SIEM pricing is a data problem, not a software problem. The licence is the small number.

A SIEM is paid for by what you feed it — gigabytes a day, sources, or events per second — for as long as a regulator says you must keep it, and it only detects what someone tuned it to detect. The meter and the tuner decide the cost; the feature list does not.

Splunk Cloud is reported at roughly $1,000 per GB / day per year at 50 GB / day; ManageEngine Log360 starts at $300 a year priced by log sources. Same logs, two different bills — and the second does not grow with volume.

Already decided — before the PoC

Your retention mandateCERT-In 180 days; RBI, SEBI add theirs
Your daily log volumedecides whether per-GB is survivable
Who will write detectionsdecides whether it is a SIEM or an archive

Still yours to weigh

The meterGB / day · sources · EPS · workload
Deploymenton-prem · cloud · India region
AutomationSOAR in the box, or beside it
If you’ve never bought one

What SIEM and log management actually is

A place where the logs from everything — endpoints, firewalls, identity, cloud, mail, applications — land, are kept for as long as policy and the regulator require, and are searched and correlated: this login, from that country, after this alert, touching that server. The correlation rules are detections; the things they raise are cases; the team that reads them is the SOC. Log management is the first half (collect, keep, search); SIEM is the second (correlate, detect, investigate).

Three things cost money and the feature grid shows none of them: the meter (gigabytes a day, sources, events per second, or compute), the retention the regulator mandates, and the people who tune it. An untuned SIEM is an expensive log archive. A SOAR beside it automates whatever the detections raise — good or noise. The MDR guide is where the people come from if you do not have them.

The meter decides more than any feature

Ingest-based vs node-based vs flat pricing decides total cost more than any capability. Per-GB grows with volume forever; per-source and per-EPS flatten; workload compute sits in between. Estimate your daily volume and your retention before you read a datasheet.

Often confused withEndpoint Protection / XDR — both claim correlation, differently·Managed Detection & Response — the people who read what the SIEM raises·Cloud & Workload Security — where cloud logs join the picture

The six routes of security — and which one is yours

Boundary — the terms this buyer confuses

SIEM vs XDR vs log management · SIEM vs SOAR

Four terms this buyer confuses, and nothing more. They are adjacent and widening scopes — each one records more or acts more, costs more, and needs more people to run. None is a better version of another.

Log management

Collect, keep, search. The storage and the retention mandate live here; so does the first half of every meter. Splunk's platform, FortiAnalyzer, Log360's entry tiers. Not a SIEM until correlation, detections and cases sit on top.

SIEM

Log management plus correlation across sources, detection content, cases and compliance reporting. Vendor-neutral by design — it ingests everything you run. Splunk ES, Microsoft Sentinel, Log360, FortiSIEM, Falcon Next-Gen SIEM, SentinelOne AI SIEM, KUMA. Needs a tuner or it is an archive.

XDR

Correlation too — but from one vendor's sensors (endpoint, email, cloud, identity) inside their platform, pre-tuned by them. Narrower than a SIEM, far less work; the 'X' often means 'our stack'. Platform vendors sell XDR as the reason you do not need a SIEM; regulators and third-party logs often disagree. Cortex XSIAM is the most explicit version of that argument — it is sold as the SIEM replacement, not a companion.

SOAR

Automation and case management over whatever raises alerts: playbooks that enrich, contain, notify, close. Adjacent, not a SIEM — it acts on detections, it does not make them. Included at CrowdStrike and SentinelOne; separate at Splunk and Fortinet; workflow-grade inside Log360 and KUMA.

Widening scopes, not tiers. Log management → SIEM adds correlation and detections; XDR is a vendor’s pre-tuned subset; SOAR acts on what either raises. Broader ingests more, costs more per gigabyte and per engineer, and only earns it if someone tunes the detections. Buy the scope your people can run — and let the MDR guide supply the people if they do not exist.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Six variables decide this purchase. The instrument tests the meter, deployment, automation and the India line; retention, content and who tunes it are prose because the honest answers are “your mandate”, “everyone ships content” and “your headcount”.

01

Ingest-based vs node-based vs flat pricing

Per GB / day grows with volume forever (Splunk, Microsoft Sentinel, CrowdStrike, SentinelOne, FortiSIEM's GB option); per source, device or EPS flattens (Log360, FortiSIEM, KUMA); workload compute (Splunk SVCs) sits between. Decides total cost more than any feature.

02

Log retention requirements

CERT-In's 180 days in India; RBI and SEBI CSCRF add theirs; your sector may add more. Retention × ingest is the cloud bill; retention × disk is the on-prem one.

03

Detection content out of the box vs built by you

Every SIEM ships content; the gap between a SIEM and an archive is who tunes it against your estate.

04

Who tunes it

The headcount that decides whether you bought a SIEM or a log archive. If nobody, the MDR guide — or a platform-native XDR — is the honest purchase.

05

SOAR and automation depth

Included (CrowdStrike Fusion, SentinelOne Hyperautomation), workflow-grade (Log360, FortiSIEM, KUMA) or a separate SKU (Splunk SOAR, FortiSOAR). Automation over untuned detections automates noise.

06

Deployment model and India residency

On-prem (Splunk Enterprise, Log360, FortiSIEM, FortiAnalyzer, KUMA) satisfies residency by definition; documented India cloud regions are FortiSIEM Cloud and SentinelOne (Mumbai) and Log360 Cloud; CrowdStrike is announced.

The narrowing instrument · the reasoning is the product

Narrow 30 products to your shortlist

Set what holds for you. Products that fail a constraint fade with the reason on them; SOAR-only and log-only products fade when a chip is about the SIEM itself. Unset a chip and everything returns.

India

Pricing model

Deployment

What you are buying

Automation

Data volume

Retention mandates, detection content and India cloud regions are in the notes below, not chips — every product retains and ships content, and on-prem satisfies residency by definition.

Still in30/ 30
Splunk logo
Price~$120–225₹9,960

per GB / day / year reported (platform $100–180 + ES $20–45) on Splunk Cloud or Enterprise; or workload pricing (SVCs ~$55–75k / yr each); ESCU detection content

SOCs that want the reference SIEM — the deepest search language, the largest content and integration ecosystem, on-prem or cloud — and have the engineers to run it.

The catch: The licence is the small number: ingest grows, SOAR is a separate product, and an untuned Splunk is the most expensive log archive there is; India cloud region not documented.

Ingest or workloadOn-prem or cloudSOAR separate
Open the intel page
Splunk logo
Price~$100–180₹8,300

per GB / day / year reported; the data platform under ES, ITSI and Observability

Teams that need log search and analytics at scale without the SIEM application on top — yet.

The catch: Log management and analytics, not a SIEM until you add Enterprise Security (and its price); the same ingest economics apply.

Log managementIngest or workloadPlatform
Open the intel page
Splunk logo
PriceQuote

per user / per action; playbooks and case management over ES or other SIEMs

SOCs automating triage and response around Splunk (or another SIEM).

The catch: A separate SKU from ES; automation only — it is not a SIEM; quote-only.

SOARSeparate SKU
Open the intel page
Microsoft logo
Price~$2.96–4.30 / GB₹20,667

per GB ingested (East US): ~$4.30 pay-as-you-go, ~$2.96 effective at the 100 GB / day commitment, down to ~$2.05 at 50,000 GB / day; data lake tier ~$0.05 / GB ingest and ~$0.026 / GB / month storage at 6:1 compression; Azure Activity, Microsoft 365 audit logs and Defender XDR alerts ingest free; 90 days retention included; Central India, Jio India West and Jio India Central regions (data lake: Central India)

Microsoft 365 and Azure estates that want SIEM and XDR in one incident queue — where the first-party logs a SOC actually watches ingest free, and a data lake tier keeps the high-volume rest affordable.

The catch: The free ingest is Microsoft data only — noisy third-party sources (firewalls, proxies, NDR) pay full analytics rates and are where the bill escalates; SaaS on Azure only, so no on-prem or air-gapped option; SOAR is Logic Apps, billed separately; the Azure portal experience retires 31 March 2027, so the Defender portal migration is work you must scope; and note that while data is STORED in your workspace region, Microsoft documents that for workspaces outside Europe, Israel and China it PROCESSES customer data in a US region.

Per GB ingestMicrosoft logs freeAzure portal retires Mar 2027
Open the intel page
Palo Alto Networks logo
Palo Alto Cortex XSIAMPalo Alto Networks
PriceQuote

platform subscription priced by data ingested and scope; SOAR, threat intel and attack-surface management included rather than sold alongside; credits-style consumption

SOCs that have concluded the alert-triage model is the problem, and want AI-led detection and automated response to replace the SIEM rather than sit on top of it.

The catch: It is a platform bet, not a drop-in SIEM: the value depends on giving it your data and letting its automation act, which is a bigger operating change than a migration. Cloud-only, quote-only, and strongest inside a Palo Alto estate. Also the destination Palo Alto is migrating IBM QRadar SaaS customers to — useful if you are one, a consideration if you are not.

AI-led SecOpsSOAR includedCloud-only
Open the intel page
Palo Alto Networks logo
Palo Alto Cortex XSOARPalo Alto Networks
PriceQuote

per-user / per-automation licensing; hundreds of product integrations; available as SaaS or self-hosted

SOCs automating repetitive investigation and response across a mixed security stack, over whichever SIEM they already run.

The catch: Automation only — it is not a SIEM and does not detect anything on its own; it acts on what your SIEM raises, so an untuned SIEM just gets its noise automated faster. Playbook engineering is real work and quote-only pricing.

SOARSeparate SKUSaaS or self-hosted
Open the intel page
Google logo

a package (Standard / Enterprise / Enterprise Plus) bought against a data cap in GB; twelve months of hot retention included on every tier, longer billed separately; the older per-employee metering has been retired; no published US list price

Large or fast-growing log estates that want retention to stop being a budget argument — twelve months hot and searchable, with SOAR and Mandiant intelligence in the same platform rather than two more contracts.

The catch: SaaS on Google Cloud only — no on-premises or air-gapped option at all; YARA-L is a rule language your team must learn, with a smaller talent pool than SPL or KQL; and it asks for a platform commitment rather than slotting beside what you run. Quote-only, and any comparison written before 2026 describes the retired per-employee model.

12 months hot retentionSOAR + intel includedCloud-only
Open the intel page
Datadog logo
Price~$0.20 / GB

reported ~$0.20 per GB of ANALYSED logs (also quoted as ~$5 per million analysed events, annual billing) on top of Log Management, which is billed separately by ingest and indexing; Flex Logs gives 3-15 months retention without rehydration and Cloud SIEM detections still run against it. Part of the Datadog Cloud Security platform, not a standalone SKU

Teams already running Datadog for observability who want threat detection on the logs they are collecting anyway — security signals correlated with the metrics and traces from the same incident, in one console.

The catch: It is a pillar of Datadog Cloud Security rather than a standalone SIEM, and it sits ON TOP of Log Management — so the Cloud SIEM line is the small half of the bill and the log ingestion and indexing underneath it is the real cost. Datadog’s per-module, per-unit billing is the thing buyers most often underestimate. Cloud-only, and weakest as a choice if you are not already a Datadog estate.

Per GB analysedOn top of Log ManagementDatadog estates
Open the intel page
Elastic logo
PriceFree → quote

engine free and open source under AGPL; you pay for a subscription tier (Standard / Gold / Platinum / Enterprise). Self-managed on your own hardware including air-gapped; Elastic Cloud Hosted priced on provisioned resources (reported ~$99/mo Standard to ~$184/mo Enterprise at entry size, scaling with resources); Serverless from a reported ~$0.50/GB ingested. Not metered per GB/day on self-managed

Estates that need on-premises or air-gapped and find the cloud-only SIEMs are therefore not candidates at all — and teams already running Elasticsearch, for whom adopting it is closer to enabling than migrating.

The catch: Named a Visionary, not a Leader, in the 2025 Gartner MQ for SIEM: out-of-the-box detection content is narrower than Splunk’s and the security talent pool is smaller than for SPL or KQL, so expect to write more of your own rules. And the free tier is what makes teams underestimate the rest — running Elasticsearch well at scale is real engineering work unless you buy Elastic Cloud.

Air-gapped capableFree tierVisionary, not Leader
Open the intel page
Exabeam logo
PriceQuote

metered on MONITORED USERS plus sources plus modules rather than gigabytes ingested — quote-only, no published list. The cloud platform the July 2024 LogRhythm merger standardised on; LogRhythm’s competing Axon was retired in its favour

Estates where log volume is large relative to security headcount — the user-based meter is built for exactly that shape, and inverts the cost curve of ingest-priced SIEMs.

The catch: The meter cuts both ways: a large workforce generating modest logs pays more here than on an ingest-priced SIEM, so you must model both. Cloud-only (LogRhythm SIEM is the self-hosted half), the talent pool is smaller than for Splunk or Microsoft, and a two-platform portfolio after a merger deserves a written roadmap question.

Priced per user, not GBUEBA-ledCloud (see LogRhythm for on-prem)
Open the intel page
Exabeam logo
PriceQuote

self-hosted licensing, quote-only; you supply and run the infrastructure. Exclusively on-premises since the Exabeam merger — 1,100+ prebuilt correlation rules mapped to MITRE ATT&CK, with compliance reporting for ISO 27001, PCI DSS, HIPAA, SOX, NIST and CIS

Regulated estates where the mandate rules out SaaS entirely — self-hosting answers BOTH storage and processing residency by definition, because the data never leaves.

The catch: You buy, run, patch and capacity-plan the infrastructure, and under-sizing storage in year one is the commonest regret. It is also the self-hosted half of a two-platform portfolio after a merger, so ask for the roadmap in writing — Axon’s retirement shows this vendor consolidates where products overlap.

Self-hosted only1,100+ rulesResidency by design
Open the intel page
Rapid7 logo

Per MONITORED ASSET rather than per GB ingested — a host with a workstation or server OS that reported data in the last 30 days — so a verbose log source does not move the licence. Three tiers: Essential (90-day log retention), Advanced and Ultimate (180 days); alert and audit data 13 months on all tiers. Rapid7’s own AWS Marketplace listings publish ~$21,479 / $33,682 / $46,149 for 12 months at up to 500 assets

Mid-market teams of roughly 500–5,000 endpoints with a security team in single figures and no detection-engineering function. Rapid7 writes and maintains the detection content itself, so the platform produces useful alerts in days rather than months — IDC named it a Leader for SIEM in the SMB segment specifically.

The catch: NO INDIA DATA REGION — five regions (US, Canada, Europe, Japan, Australia), so an Indian entity holds its logs in Tokyo or further. 13-month retention exceeds CERT-In’s 180 days on duration and fails on location. Cloud-only, so no air-gap at any price. Gartner rates it a CHALLENGER not a Leader, citing no supervised ML or custom deep-learning models; reports group by one field at a time; default cap of 200 custom detection rules.

Per asset, not per GBNo India regionChallenger, not Leader
Open the intel page
Wazuh logo

A bespoke annual support contract on a platform whose licence stays free under GPLv2 — you are buying accountability, not software. Standard is 8/5 with an 8-hour response SLA and two health checks a year; Premium is 24/7 on critical issues with a 4-hour SLA and four health checks. Both include architecture guidance, upgrade planning, custom rules and decoders, and a named CSM. No published price

Organisations whose mandate rules out SaaS entirely — RBI, SEBI and IRDAI-regulated entities, government, and anyone contractually barred from sending security telemetry offshore — who have real platform-engineering capacity but need the vendor contractually accountable. Also estates above ~500 agents where per-agent cloud tiers stop making sense.

The catch: This is SUPPORT, not a managed service and definitively not MDR — you still run the cluster, own the upgrades and carry the pager, and nobody is watching your alerts. Conflating those three is the commonest disappointment here. The real cost is your infrastructure plus 0.3–0.5 FTE on top of the contract. And self-hosting lets you place the indexer in India — it does not do it for you.

Air-gap capableSupport, not MDRNo published price
Open the intel page
Exabeam logo

Priced on monitored users and log sources rather than data volume, which is the structural difference from ingest-metered SIEM — your bill tracks headcount, not how chatty your firewall is. Sold as the behavioural analytics layer of New-Scale rather than a standalone SIEM

Teams whose threat model centres on credentials and people rather than malware — insider misuse and account takeover, where the attacker logs in correctly and does permitted things, so no rule fires. This is the gap rule-based detection structurally cannot close.

The catch: Not a SIEM on its own — it is the analytics layer and needs the platform underneath. Its output is bounded by your identity data: peer groups built on a stale directory mean little, and service accounts need owners before they need baselines. Models need 8–16 weeks observing normal before their output should be acted on, and teams that judge it in week two decide on bad evidence.

UEBAPriced on usersNeeds 8-16 weeks baselining
Open the intel page
Exabeam logo
PriceQuote

An agentic AI layer over the Exabeam platform rather than a separately deployable product; commercial terms are quoted with the platform

Existing Exabeam customers wanting AI-assisted triage and investigation summarisation on top of a platform they already run.

The catch: Emerging rather than proven — treat vendor productivity statistics as unaudited, and do not let an AI layer become the reason to buy the platform underneath it. It cannot analyse data the platform did not collect.

Agentic AILayer, not a platformVendor claims unaudited
Open the intel page
Securonix logo
PriceQuote

Included in the Unified Defense entitlement rather than metered separately, so the commercial question is the platform’s GB/day band rather than a per-user analytics licence

Organisations whose threat model centres on credentials and insiders, and who want behavioural scoring integrated with the SIEM rather than bolted alongside it — the analyst moves from a risk score to the raw events without switching tools.

The catch: Bounded by identity-data quality: peer groups are only as good as your directory, and service accounts need named owners first. Needs 8–16 weeks of baselining before its output is trustworthy. And it inherits the platform’s hard limit — no air-gapped or on-premises deployment in any configuration.

UEBAIn the platform entitlementNo air-gap option
Open the intel page
Securonix logo

Included in the Unified Defense entitlement; retro-hunts historical data when new threat intelligence lands, which is why the platform’s 365 days of hot searchable data is the feature that makes it useful

Teams that want retrospective hunting automated rather than dependent on someone remembering to re-run a query after a disclosure — when an indicator becomes public, the sweep happens whether or not anyone thought of it.

The catch: It can only re-hunt data you actually ingested. Every source filtered out to control the GB/day bill is a source no future sweep can reach — and a blind sweep looks exactly like a clean one. That tension between cost control and retrospective coverage is real and deserves a deliberate decision rather than a default.

Retro-huntingBounded by what you ingestedNo air-gap option
Open the intel page
Gurucul logo
PriceQuote

Quote-only. Gartner records the metering axes as all-inclusive per-asset and per-user pricing, ELAs, module-based, data-volume/EPS-based and platform-based. The per-asset and per-user axes break the dynamic where better logging costs more — but note the precision: they are offered AS AN ALTERNATIVE to per-GB, not instead of it, so which axis your order form specifies is the highest-value clause in the contract

The buyer a mandate has cornered. Gurucul was named a Leader in the 2025 Gartner MQ for SIEM (its first year, after three as a Visionary) AND — confirmed in Gartner’s own report text — runs SaaS, cloud or SELF-HOSTED. Of the six 2025 Leaders, the other five are cloud-only or cloud-only where the analytics run, so this is the only analyst-recognised Leader a regulated Indian buyer under an on-premises mandate can actually deploy. Behavioural analytics is the founding capability from 2010 rather than an acquisition, and Pune has been the engineering base since 2013.

The catch: A bootstrapped sub-$100M boutique competing with Microsoft, Google and Cisco — no investor pressure, but no war chest either, and vendor scale is a question your risk function should answer deliberately. Analyst strength is Gartner-SPECIFIC: absent from the June 2025 Forrester Wave where the other five Leaders all appear, and its KuppingerCole Leader award is the 2024 report. We found no evidence of a vendor-run India data region — the India answer is self-hosting. And a genuine AIR-GAP is marketed but UNVERIFIED; self-hosted is not the same thing, so get it in writing.

2025 MQ Leader — 1st yearSelf-hostableAir-gap unverified
Open the intel page
Gurucul logo
PriceIncluded

Part of the REVEAL platform entitlement rather than a separate meter, so the commercial question is the platform’s pricing axis rather than a per-user analytics licence

Threat models centred on credentials and people rather than malware. This is the capability Gurucul was founded on in 2010 — it built the analytics first and grew a SIEM around them, which is the reverse of how most of this market was assembled. The practical consequence is that a risk score and the events that produced it live on one platform, so an analyst investigating a borderline score clicks through rather than filing an export request.

The catch: Bounded by identity-data quality — peer groups built on a stale directory produce confident nonsense, and service accounts need named owners before they need baselines. Models also need WEEKS observing normal before their output should be acted on; teams judging alert quality in week two are deciding on bad evidence. Neither is a product fault and both are true of every UEBA product, but both are where deployments actually fail. Not sold standalone.

The founding capability, 2010On the platform, not a meterNeeds weeks of baselining
Open the intel page
Gurucul logo
PriceIncluded

Part of the REVEAL platform rather than a separate purchase with its own meter — no second data lake sitting beside your SIEM, and one query surface rather than two

Heterogeneous estates assembled over a decade, where real telemetry sits across an EDR chosen three years ago, a firewall estate from a different decision and an identity provider nobody will migrate off. Open XDR ingests from what you already run rather than demanding its own agent everywhere — which is why so many XDR pilots stall — then layers identity and behavioural analytics on top.

The catch: Test the openness rather than believing it. Every XDR vendor claims it, and rich normalised telemetry and forwarded alerts are BOTH called integrations — only one supports an investigation. Check your two or three most depended-on tools during the PoC. Also: it is not MDR (nobody watches your alerts), not an EDR (it consumes endpoint telemetry, it does not prevent), and not sold standalone. Single-vendor stacks get deeper native integration from CrowdStrike or Microsoft.

Keeps the tools you ownTest connector DEPTHNot MDR, not EDR
Open the intel page
Gurucul logo
PriceIncluded

Part of the REVEAL platform entitlement; shares one identity model with the SIEM and UEBA, so access risk and threat detection reason over the same picture of who your users are

BFSI buyers who can list who has access but cannot say which access is DANGEROUS. It scores entitlements and access patterns for risk rather than cataloguing them — excess privilege, dormant high-risk access, and the permissions that accumulate across a decade of role changes and never get removed. That last one is the real problem: no individual grant was wrong, and the aggregate is invisible to a review that examines grants one at a time. Maps onto RBI and SEBI access-review evidence.

The catch: This is ANALYTICS, NOT IDENTITY GOVERNANCE, and the categories are adjacent enough that vendors blur them. It tells you what access is risky and evidences it. It does not provision or deprovision accounts, does not run joiner-mover-leaver workflow, and does not own certification campaigns end to end. It complements SailPoint, Saviynt or One Identity rather than replacing one — and if you have no governance platform at all, fix provisioning first or you will get an accurate description of chaos.

Risk, not inventoryRBI / SEBI evidenceNOT an IGA suite
Open the intel page
Wazuh logo
WazuhWazuh
PriceFree core₹0

The platform itself is free under GPLv2 — no agent cap, no ingestion metering, no feature paywall, and no enterprise edition holding detection back. What is sold is operation: Wazuh Cloud from a reported ~$571/mo for 100 agents (1 month indexed, 3 months archive), ~$923 for 250 (3 months indexed, 1 year archive), ~$1,467 for 500. Professional Support is a bespoke annual contract with no published price. Note that retention forces the tier more often than agent count does

Two quite different buyers. Estates where an ingestion meter is currently shaping what gets collected — removing that meter is the strongest single argument in the category. And regulated Indian buyers whose mandate rules out SaaS entirely: Wazuh self-hosts on-premises or fully air-gapped, with documented offline installation and offline CVE feeds, which is where the cloud-only SIEMs simply cannot go at any price.

The catch: The licence is free; the system is not. Infrastructure plus 0.3–0.5 FTE means self-hosting lands around ₹8–11 lakh a year at 250 agents — roughly LEVEL with the Cloud subscription, not the saving people assume. Also: no machine-learning-driven detections and a simpler query model than Elastic; real tuning effort in week one because collection is broad; and Wazuh does not sell MDR at all. Wazuh Cloud has no publicly documented India region — confirm in writing before trialling, or self-host.

Free GPLv2 coreAir-gap capableOps cost is real
Open the intel page
Securonix logo

GB/day in tiered bands, hybrid commitment plus pay-as-you-go with pre-negotiated overages — but note the licensing terms default overage to 120% of your GB/day rate where the order form specifies no rate. 365 days of hot searchable data included as standard; Data Pipeline Manager flexes one entitlement across Analytics 1.0x, Investigation 0.5x and Basic 0.25x tiers

Cloud-accepting estates that want retention solved rather than negotiated — a full year of hot data means the investigation reaching back eleven months is a query, not a restore ticket — and that value behavioural detection enough to build around it.

The catch: No air-gapped or on-premises deployment in ANY configuration. BYO-AWS and BYO-Snowflake let your own account hold the data lake, which can answer an India-residency obligation, but the analytics control plane is always Securonix’s cloud — so an air-gap mandate rules it out entirely. Also: three CEOs in two years, and the 120% default overage is the commonest avoidable cost in the contract.

365 days hot included6x MQ LeaderNo air-gap option
Open the intel page
ManageEngine logo
Price$300–1,995₹24,900

per year entry tiers (Basic $300 · Standard $995 · Professional $1,995; MSSP $194 / mo); priced by log sources, unlimited users; Zoho-hosted cloud with India data centres

Mid-market and regulated Indian estates that want a SIEM with UEBA and compliance reports priced by sources, not gigabytes, from an India-built vendor.

The catch: Predictable and cheap until the source count climbs; SOAR is built-in workflows rather than a full automation platform; documented scale tops out below the hyperscale SIEMs.

India-builtPer sourceOn-prem or cloud
Open the intel page
Fortinet logo
PriceQuote

per device / EPS or per GB / day subscription; appliance, VM or FortiSIEM Cloud (Mumbai region); FortiSOAR separate

Fortinet Security Fabric estates that want SIEM plus CMDB-style asset context, on appliances or in a Mumbai-hosted cloud.

The catch: Full SOAR is FortiSOAR (separate); strongest inside a Fortinet estate; quote-only across several meters.

Device / EPS or GBMumbai cloud regionSecurity Fabric
Open the intel page
Fortinet logo
PriceQuote

appliance / VM / cloud licensed by devices and GB / day; Fortinet-centric logging, analytics and playbooks

Fortinet estates that need fabric logging, reporting and automation before (or instead of) a full SIEM.

The catch: Log analytics for the Fortinet fabric — third-party breadth and SIEM correlation are FortiSIEM's job.

Log managementFortinet-centricPlaybooks
Open the intel page
CrowdStrike logo
Price~$5.95 / GB

AWS Marketplace pay-as-you-go $5.95 / GB (13-month retention); list reported ~$2,700 per GB / day / year for third-party data; 10 GB / day of third-party data included with Falcon Insight; Fusion SOAR included

Falcon estates that want SIEM on the data already in the platform, with third-party ingestion priced per GB and SOAR in the box.

The catch: Cloud-only; third-party ingest beyond the included 10 GB / day is where the bill lives; India in-country cloud announced, not yet documented live.

Per GB ingestSOAR includedCloud-only
Open the intel page
CrowdStrike logo

agentic automation over Falcon Next-Gen SIEM and Fusion workflows

Falcon SOCs pushing triage and response automation beyond playbooks.

The catch: Falcon-only; quote-only; not a SIEM on its own.

SOARFalcon-only
Open the intel page
SentinelOne logo
PriceQuote

consumption per GB / day of ingested data (rates not published); Singularity Data Lake; Hyperautomation (SOAR) and Purple AI included in platform packages; Mumbai region

SentinelOne estates that want SIEM on the Singularity Data Lake with automation and an AI analyst in the same console, with a Mumbai data region.

The catch: Rates are not published — the per-GB consumption is a quote; cloud-only; strongest when SentinelOne is already the agent.

Per GB ingestSOAR includedMumbai region
Open the intel page
Kaspersky logo
PriceQuote

licensed by events per second (EPS); on-prem; documented 300,000+ EPS per correlation node

Estates that want a high-throughput on-prem SIEM priced by EPS rather than gigabytes, with Kaspersky's detection content.

The catch: Procurement-sensitive in some sectors and countries (check your regulator); automation is playbook-grade rather than a full SOAR; quote-only.

Per EPSOn-premProcurement caveat
Open the intel page
Why each constraint rules out what it doesShow the reasoning ↓

India-built vendorRules out Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Splunk SOAR, Microsoft Sentinel, Palo Alto Cortex XSIAM, Palo Alto Cortex XSOAR, Google Security Operations, Datadog Cloud SIEM, Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support, Exabeam New-Scale Analytics (UEBA), Exabeam Nova (agentic AI), Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, Securonix Unified Defense SIEM, Fortinet FortiSIEM, Fortinet FortiAnalyzer, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA) — not an India-built vendor. That leaves ManageEngine Log360 (on-prem) / Log360 Cloud.

Ingest-based pricingRules out Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR, Palo Alto Cortex XSOAR, Exabeam Nova (agentic AI) and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM; Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Exabeam New-Scale Analytics (UEBA), Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, ManageEngine Log360 (on-prem) / Log360 Cloud and Kaspersky SIEM (KUMA) — priced per source / EPS, not by data volume; Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support and Wazuh — no ingestion meter at all; the free core is priced by agent count for the managed edition. That leaves Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Securonix UEBA, Securonix Autonomous Threat Sweeper, Securonix Unified Defense SIEM, Fortinet FortiSIEM, CrowdStrike Falcon Next-Gen SIEM and SentinelOne Singularity AI SIEM. It flags Splunk Enterprise Security — Also offers workload (compute) pricing and Fortinet FortiSIEM — GB / day subscription is one of its meters; device / EPS is the other — marked on the cards, not removed.

Per source / device / EPS pricingRules out Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Securonix Unified Defense SIEM, CrowdStrike Falcon Next-Gen SIEM and SentinelOne Singularity AI SIEM — ingest or workload-compute pricing, not per source; Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR, Palo Alto Cortex XSOAR, Exabeam Nova (agentic AI) and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM; Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support and Wazuh — priced per agent count, not per source; and the core licence is free regardless. That leaves Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Exabeam New-Scale Analytics (UEBA), ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM and Kaspersky SIEM (KUMA). It flags Fortinet FortiSIEM — Device / EPS meter available; GB / day is the other — marked on the cards, not removed.

Self-hosted or on-premRules out Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Exabeam New-Scale SIEM, Rapid7 Incident Command (formerly InsightIDR), Exabeam New-Scale Analytics (UEBA), Exabeam Nova (agentic AI), Securonix UEBA, Securonix Autonomous Threat Sweeper, Securonix Unified Defense SIEM, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR and SentinelOne Singularity AI SIEM — cloud-only. That leaves Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Splunk SOAR, Palo Alto Cortex XSOAR, Elastic Security, LogRhythm SIEM, Wazuh Professional Support, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, Fortinet FortiAnalyzer and Kaspersky SIEM (KUMA).

A full SIEMRules out Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR, Palo Alto Cortex XSOAR, Exabeam Nova (agentic AI) and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM. That leaves Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSIAM, Google Security Operations, Datadog Cloud SIEM, Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support, Exabeam New-Scale Analytics (UEBA), Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, Securonix Unified Defense SIEM, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, CrowdStrike Falcon Next-Gen SIEM, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA).

SOAR includedRules out Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Microsoft Sentinel and Exabeam New-Scale Analytics (UEBA) — SOAR is a separate product from this vendor. That leaves Splunk SOAR, Palo Alto Cortex XSIAM, Palo Alto Cortex XSOAR, Google Security Operations, Datadog Cloud SIEM, Elastic Security, Exabeam New-Scale SIEM, LogRhythm SIEM, Rapid7 Incident Command (formerly InsightIDR), Wazuh Professional Support, Exabeam Nova (agentic AI), Securonix UEBA, Securonix Autonomous Threat Sweeper, Gurucul Next-Gen SIEM, Gurucul UEBA, Gurucul Open XDR, Gurucul Identity Analytics, Wazuh, Securonix Unified Defense SIEM, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, Fortinet FortiAnalyzer, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA). It flags Elastic Security — Built-in workflows / playbooks rather than a full SOAR platform, Exabeam New-Scale SIEM — Built-in workflows / playbooks rather than a full SOAR platform, LogRhythm SIEM — Built-in workflows / playbooks rather than a full SOAR platform, ManageEngine Log360 (on-prem) / Log360 Cloud — Built-in workflows / playbooks rather than a full SOAR platform, Fortinet FortiSIEM — Built-in workflows / playbooks rather than a full SOAR platform, Fortinet FortiAnalyzer — Built-in workflows / playbooks rather than a full SOAR platform and Kaspersky SIEM (KUMA) — Built-in workflows / playbooks rather than a full SOAR platform — marked on the cards, not removed.

Above 1 TB / dayRules nothing out on published terms. It flags Exabeam Nova (agentic AI) — Documented scale is mid-market, Gurucul Open XDR — Documented scale is mid-market and ManageEngine Log360 (on-prem) / Log360 Cloud — Documented scale is mid-market — marked on the cards, not removed.

India data residency (cloud)Documented: FortiSIEM Cloud (Mumbai region), SentinelOne Singularity (Mumbai), ManageEngine Log360 Cloud (Zoho India data centres), Microsoft Sentinel (Central India, Jio India West, Jio India Central). Sentinel is the one to read carefully: it STORES data in the workspace region, but Microsoft documents that for workspaces outside Europe, Israel and China it PROCESSES customer data in a US region — storage residency is not processing residency, and which one your regulator means is worth settling before the PoC. CrowdStrike's India in-country cloud is announced (January 2026), not yet documented live; Splunk Cloud publishes no Mumbai region; Kaspersky SIEM is on-prem. Nothing is ruled out on it — on-prem satisfies residency by definition, which is half the reason Log360, FortiSIEM and KUMA are on Indian shortlists.

Detection content out of the box vs built by youRules nothing out: every SIEM here ships detection content (Splunk ESCU, Log360 correlation rules and UEBA, FortiSIEM rules, Falcon detections, SentinelOne content, Kaspersky rules). What differs is who tunes it against your estate — and an untuned SIEM is an expensive log archive. The tuning headcount is the variable, and it is prose because it is yours.

Log retention mandatesNot a chip — retention is a configuration and a storage bill, not a capability: CERT-In's 2022 directions require 180 days of ICT logs in India; RBI and SEBI CSCRF add their own. Every product here retains; what you pay is ingest × retention (cloud) or disk (on-prem). Confirm the mandate before the ingest estimate, not at the audit.

Narrow to your situation

Eight situations, eight shortlists — starting from the meter

Each shortlist begins with how you will pay (gigabytes, sources, EPS) and where the logs may live. The feature list comes after.

Mid-market, regulated, India — predictable price, logs in India

Why: Per-source or per-EPS pricing, on-prem or an India-hosted cloud, compliance reports for the Indian regulators — and an India-built vendor in Log360.

The trade-off: Documented scale tops out below the hyperscale SIEMs; SOAR is built-in workflows rather than a platform; KUMA carries procurement caveats in some sectors.

You already run CrowdStrike Falcon

Why: Falcon data is already in the platform; 10 GB / day of third-party data is included with Insight, Fusion SOAR is in the box, and the per-GB meter is published on AWS Marketplace.

The trade-off: Third-party ingest beyond the included volume is the bill; cloud-only; India in-country cloud announced, not yet live.

You already run SentinelOne

Why: Singularity Data Lake with AI SIEM, Hyperautomation and Purple AI in the same console, and a Mumbai data region.

The trade-off: Consumption rates are not published — the per-GB price is a quote; one survivor here is the platform answer, not a gap. Splunk or Log360 remain the vendor-neutral alternatives.

You already run Microsoft 365 E5 and Azure

Why: Azure Activity, Microsoft 365 audit logs and Defender XDR alerts ingest free, so much of what the SOC watches costs nothing to collect; Sentinel and Defender XDR alerts land in one incident queue in the Defender portal; the data lake tier keeps high-volume logs at ~$0.05 / GB.

The trade-off: One survivor is the estate answer, not a gap — and it only holds while your volume is Microsoft-shaped: third-party firewall and proxy logs pay full analytics rates. Cloud-only, so on-prem residency needs Log360 or FortiSIEM instead — and Sentinel stores in-region but processes customer data in the US for Indian workspaces. Budget the 31 March 2027 Defender portal migration.

You believe the alert-triage SOC model itself is the problem

Why: These are sold as replacements for the SIEM-led SOC rather than better versions of it — AI-led detection that stitches signals into a few high-fidelity incidents, with automation included rather than bought beside it.

The trade-off: You are buying an operating model, not a log store: the value only lands if you give the platform your data and let its automation act. All three are cloud-only and quote-only, and each is strongest inside its own vendor’s estate.

You already run Datadog for observability

Why: Threat detection on logs you are already collecting and paying to index, with security signals correlated against the metrics and traces from the same incident — and Flex Logs keeps 3-15 months searchable without rehydration while detections still run against it.

The trade-off: One survivor is the estate answer, not a gap. Cloud SIEM is priced on analysed logs on top of Log Management, so the ingestion and indexing underneath is the real bill — Datadog’s per-module billing is what buyers underestimate. If you are not already a Datadog estate, the vendor-neutral SIEMs are the honest comparison.

A real SOC, with engineers, that wants the deepest search and content

Why: Splunk ES is the reference — SPL, ESCU content, the integration ecosystem — with SOAR alongside; Falcon Next-Gen SIEM is the platform-native alternative for Falcon estates.

The trade-off: Splunk's ingest economics and the tuning headcount are the contract; without engineers it is the most expensive archive in security.

Fortinet fabric estate

Why: FortiAnalyzer for fabric logging and playbooks; FortiSIEM for correlation, CMDB context and third-party sources, on appliances or in the Mumbai cloud region.

The trade-off: Strongest inside Fortinet; full SOAR is FortiSOAR, separate; several meters to match at quote.

Log management first, SIEM maybe later

Why: Search and retention at scale without the SIEM application's price — Splunk's platform, FortiAnalyzer for Fortinet estates, Log360's entry tiers for everyone else.

The trade-off: A log platform is not a SIEM until correlation, detections and cases are on it — and the ingest meter is the same.

Retention is the problem — you keep deleting data you later need

Why: Google SecOps includes twelve months of hot, searchable retention in every package, so the keep-or-delete decision leaves the budget conversation; Log360 and KUMA get there differently, by not metering gigabytes at all.

The trade-off: Google SecOps is cloud-only on Google Cloud and quote-only, and beyond twelve months retention is billed by volume again. The per-source and per-EPS meters trade volume risk for scale ceilings.

Ingest is exploding and the bill is the problem

Why: Meters that are not gigabytes: per source (Log360), per EPS (KUMA), per device (FortiSIEM) — the cost curve flattens as volume grows.

The trade-off: Predictable meters trade volume risk for scale ceilings and narrower ecosystems; the honest alternative is filtering and tiering data before a per-GB SIEM, not abandoning it.

SOAR first — automate the triage you already have

Why: Splunk SOAR over ES or another SIEM; Charlotte Agentic SOAR and SentinelOne Hyperautomation included with their platforms.

The trade-off: Automation needs the detections to be good first — SOAR over an untuned SIEM automates noise.

The spine of the decision

Four meters, and why the cheapest year one is rarely the cheapest year three

Every SIEM quote is a bet on your data growth. The meter decides who wins that bet.

Meter 1

Ingest — per GB / day

You pay for volume, forever, times retention. Splunk Cloud is reported near $1,000 per GB / day / year at 50 GB / day (tapering with commit); CrowdStrike publishes $5.95 / GB pay-as-you-go with 13-month retention and includes 10 GB / day of third-party data with Falcon Insight; SentinelOne meters per GB but does not publish rates. Microsoft Sentinel publishes ~$4.30 / GB pay-as-you-go falling to ~$2.96 at a 100 GB / day commitment — and ingests Microsoft’s own logs free, which is why a Microsoft estate’s bill is far below its raw volume. Year-one cheap, year-three expensive unless you filter at the source.

Meter 2

Workload — compute (SVCs)

Splunk's alternative: pay for search and indexing compute (~$55–75k per SVC per year reported) rather than volume. Flattens the data bet, moves it to a usage bet; suits estates that ingest a lot and search predictably.

Meter 3

Sources, devices, EPS

Log360 per log source with unlimited users ($300 → $1,995 / year entry tiers); FortiSIEM per device / EPS or per GB / day; KUMA per EPS. The curve flattens as volume grows; the trade is a scale ceiling and a narrower ecosystem.

Meter 4

Flat / included

SOAR included with a platform (Fusion, Hyperautomation), or the SIEM sold as part of a platform commit. The cheapest line is the one you already pay for — until the third-party data arrives.

Retention and residency

The mandate is a storage bill with a regulator attached.

  • CERT-In (2022): 180 days of ICT system logs, maintained in India. RBI and SEBI CSCRF add sector retention and reporting; your circular may add more. Retention × ingest is the cloud bill; retention × disk the on-prem one.
  • On-prem satisfies residency by definition — half the reason Log360, FortiSIEM and KUMA lead Indian shortlists. Documented India cloud regions: FortiSIEM Cloud (Mumbai), SentinelOne (Mumbai), Log360 Cloud (Zoho India DCs); CrowdStrike announced; Splunk Cloud publishes none.
  • Tiering is the lever: hot search for weeks, warm for the mandate, cold archive beyond — every vendor here supports it; few quotes assume it.

Who tunes it

An untuned SIEM is an expensive log archive.

  • Content exists everywhere — Splunk ESCU, Log360 rules and UEBA, FortiSIEM rules, Falcon and SentinelOne detections, KUMA content. None of it knows your estate until someone maps sources, suppresses the noise and writes the detections you actually need.
  • Budget the engineer (or the MDR that supplies one) beside the licence. At 2,000 endpoints the tuning is a role; at a TB / day it is a team.
  • XDR is the honest alternative when nobody will tune: pre-tuned correlation from one vendor’s sensors, narrower than a SIEM, far less work. Regulators and third-party logs decide whether it is enough.
  • SOAR last: automate after the detections are good, or you automate noise.
What breaks as you grow

What changes at 50 GB, 500 GB and 5 TB a day

SIEMs scale by data, not by seats. Each step changes which meter survives and how many people the detections need.

50GB / day

The meter is the constraint

  • Per-GB is survivable; per-source is cheaper; the difference is the retention mandate times the volume.
  • Log360, FortiSIEM, KUMA and the platform-native SIEMs with included data fit this band; Splunk ES is rarely the cheapest here.
  • One engineer tunes part-time — or nobody does, and it becomes an archive.

Put this in your PoC

Estimate your real volume from a week of sources; price it at 180 days and at your mandate; compare per-GB against per-source with the same sources.

500GB / day

Tuning and filtering are the constraint

  • Filtering and tiering at the source decide whether per-GB is affordable; workload pricing starts to make sense.
  • Detections need an owner; alert fatigue is now a staffing problem, not a tool problem.
  • Third-party ingest is where platform-native SIEMs stop being 'included'.

Put this in your PoC

Measure alerts per analyst per day for a month; ask each vendor what the bill is with 30% of volume filtered or tiered.

5,000GB / day

Architecture and sovereignty are the constraint

  • Multi-tenant, multi-region SIEM with delegated access; residency per source; EPS-based or workload pricing on the table.
  • Detection engineering is a team with a pipeline; SOAR is mandatory to survive the volume.
  • Migration now means rewriting every detection rule — plan the exit before signing the entry.

Put this in your PoC

Load-test your peak EPS; confirm region sharding and retention tiers in writing; price the exit.

Splunk, CrowdStrike, SentinelOne, FortiSIEM and KUMA document very large deployments (KUMA 300,000+ EPS per node); Log360’s documented scale is mid-market — flagged, not ruled out. Where a specific console strains for your volume: [TechBag to confirm].

The switching cost

Migration means rewriting every detection rule

Sources re-point in weeks. The detections, the parsers, the dashboards and the years of logs under a retention mandate are what make a SIEM migration a year, not a quarter.

Sources and collectors

Re-point syslog, agents and API connectors; re-parse each source's format for the new platform. Weeks per estate, scriptable in parts.

Exit costRe-point, re-parse

Detections and dashboards

Every correlation rule, every tuned exclusion and every compliance dashboard is rewritten in the new language — SPL is not KQL is not Log360's rules. The year.

Exit costRewrite

Retained logs

Logs under a mandate must stay searchable for the mandate; either keep the old SIEM in read-only for the period or export and re-index. Both cost.

Exit costKeep or re-index

Playbooks and integrations

SOAR playbooks, ticketing and MDR integrations are rebuilt; the MDR may have to re-onboard the new SIEM as a source.

Exit costRebuild

Detection-rewrite months and retained-log strategy for your estate: [TechBag to confirm] — TechBag scopes it from your rule count, sources and mandate.

What it costs

The licence is the small number

What you may already hold, the meters compared in USD and INR at three daily volumes, and what the licence leaves out — retention, tuning, and the exit.

01

Do you already own one?

Four places a SIEM — or enough of one — may already be on your invoice.

Microsoft 365 E5
Partly E5 carries Defender XDR (correlation across Microsoft sensors) and Sentinel benefits (a daily data grant for Microsoft 365 logs). Sentinel itself is Azure consumption per GB — a SIEM you already half-pay for if the estate is Microsoft.
Your EDR platform
Often CrowdStrike (Next-Gen SIEM with 10 GB / day of third-party data included with Insight), SentinelOne (AI SIEM on the Data Lake), Trend, Sophos and Palo Alto all sell SIEM or XDR on the sensor you run. The included part is the vendor’s data; the bill is the rest.
Your firewall vendor
Sometimes FortiAnalyzer logs the Fortinet fabric and runs playbooks; FortiSIEM adds correlation. Check Point, Cisco and Palo Alto have their own. Fabric logging is not a SIEM until third-party sources are in.
Your cloud provider
Partly AWS Security Lake, Microsoft Sentinel and Google Security Command Center / Google Security Operations ingest their own clouds cheaply. One cloud each — the vendor-neutral SIEM question remains.

If the logs you must keep are already sitting somewhere you pay for, we say so — and then price what it costs to keep them for the mandate.

02

What the rest actually cost

Reported and published rates per meter (INR for scale), then worked at 50 / 500 / 5,000 GB a day. Per-source and per-EPS products cannot be expressed per gigabyte — the grid says so rather than inventing a conversion.

50GB / day · per year
  • CrowdStrike Next-Gen SIEM — third-party data(PAYG $5.95 / GB → list ~$2,700 / GB / day / yr; 10 GB / day included)$86,8701,08,000 ₹72,10,210₹89,64,000
  • Splunk Cloud platform(reported ~$750–1,620 / GB / day / yr, tapering with commit)$37,50081,000 ₹31,12,500₹67,23,000
  • Splunk Enterprise Security add-on(reported +$20–45 / GB / day / yr)$12,00027,000 ₹9,96,000₹22,41,000
  • SentinelOne AI SIEM(per GB, rates not published)Quote / other meter
  • FortiSIEM(GB / day subscription or device / EPS — quote)Quote / other meter
  • ManageEngine Log360(per source — $300 / $995 / $1,995 / yr entry tiers; not per GB)Quote / other meter
  • Kaspersky SIEM / KUMA(per EPS — quote)Quote / other meter
  • FortiAnalyzer(devices / GB — quote)Quote / other meter
500GB / day · per year
  • CrowdStrike Next-Gen SIEM — third-party data(PAYG $5.95 / GB → list ~$2,700 / GB / day / yr; 10 GB / day included)$10,64,15813,23,000 ₹8,83,25,114₹10,98,09,000
  • Splunk Cloud platform(reported ~$750–1,620 / GB / day / yr, tapering with commit)$3,75,0008,10,000 ₹3,11,25,000₹6,72,30,000
  • Splunk Enterprise Security add-on(reported +$20–45 / GB / day / yr)$1,20,0002,70,000 ₹99,60,000₹2,24,10,000
  • SentinelOne AI SIEM(per GB, rates not published)Quote / other meter
  • FortiSIEM(GB / day subscription or device / EPS — quote)Quote / other meter
  • ManageEngine Log360(per source — $300 / $995 / $1,995 / yr entry tiers; not per GB)Quote / other meter
  • Kaspersky SIEM / KUMA(per EPS — quote)Quote / other meter
  • FortiAnalyzer(devices / GB — quote)Quote / other meter
5,000GB / day · per year
  • CrowdStrike Next-Gen SIEM — third-party data(PAYG $5.95 / GB → list ~$2,700 / GB / day / yr; 10 GB / day included)$1,08,37,0331,34,73,000 ₹89,94,73,739₹1,11,82,59,000
  • Splunk Cloud platform(reported ~$750–1,620 / GB / day / yr, tapering with commit)$37,50,00081,00,000 ₹31,12,50,000₹67,23,00,000
  • Splunk Enterprise Security add-on(reported +$20–45 / GB / day / yr)$12,00,00027,00,000 ₹9,96,00,000₹22,41,00,000
  • SentinelOne AI SIEM(per GB, rates not published)Quote / other meter
  • FortiSIEM(GB / day subscription or device / EPS — quote)Quote / other meter
  • ManageEngine Log360(per source — $300 / $995 / $1,995 / yr entry tiers; not per GB)Quote / other meter
  • Kaspersky SIEM / KUMA(per EPS — quote)Quote / other meter
  • FortiAnalyzer(devices / GB — quote)Quote / other meter
The grid is the meter, not the bill. Per-GB lines exclude retention beyond the included window, premium support and the engineers; per-source and per-EPS products are deliberately not converted — a conversion would be fiction. Price Log360, FortiSIEM and KUMA on your source count and peak EPS.
Tier- and term-match. Splunk platform is not Splunk ES; Falcon Next-Gen SIEM’s included data is Falcon data plus 10 GB / day, not your firewall logs; AWS pay-as-you-go is not a three-year commit. Compare the same volume, the same retention, the same term.
The India line. Log360 is India-built with INR pricing by source; FortiSIEM Cloud and SentinelOne document Mumbai regions; on-prem (Splunk Enterprise, Log360, FortiSIEM, KUMA) keeps the logs in India by construction.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

Retention beyond the included window

Per-GB meters quote a retention (CrowdStrike 13 months PAYG; Splunk by tier); the mandate may want 180 days hot and years cold. Retention × volume is the part of the bill that grows after year one — and it multiplies at renewal.

The tuner

Detection engineering is a role at 2,000 endpoints and a team at a TB / day. Budget it beside the licence or buy the people through the MDR guide; a SIEM nobody tunes is an archive with a dashboard.

The rewrite

Leaving means rewriting every detection in the new language and keeping the old logs searchable for the mandate — the switching-cost section. Your rule count and months: [TechBag to confirm].

Before you commit

What goes wrong

Documented meter behaviour and programme failures, cross-checked against TechBag engagements before any becomes a named case. Most are visible in the quote if you know where to look.

Ingest costs multiplying after year one

Volume grew, retention stayed, the per-GB meter did what it said. Filtering and tiering at the source were never designed in.

Retention mandates discovered at audit

CERT-In's 180 days, RBI's and SEBI's retention — found when the regulator asked, after the cheapest retention tier was chosen.

No engineering capacity to write detections

Content shipped; nobody mapped sources or suppressed noise; the SIEM became a log archive with an invoice.

Alert fatigue at volume

Untuned detections at 500 GB a day outran the team; real alerts drowned. A staffing problem bought as a tool.

Migration meaning every detection rule rewritten

Years of tuning in one vendor's language; the new platform started empty. The exit nobody priced.

'Included' SIEM that wasn't

The platform's SIEM was free for the platform's data; the firewall and identity logs were the bill. Name the third-party volume before signing.

XDR sold as a SIEM replacement

Pre-tuned correlation from one vendor's sensors covered their stack; the regulator wanted everything, retained in India. Different scope.

SOAR over untuned detections

Playbooks automated the noise faster. Automate after the detections are good.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Security map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.