEM, Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support, Exabeam New-Scale Analytics (UEBA), Exabeam Nova (agentic AI), Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, Securonix Unified Defense SIEM, Fortinet FortiSIEM, Fortinet FortiAnalyzer, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA) — not an India-built vendor. That leaves ManageEngine Log360 (on-prem) / Log360 Cloud.
Ingest-based pricingRules out Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR, Palo Alto Cortex XSOAR, Exabeam Nova (agentic AI) and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM; Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Exabeam New-Scale Analytics (UEBA), Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, ManageEngine Log360 (on-prem) / Log360 Cloud and Kaspersky SIEM (KUMA) — priced per source / EPS, not by data volume; Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support and Wazuh — no ingestion meter at all; the free core is priced by agent count for the managed edition. That leaves Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Securonix UEBA, Securonix Autonomous Threat Sweeper, Securonix Unified Defense SIEM, Fortinet FortiSIEM, CrowdStrike Falcon Next-Gen SIEM and SentinelOne Singularity AI SIEM. It flags Splunk Enterprise Security — Also offers workload (compute) pricing and Fortinet FortiSIEM — GB / day subscription is one of its meters; device / EPS is the other — marked on the cards, not removed.
Per source / device / EPS pricingRules out Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Securonix Unified Defense SIEM, CrowdStrike Falcon Next-Gen SIEM and SentinelOne Singularity AI SIEM — ingest or workload-compute pricing, not per source; Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR, Palo Alto Cortex XSOAR, Exabeam Nova (agentic AI) and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM; Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support and Wazuh — priced per agent count, not per source; and the core licence is free regardless. That leaves Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Exabeam New-Scale Analytics (UEBA), ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM and Kaspersky SIEM (KUMA). It flags Fortinet FortiSIEM — Device / EPS meter available; GB / day is the other — marked on the cards, not removed.
Self-hosted or on-premRules out Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Exabeam New-Scale SIEM, Rapid7 Incident Command (formerly InsightIDR), Exabeam New-Scale Analytics (UEBA), Exabeam Nova (agentic AI), Securonix UEBA, Securonix Autonomous Threat Sweeper, Securonix Unified Defense SIEM, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR and SentinelOne Singularity AI SIEM — cloud-only. That leaves Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Splunk SOAR, Palo Alto Cortex XSOAR, Elastic Security, LogRhythm SIEM, Wazuh Professional Support, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, Fortinet FortiAnalyzer and Kaspersky SIEM (KUMA).
A full SIEMRules out Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR, Palo Alto Cortex XSOAR, Exabeam Nova (agentic AI) and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM. That leaves Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support, Exabeam New-Scale Analytics (UEBA), Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, Securonix Unified Defense SIEM, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, CrowdStrike Falcon Next-Gen SIEM, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA).
SOAR includedRules out Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Microsoft Sentinel and Exabeam New-Scale Analytics (UEBA) — SOAR is a separate product from this vendor. That leaves Splunk SOAR, Palo Alto Cortex XSIAM, Palo Alto Cortex XSOAR, Google Security Operations, Datadog Cloud SIEM, Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support, Exabeam Nova (agentic AI), Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, Securonix Unified Defense SIEM, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, Fortinet FortiAnalyzer, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA). It flags Elastic Security — Built-in workflows / playbooks rather than a full SOAR platform, Exabeam New-Scale SIEM — Built-in workflows / playbooks rather than a full SOAR platform, LogRhythm SIEM — Built-in workflows / playbooks rather than a full SOAR platform, ManageEngine Log360 (on-prem) / Log360 Cloud — Built-in workflows / playbooks rather than a full SOAR platform, Fortinet FortiSIEM — Built-in workflows / playbooks rather than a full SOAR platform, Fortinet FortiAnalyzer — Built-in workflows / playbooks rather than a full SOAR platform and Kaspersky SIEM (KUMA) — Built-in workflows / playbooks rather than a full SOAR platform — marked on the cards, not removed.
Above 1 TB / dayRules nothing out on published terms. It flags Exabeam Nova (agentic AI) — Documented scale is mid-market, Gurucul Open XDR — Documented scale is mid-market and ManageEngine Log360 (on-prem) / Log360 Cloud — Documented scale is mid-market — marked on the cards, not removed.
India data residency (cloud)Documented: FortiSIEM Cloud (Mumbai region), SentinelOne Singularity (Mumbai), ManageEngine Log360 Cloud (Zoho India data centres), Microsoft Sentinel (Central India, Jio India West, Jio India Central). Sentinel is the one to read carefully: it STORES data in the workspace region, but Microsoft documents that for workspaces outside Europe, Israel and China it PROCESSES customer data in a US region — storage residency is not processing residency, and which one your regulator means is worth settling before the PoC. CrowdStrike's India in-country cloud is announced (January 2026), not yet documented live; Splunk Cloud publishes no Mumbai region; Kaspersky SIEM is on-prem. Nothing is ruled out on it — on-prem satisfies residency by definition, which is half the reason Log360, FortiSIEM and KUMA are on Indian shortlists.
Detection content out of the box vs built by youRules nothing out: every SIEM here ships detection content (Splunk ESCU, Log360 correlation rules and UEBA, FortiSIEM rules, Falcon detections, SentinelOne content, Kaspersky rules). What differs is who tunes it against your estate — and an untuned SIEM is an expensive log archive. The tuning headcount is the variable, and it is prose because it is yours.
Log retention mandatesNot a chip — retention is a configuration and a storage bill, not a capability: CERT-In's 2022 directions require 180 days of ICT logs in India; RBI and SEBI CSCRF add their own. Every product here retains; what you pay is ingest × retention (cloud) or disk (on-prem). Confirm the mandate before the ingest estimate, not at the audit.
Each shortlist begins with how you will pay (gigabytes, sources, EPS) and where the logs may live. The feature list comes after.
Why: Per-source or per-EPS pricing, on-prem or an India-hosted cloud, compliance reports for the Indian regulators — and an India-built vendor in Log360.
The trade-off: Documented scale tops out below the hyperscale SIEMs; SOAR is built-in workflows rather than a platform; KUMA carries procurement caveats in some sectors.
Why: Falcon data is already in the platform; 10 GB / day of third-party data is included with Insight, Fusion SOAR is in the box, and the per-GB meter is published on AWS Marketplace.
The trade-off: Third-party ingest beyond the included volume is the bill; cloud-only; India in-country cloud announced, not yet live.
Why: Singularity Data Lake with AI SIEM, Hyperautomation and Purple AI in the same console, and a Mumbai data region.
The trade-off: Consumption rates are not published — the per-GB price is a quote; one survivor here is the platform answer, not a gap. Splunk or Log360 remain the vendor-neutral alternatives.
Why: Azure Activity, Microsoft 365 audit logs and Defender XDR alerts ingest free, so much of what the SOC watches costs nothing to collect; Sentinel and Defender XDR alerts land in one incident queue in the Defender portal; the data lake tier keeps high-volume logs at ~$0.05 / GB.
The trade-off: One survivor is the estate answer, not a gap — and it only holds while your volume is Microsoft-shaped: third-party firewall and proxy logs pay full analytics rates. Cloud-only, so on-prem residency needs Log360 or FortiSIEM instead — and Sentinel stores in-region but processes customer data in the US for Indian workspaces. Budget the 31 March 2027 Defender portal migration.
Why: These are sold as replacements for the SIEM-led SOC rather than better versions of it — AI-led detection that stitches signals into a few high-fidelity incidents, with automation included rather than bought beside it.
The trade-off: You are buying an operating model, not a log store: the value only lands if you give the platform your data and let its automation act. All three are cloud-only and quote-only, and each is strongest inside its own vendor’s estate.
Why: Threat detection on logs you are already collecting and paying to index, with security signals correlated against the metrics and traces from the same incident — and Flex Logs keeps 3-15 months searchable without rehydration while detections still run against it.
The trade-off: One survivor is the estate answer, not a gap. Cloud SIEM is priced on analysed logs on top of Log Management, so the ingestion and indexing underneath is the real bill — Datadog’s per-module billing is what buyers underestimate. If you are not already a Datadog estate, the vendor-neutral SIEMs are the honest comparison.
Why: Splunk ES is the reference — SPL, ESCU content, the integration ecosystem — with SOAR alongside; Falcon Next-Gen SIEM is the platform-native alternative for Falcon estates.
The trade-off: Splunk's ingest economics and the tuning headcount are the contract; without engineers it is the most expensive archive in security.
Why: FortiAnalyzer for fabric logging and playbooks; FortiSIEM for correlation, CMDB context and third-party sources, on appliances or in the Mumbai cloud region.
The trade-off: Strongest inside Fortinet; full SOAR is FortiSOAR, separate; several meters to match at quote.
Why: Search and retention at scale without the SIEM application's price — Splunk's platform, FortiAnalyzer for Fortinet estates, Log360's entry tiers for everyone else.
The trade-off: A log platform is not a SIEM until correlation, detections and cases are on it — and the ingest meter is the same.
Why: Google SecOps includes twelve months of hot, searchable retention in every package, so the keep-or-delete decision leaves the budget conversation; Log360 and KUMA get there differently, by not metering gigabytes at all.
The trade-off: Google SecOps is cloud-only on Google Cloud and quote-only, and beyond twelve months retention is billed by volume again. The per-source and per-EPS meters trade volume risk for scale ceilings.
Why: Meters that are not gigabytes: per source (Log360), per EPS (KUMA), per device (FortiSIEM) — the cost curve flattens as volume grows.
The trade-off: Predictable meters trade volume risk for scale ceilings and narrower ecosystems; the honest alternative is filtering and tiering data before a per-GB SIEM, not abandoning it.
Why: Splunk SOAR over ES or another SIEM; Charlotte Agentic SOAR and SentinelOne Hyperautomation included with their platforms.
The trade-off: Automation needs the detections to be good first — SOAR over an untuned SIEM automates noise.
Every SIEM quote is a bet on your data growth. The meter decides who wins that bet.
Meter 1
Ingest — per GB / day
You pay for volume, forever, times retention. Splunk Cloud is reported near $1,000 per GB / day / year at 50 GB / day (tapering with commit); CrowdStrike publishes $5.95 / GB pay-as-you-go with 13-month retention and includes 10 GB / day of third-party data with Falcon Insight; SentinelOne meters per GB but does not publish rates. Microsoft Sentinel publishes ~$4.30 / GB pay-as-you-go falling to ~$2.96 at a 100 GB / day commitment — and ingests Microsoft’s own logs free, which is why a Microsoft estate’s bill is far below its raw volume. Year-one cheap, year-three expensive unless you filter at the source.
Meter 2
Workload — compute (SVCs)
Splunk's alternative: pay for search and indexing compute (~$55–75k per SVC per year reported) rather than volume. Flattens the data bet, moves it to a usage bet; suits estates that ingest a lot and search predictably.
Meter 3
Sources, devices, EPS
Log360 per log source with unlimited users ($300 → $1,995 / year entry tiers); FortiSIEM per device / EPS or per GB / day; KUMA per EPS. The curve flattens as volume grows; the trade is a scale ceiling and a narrower ecosystem.
Meter 4
Flat / included
SOAR included with a platform (Fusion, Hyperautomation), or the SIEM sold as part of a platform commit. The cheapest line is the one you already pay for — until the third-party data arrives.
Retention and residency
The mandate is a storage bill with a regulator attached.
Who tunes it
An untuned SIEM is an expensive log archive.
SIEMs scale by data, not by seats. Each step changes which meter survives and how many people the detections need.
The meter is the constraint
Put this in your PoC
Estimate your real volume from a week of sources; price it at 180 days and at your mandate; compare per-GB against per-source with the same sources.
Tuning and filtering are the constraint
Put this in your PoC
Measure alerts per analyst per day for a month; ask each vendor what the bill is with 30% of volume filtered or tiered.
Architecture and sovereignty are the constraint
Put this in your PoC
Load-test your peak EPS; confirm region sharding and retention tiers in writing; price the exit.
Splunk, CrowdStrike, SentinelOne, FortiSIEM and KUMA document very large deployments (KUMA 300,000+ EPS per node); Log360’s documented scale is mid-market — flagged, not ruled out. Where a specific console strains for your volume: [TechBag to confirm].
Sources re-point in weeks. The detections, the parsers, the dashboards and the years of logs under a retention mandate are what make a SIEM migration a year, not a quarter.
Sources and collectors
Re-point syslog, agents and API connectors; re-parse each source's format for the new platform. Weeks per estate, scriptable in parts.
Detections and dashboards
Every correlation rule, every tuned exclusion and every compliance dashboard is rewritten in the new language — SPL is not KQL is not Log360's rules. The year.
Retained logs
Logs under a mandate must stay searchable for the mandate; either keep the old SIEM in read-only for the period or export and re-index. Both cost.
Playbooks and integrations
SOAR playbooks, ticketing and MDR integrations are rebuilt; the MDR may have to re-onboard the new SIEM as a source.
Detection-rewrite months and retained-log strategy for your estate: [TechBag to confirm] — TechBag scopes it from your rule count, sources and mandate.
What you may already hold, the meters compared in USD and INR at three daily volumes, and what the licence leaves out — retention, tuning, and the exit.
Four places a SIEM — or enough of one — may already be on your invoice.
If the logs you must keep are already sitting somewhere you pay for, we say so — and then price what it costs to keep them for the mandate.
Reported and published rates per meter (INR for scale), then worked at 50 / 500 / 5,000 GB a day. Per-source and per-EPS products cannot be expressed per gigabyte — the grid says so rather than inventing a conversion.
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
Per-GB meters quote a retention (CrowdStrike 13 months PAYG; Splunk by tier); the mandate may want 180 days hot and years cold. Retention × volume is the part of the bill that grows after year one — and it multiplies at renewal.
Detection engineering is a role at 2,000 endpoints and a team at a TB / day. Budget it beside the licence or buy the people through the MDR guide; a SIEM nobody tunes is an archive with a dashboard.
Leaving means rewriting every detection in the new language and keeping the old logs searchable for the mandate — the switching-cost section. Your rule count and months: [TechBag to confirm].
Documented meter behaviour and programme failures, cross-checked against TechBag engagements before any becomes a named case. Most are visible in the quote if you know where to look.
Ingest costs multiplying after year one
Volume grew, retention stayed, the per-GB meter did what it said. Filtering and tiering at the source were never designed in.
Retention mandates discovered at audit
CERT-In's 180 days, RBI's and SEBI's retention — found when the regulator asked, after the cheapest retention tier was chosen.
No engineering capacity to write detections
Content shipped; nobody mapped sources or suppressed noise; the SIEM became a log archive with an invoice.
Alert fatigue at volume
Untuned detections at 500 GB a day outran the team; real alerts drowned. A staffing problem bought as a tool.
Migration meaning every detection rule rewritten
Years of tuning in one vendor's language; the new platform started empty. The exit nobody priced.
'Included' SIEM that wasn't
The platform's SIEM was free for the platform's data; the firewall and identity logs were the bill. Name the third-party volume before signing.
XDR sold as a SIEM replacement
Pre-tuned correlation from one vendor's sensors covered their stack; the regulator wanted everything, retained in India. Different scope.
SOAR over untuned detections
Playbooks automated the noise faster. Automate after the detections are good.
Vendor-neutral. No gated content.