SIEM pricing is a data problem, not a software problem. The licence is the small number.

A SIEM is paid for by what you feed it — gigabytes a day, sources, or events per second — for as long as a regulator says you must keep it, and it only detects what someone tuned it to detect. The meter and the tuner decide the cost; the feature list does not.

Splunk Cloud is reported at roughly $1,000 per GB / day per year at 50 GB / day; ManageEngine Log360 starts at $300 a year priced by log sources. Same logs, two different bills — and the second does not grow with volume.

Already decided — before the PoC

Your retention mandateCERT-In 180 days; RBI, SEBI add theirs
Your daily log volumedecides whether per-GB is survivable
Who will write detectionsdecides whether it is a SIEM or an archive

Still yours to weigh

The meterGB / day · sources · EPS · workload
Deploymenton-prem · cloud · India region
AutomationSOAR in the box, or beside it
If you’ve never bought one

What SIEM and log management actually is

A place where the logs from everything — endpoints, firewalls, identity, cloud, mail, applications — land, are kept for as long as policy and the regulator require, and are searched and correlated: this login, from that country, after this alert, touching that server. The correlation rules are detections; the things they raise are cases; the team that reads them is the SOC. Log management is the first half (collect, keep, search); SIEM is the second (correlate, detect, investigate).

Three things cost money and the feature grid shows none of them: the meter (gigabytes a day, sources, events per second, or compute), the retention the regulator mandates, and the people who tune it. An untuned SIEM is an expensive log archive. A SOAR beside it automates whatever the detections raise — good or noise. The MDR guide is where the people come from if you do not have them.

The meter decides more than any feature

Ingest-based vs node-based vs flat pricing decides total cost more than any capability. Per-GB grows with volume forever; per-source and per-EPS flatten; workload compute sits in between. Estimate your daily volume and your retention before you read a datasheet.

Often confused withEndpoint Protection / XDR — both claim correlation, differently·Managed Detection & Response — the people who read what the SIEM raises·Cloud & Workload Security — where cloud logs join the picture

The six routes of security — and which one is yours

Boundary — the terms this buyer confuses

SIEM vs XDR vs log management · SIEM vs SOAR

Four terms this buyer confuses, and nothing more. They are adjacent and widening scopes — each one records more or acts more, costs more, and needs more people to run. None is a better version of another.

Log management

Collect, keep, search. The storage and the retention mandate live here; so does the first half of every meter. Splunk's platform, FortiAnalyzer, Log360's entry tiers. Not a SIEM until correlation, detections and cases sit on top.

SIEM

Log management plus correlation across sources, detection content, cases and compliance reporting. Vendor-neutral by design — it ingests everything you run. Splunk ES, Log360, FortiSIEM, Falcon Next-Gen SIEM, SentinelOne AI SIEM, KUMA. Needs a tuner or it is an archive.

XDR

Correlation too — but from one vendor's sensors (endpoint, email, cloud, identity) inside their platform, pre-tuned by them. Narrower than a SIEM, far less work; the 'X' often means 'our stack'. Platform vendors sell XDR as the reason you do not need a SIEM; regulators and third-party logs often disagree.

SOAR

Automation and case management over whatever raises alerts: playbooks that enrich, contain, notify, close. Adjacent, not a SIEM — it acts on detections, it does not make them. Included at CrowdStrike and SentinelOne; separate at Splunk and Fortinet; workflow-grade inside Log360 and KUMA.

Widening scopes, not tiers. Log management → SIEM adds correlation and detections; XDR is a vendor’s pre-tuned subset; SOAR acts on what either raises. Broader ingests more, costs more per gigabyte and per engineer, and only earns it if someone tunes the detections. Buy the scope your people can run — and let the MDR guide supply the people if they do not exist.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Six variables decide this purchase. The instrument tests the meter, deployment, automation and the India line; retention, content and who tunes it are prose because the honest answers are “your mandate”, “everyone ships content” and “your headcount”.

01

Ingest-based vs node-based vs flat pricing

Per GB / day grows with volume forever (Splunk, CrowdStrike, SentinelOne, FortiSIEM's GB option); per source, device or EPS flattens (Log360, FortiSIEM, KUMA); workload compute (Splunk SVCs) sits between. Decides total cost more than any feature.

02

Log retention requirements

CERT-In's 180 days in India; RBI and SEBI CSCRF add theirs; your sector may add more. Retention × ingest is the cloud bill; retention × disk is the on-prem one.

03

Detection content out of the box vs built by you

Every SIEM ships content; the gap between a SIEM and an archive is who tunes it against your estate.

04

Who tunes it

The headcount that decides whether you bought a SIEM or a log archive. If nobody, the MDR guide — or a platform-native XDR — is the honest purchase.

05

SOAR and automation depth

Included (CrowdStrike Fusion, SentinelOne Hyperautomation), workflow-grade (Log360, FortiSIEM, KUMA) or a separate SKU (Splunk SOAR, FortiSOAR). Automation over untuned detections automates noise.

06

Deployment model and India residency

On-prem (Splunk Enterprise, Log360, FortiSIEM, FortiAnalyzer, KUMA) satisfies residency by definition; documented India cloud regions are FortiSIEM Cloud and SentinelOne (Mumbai) and Log360 Cloud; CrowdStrike is announced.

The narrowing instrument · the reasoning is the product

Narrow 10 products to your shortlist

Set what holds for you. Products that fail a constraint fade with the reason on them; SOAR-only and log-only products fade when a chip is about the SIEM itself. Unset a chip and everything returns.

India

Pricing model

What you are buying

Deployment

Automation

Data volume

Retention mandates, detection content and India cloud regions are in the notes below, not chips — every product retains and ships content, and on-prem satisfies residency by definition.

Still in10/ 10
Splunk logo
~$120–225₹9,960

per GB / day / year reported (platform $100–180 + ES $20–45) on Splunk Cloud or Enterprise; or workload pricing (SVCs ~$55–75k / yr each); ESCU detection content

SOCs that want the reference SIEM — the deepest search language, the largest content and integration ecosystem, on-prem or cloud — and have the engineers to run it.

The catch: The licence is the small number: ingest grows, SOAR is a separate product, and an untuned Splunk is the most expensive log archive there is; India cloud region not documented.

Ingest or workloadOn-prem or cloudSOAR separate
Intel page →
Splunk logo
~$100–180₹8,300

per GB / day / year reported; the data platform under ES, ITSI and Observability

Teams that need log search and analytics at scale without the SIEM application on top — yet.

The catch: Log management and analytics, not a SIEM until you add Enterprise Security (and its price); the same ingest economics apply.

Log managementIngest or workloadPlatform
Intel page →
Splunk logo
Quote

per user / per action; playbooks and case management over ES or other SIEMs

SOCs automating triage and response around Splunk (or another SIEM).

The catch: A separate SKU from ES; automation only — it is not a SIEM; quote-only.

SOARSeparate SKU
Intel page →
ManageEngine logo
$300–1,995₹24,900

per year entry tiers (Basic $300 · Standard $995 · Professional $1,995; MSSP $194 / mo); priced by log sources, unlimited users; Zoho-hosted cloud with India data centres

Mid-market and regulated Indian estates that want a SIEM with UEBA and compliance reports priced by sources, not gigabytes, from an India-built vendor.

The catch: Predictable and cheap until the source count climbs; SOAR is built-in workflows rather than a full automation platform; documented scale tops out below the hyperscale SIEMs.

India-builtPer sourceOn-prem or cloud
Intel page →
Fortinet logo
Quote

per device / EPS or per GB / day subscription; appliance, VM or FortiSIEM Cloud (Mumbai region); FortiSOAR separate

Fortinet Security Fabric estates that want SIEM plus CMDB-style asset context, on appliances or in a Mumbai-hosted cloud.

The catch: Full SOAR is FortiSOAR (separate); strongest inside a Fortinet estate; quote-only across several meters.

Device / EPS or GBMumbai cloud regionSecurity Fabric
Intel page →
Fortinet logo

appliance / VM / cloud licensed by devices and GB / day; Fortinet-centric logging, analytics and playbooks

Fortinet estates that need fabric logging, reporting and automation before (or instead of) a full SIEM.

The catch: Log analytics for the Fortinet fabric — third-party breadth and SIEM correlation are FortiSIEM's job.

Log managementFortinet-centricPlaybooks
Intel page →
CrowdStrike logo
~$5.95 / GB

AWS Marketplace pay-as-you-go $5.95 / GB (13-month retention); list reported ~$2,700 per GB / day / year for third-party data; 10 GB / day of third-party data included with Falcon Insight; Fusion SOAR included

Falcon estates that want SIEM on the data already in the platform, with third-party ingestion priced per GB and SOAR in the box.

The catch: Cloud-only; third-party ingest beyond the included 10 GB / day is where the bill lives; India in-country cloud announced, not yet documented live.

Per GB ingestSOAR includedCloud-only
Intel page →
CrowdStrike logo

agentic automation over Falcon Next-Gen SIEM and Fusion workflows

Falcon SOCs pushing triage and response automation beyond playbooks.

The catch: Falcon-only; quote-only; not a SIEM on its own.

SOARFalcon-only
Intel page →
SentinelOne logo

consumption per GB / day of ingested data (rates not published); Singularity Data Lake; Hyperautomation (SOAR) and Purple AI included in platform packages; Mumbai region

SentinelOne estates that want SIEM on the Singularity Data Lake with automation and an AI analyst in the same console, with a Mumbai data region.

The catch: Rates are not published — the per-GB consumption is a quote; cloud-only; strongest when SentinelOne is already the agent.

Per GB ingestSOAR includedMumbai region
Intel page →
Kaspersky logo
Quote

licensed by events per second (EPS); on-prem; documented 300,000+ EPS per correlation node

Estates that want a high-throughput on-prem SIEM priced by EPS rather than gigabytes, with Kaspersky's detection content.

The catch: Procurement-sensitive in some sectors and countries (check your regulator); automation is playbook-grade rather than a full SOAR; quote-only.

Per EPSOn-premProcurement caveat
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

India-built vendorRules out Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Splunk SOAR, Fortinet FortiSIEM, Fortinet FortiAnalyzer, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA) — not an India-built vendor. That leaves ManageEngine Log360 (on-prem) / Log360 Cloud.

Ingest-based pricingRules out Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM; ManageEngine Log360 (on-prem) / Log360 Cloud and Kaspersky SIEM (KUMA) — priced per source / EPS, not by data volume. That leaves Splunk Enterprise Security, Fortinet FortiSIEM, CrowdStrike Falcon Next-Gen SIEM and SentinelOne Singularity AI SIEM. It flags Splunk Enterprise Security — Also offers workload (compute) pricing and Fortinet FortiSIEM — GB / day subscription is one of its meters; device / EPS is the other — marked on the cards, not removed.

Per source / device / EPS pricingRules out Splunk Enterprise Security, CrowdStrike Falcon Next-Gen SIEM and SentinelOne Singularity AI SIEM — ingest or workload-compute pricing, not per source; Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM. That leaves ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM and Kaspersky SIEM (KUMA). It flags Fortinet FortiSIEM — Device / EPS meter available; GB / day is the other — marked on the cards, not removed.

A full SIEMRules out Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM. That leaves Splunk Enterprise Security, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, CrowdStrike Falcon Next-Gen SIEM, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA).

Self-hosted or on-premRules out CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR and SentinelOne Singularity AI SIEM — cloud-only. That leaves Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Splunk SOAR, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, Fortinet FortiAnalyzer and Kaspersky SIEM (KUMA).

SOAR includedRules out Splunk Enterprise Security and Splunk Platform (Enterprise / Cloud) — SOAR is a separate product from this vendor. That leaves Splunk SOAR, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, Fortinet FortiAnalyzer, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA). It flags ManageEngine Log360 (on-prem) / Log360 Cloud — Built-in workflows / playbooks rather than a full SOAR platform, Fortinet FortiSIEM — Built-in workflows / playbooks rather than a full SOAR platform, Fortinet FortiAnalyzer — Built-in workflows / playbooks rather than a full SOAR platform and Kaspersky SIEM (KUMA) — Built-in workflows / playbooks rather than a full SOAR platform — marked on the cards, not removed.

Above 1 TB / dayRules nothing out on published terms. It flags ManageEngine Log360 (on-prem) / Log360 Cloud — Documented scale is mid-market — marked on the cards, not removed.

India data residency (cloud)Documented: FortiSIEM Cloud (Mumbai region), SentinelOne Singularity (Mumbai), ManageEngine Log360 Cloud (Zoho India data centres). CrowdStrike's India in-country cloud is announced (January 2026), not yet documented live; Splunk Cloud publishes no Mumbai region; Kaspersky SIEM is on-prem. Nothing is ruled out on it — on-prem satisfies residency by definition, which is half the reason Log360, FortiSIEM and KUMA are on Indian shortlists.

Detection content out of the box vs built by youRules nothing out: every SIEM here ships detection content (Splunk ESCU, Log360 correlation rules and UEBA, FortiSIEM rules, Falcon detections, SentinelOne content, Kaspersky rules). What differs is who tunes it against your estate — and an untuned SIEM is an expensive log archive. The tuning headcount is the variable, and it is prose because it is yours.

Log retention mandatesNot a chip — retention is a configuration and a storage bill, not a capability: CERT-In's 2022 directions require 180 days of ICT logs in India; RBI and SEBI CSCRF add their own. Every product here retains; what you pay is ingest × retention (cloud) or disk (on-prem). Confirm the mandate before the ingest estimate, not at the audit.

Narrow to your situation

Eight situations, eight shortlists — starting from the meter

Each shortlist begins with how you will pay (gigabytes, sources, EPS) and where the logs may live. The feature list comes after.

Mid-market, regulated, India — predictable price, logs in India

Why: Per-source or per-EPS pricing, on-prem or an India-hosted cloud, compliance reports for the Indian regulators — and an India-built vendor in Log360.

The trade-off: Documented scale tops out below the hyperscale SIEMs; SOAR is built-in workflows rather than a platform; KUMA carries procurement caveats in some sectors.

You already run CrowdStrike Falcon

Why: Falcon data is already in the platform; 10 GB / day of third-party data is included with Insight, Fusion SOAR is in the box, and the per-GB meter is published on AWS Marketplace.

The trade-off: Third-party ingest beyond the included volume is the bill; cloud-only; India in-country cloud announced, not yet live.

You already run SentinelOne

Why: Singularity Data Lake with AI SIEM, Hyperautomation and Purple AI in the same console, and a Mumbai data region.

The trade-off: Consumption rates are not published — the per-GB price is a quote; one survivor here is the platform answer, not a gap. Splunk or Log360 remain the vendor-neutral alternatives.

A real SOC, with engineers, that wants the deepest search and content

Why: Splunk ES is the reference — SPL, ESCU content, the integration ecosystem — with SOAR alongside; Falcon Next-Gen SIEM is the platform-native alternative for Falcon estates.

The trade-off: Splunk's ingest economics and the tuning headcount are the contract; without engineers it is the most expensive archive in security.

Fortinet fabric estate

Why: FortiAnalyzer for fabric logging and playbooks; FortiSIEM for correlation, CMDB context and third-party sources, on appliances or in the Mumbai cloud region.

The trade-off: Strongest inside Fortinet; full SOAR is FortiSOAR, separate; several meters to match at quote.

Log management first, SIEM maybe later

Why: Search and retention at scale without the SIEM application's price — Splunk's platform, FortiAnalyzer for Fortinet estates, Log360's entry tiers for everyone else.

The trade-off: A log platform is not a SIEM until correlation, detections and cases are on it — and the ingest meter is the same.

Ingest is exploding and the bill is the problem

Why: Meters that are not gigabytes: per source (Log360), per EPS (KUMA), per device (FortiSIEM) — the cost curve flattens as volume grows.

The trade-off: Predictable meters trade volume risk for scale ceilings and narrower ecosystems; the honest alternative is filtering and tiering data before a per-GB SIEM, not abandoning it.

SOAR first — automate the triage you already have

Why: Splunk SOAR over ES or another SIEM; Charlotte Agentic SOAR and SentinelOne Hyperautomation included with their platforms.

The trade-off: Automation needs the detections to be good first — SOAR over an untuned SIEM automates noise.

The spine of the decision

Four meters, and why the cheapest year one is rarely the cheapest year three

Every SIEM quote is a bet on your data growth. The meter decides who wins that bet.

Meter 1

Ingest — per GB / day

You pay for volume, forever, times retention. Splunk Cloud is reported near $1,000 per GB / day / year at 50 GB / day (tapering with commit); CrowdStrike publishes $5.95 / GB pay-as-you-go with 13-month retention and includes 10 GB / day of third-party data with Falcon Insight; SentinelOne meters per GB but does not publish rates. Year-one cheap, year-three expensive unless you filter at the source.

Meter 2

Workload — compute (SVCs)

Splunk's alternative: pay for search and indexing compute (~$55–75k per SVC per year reported) rather than volume. Flattens the data bet, moves it to a usage bet; suits estates that ingest a lot and search predictably.

Meter 3

Sources, devices, EPS

Log360 per log source with unlimited users ($300 → $1,995 / year entry tiers); FortiSIEM per device / EPS or per GB / day; KUMA per EPS. The curve flattens as volume grows; the trade is a scale ceiling and a narrower ecosystem.

Meter 4

Flat / included

SOAR included with a platform (Fusion, Hyperautomation), or the SIEM sold as part of a platform commit. The cheapest line is the one you already pay for — until the third-party data arrives.

Retention and residency

The mandate is a storage bill with a regulator attached.

  • CERT-In (2022): 180 days of ICT system logs, maintained in India. RBI and SEBI CSCRF add sector retention and reporting; your circular may add more. Retention × ingest is the cloud bill; retention × disk the on-prem one.
  • On-prem satisfies residency by definition — half the reason Log360, FortiSIEM and KUMA lead Indian shortlists. Documented India cloud regions: FortiSIEM Cloud (Mumbai), SentinelOne (Mumbai), Log360 Cloud (Zoho India DCs); CrowdStrike announced; Splunk Cloud publishes none.
  • Tiering is the lever: hot search for weeks, warm for the mandate, cold archive beyond — every vendor here supports it; few quotes assume it.

Who tunes it

An untuned SIEM is an expensive log archive.

  • Content exists everywhere — Splunk ESCU, Log360 rules and UEBA, FortiSIEM rules, Falcon and SentinelOne detections, KUMA content. None of it knows your estate until someone maps sources, suppresses the noise and writes the detections you actually need.
  • Budget the engineer (or the MDR that supplies one) beside the licence. At 2,000 endpoints the tuning is a role; at a TB / day it is a team.
  • XDR is the honest alternative when nobody will tune: pre-tuned correlation from one vendor’s sensors, narrower than a SIEM, far less work. Regulators and third-party logs decide whether it is enough.
  • SOAR last: automate after the detections are good, or you automate noise.
What breaks as you grow

What changes at 50 GB, 500 GB and 5 TB a day

SIEMs scale by data, not by seats. Each step changes which meter survives and how many people the detections need.

50GB / day

The meter is the constraint

  • Per-GB is survivable; per-source is cheaper; the difference is the retention mandate times the volume.
  • Log360, FortiSIEM, KUMA and the platform-native SIEMs with included data fit this band; Splunk ES is rarely the cheapest here.
  • One engineer tunes part-time — or nobody does, and it becomes an archive.

Put this in your PoC

Estimate your real volume from a week of sources; price it at 180 days and at your mandate; compare per-GB against per-source with the same sources.

500GB / day

Tuning and filtering are the constraint

  • Filtering and tiering at the source decide whether per-GB is affordable; workload pricing starts to make sense.
  • Detections need an owner; alert fatigue is now a staffing problem, not a tool problem.
  • Third-party ingest is where platform-native SIEMs stop being 'included'.

Put this in your PoC

Measure alerts per analyst per day for a month; ask each vendor what the bill is with 30% of volume filtered or tiered.

5,000GB / day

Architecture and sovereignty are the constraint

  • Multi-tenant, multi-region SIEM with delegated access; residency per source; EPS-based or workload pricing on the table.
  • Detection engineering is a team with a pipeline; SOAR is mandatory to survive the volume.
  • Migration now means rewriting every detection rule — plan the exit before signing the entry.

Put this in your PoC

Load-test your peak EPS; confirm region sharding and retention tiers in writing; price the exit.

Splunk, CrowdStrike, SentinelOne, FortiSIEM and KUMA document very large deployments (KUMA 300,000+ EPS per node); Log360’s documented scale is mid-market — flagged, not ruled out. Where a specific console strains for your volume: [TechBag to confirm].

The switching cost

Migration means rewriting every detection rule

Sources re-point in weeks. The detections, the parsers, the dashboards and the years of logs under a retention mandate are what make a SIEM migration a year, not a quarter.

Sources and collectors

Re-point syslog, agents and API connectors; re-parse each source's format for the new platform. Weeks per estate, scriptable in parts.

Exit costRe-point, re-parse

Detections and dashboards

Every correlation rule, every tuned exclusion and every compliance dashboard is rewritten in the new language — SPL is not KQL is not Log360's rules. The year.

Exit costRewrite

Retained logs

Logs under a mandate must stay searchable for the mandate; either keep the old SIEM in read-only for the period or export and re-index. Both cost.

Exit costKeep or re-index

Playbooks and integrations

SOAR playbooks, ticketing and MDR integrations are rebuilt; the MDR may have to re-onboard the new SIEM as a source.

Exit costRebuild

Detection-rewrite months and retained-log strategy for your estate: [TechBag to confirm] — TechBag scopes it from your rule count, sources and mandate.

What it costs

The licence is the small number

What you may already hold, the meters compared in USD and INR at three daily volumes, and what the licence leaves out — retention, tuning, and the exit.

01

Do you already own one?

Four places a SIEM — or enough of one — may already be on your invoice.

Microsoft 365 E5
Partly E5 carries Defender XDR (correlation across Microsoft sensors) and Sentinel benefits (a daily data grant for Microsoft 365 logs). Sentinel itself is Azure consumption per GB — a SIEM you already half-pay for if the estate is Microsoft.
Your EDR platform
Often CrowdStrike (Next-Gen SIEM with 10 GB / day of third-party data included with Insight), SentinelOne (AI SIEM on the Data Lake), Trend, Sophos and Palo Alto all sell SIEM or XDR on the sensor you run. The included part is the vendor’s data; the bill is the rest.
Your firewall vendor
Sometimes FortiAnalyzer logs the Fortinet fabric and runs playbooks; FortiSIEM adds correlation. Check Point, Cisco and Palo Alto have their own. Fabric logging is not a SIEM until third-party sources are in.
Your cloud provider
Partly AWS Security Lake, Azure Sentinel and Google Security Command Center / Chronicle ingest their own clouds cheaply. One cloud each — the vendor-neutral SIEM question remains.

If the logs you must keep are already sitting somewhere you pay for, we say so — and then price what it costs to keep them for the mandate.

02

What the rest actually cost

Reported and published rates per meter (INR for scale), then worked at 50 / 500 / 5,000 GB a day. Per-source and per-EPS products cannot be expressed per gigabyte — the grid says so rather than inventing a conversion.

50GB / day · per year
  • CrowdStrike Next-Gen SIEM — third-party data(PAYG $5.95 / GB → list ~$2,700 / GB / day / yr; 10 GB / day included)$86,8701,08,000 ₹72,10,210₹89,64,000
  • Splunk Cloud platform(reported ~$750–1,620 / GB / day / yr, tapering with commit)$37,50081,000 ₹31,12,500₹67,23,000
  • Splunk Enterprise Security add-on(reported +$20–45 / GB / day / yr)$12,00027,000 ₹9,96,000₹22,41,000
  • SentinelOne AI SIEM(per GB, rates not published)Quote / other meter
  • FortiSIEM(GB / day subscription or device / EPS — quote)Quote / other meter
  • ManageEngine Log360(per source — $300 / $995 / $1,995 / yr entry tiers; not per GB)Quote / other meter
  • Kaspersky SIEM / KUMA(per EPS — quote)Quote / other meter
  • FortiAnalyzer(devices / GB — quote)Quote / other meter
500GB / day · per year
  • CrowdStrike Next-Gen SIEM — third-party data(PAYG $5.95 / GB → list ~$2,700 / GB / day / yr; 10 GB / day included)$10,64,15813,23,000 ₹8,83,25,114₹10,98,09,000
  • Splunk Cloud platform(reported ~$750–1,620 / GB / day / yr, tapering with commit)$3,75,0008,10,000 ₹3,11,25,000₹6,72,30,000
  • Splunk Enterprise Security add-on(reported +$20–45 / GB / day / yr)$1,20,0002,70,000 ₹99,60,000₹2,24,10,000
  • SentinelOne AI SIEM(per GB, rates not published)Quote / other meter
  • FortiSIEM(GB / day subscription or device / EPS — quote)Quote / other meter
  • ManageEngine Log360(per source — $300 / $995 / $1,995 / yr entry tiers; not per GB)Quote / other meter
  • Kaspersky SIEM / KUMA(per EPS — quote)Quote / other meter
  • FortiAnalyzer(devices / GB — quote)Quote / other meter
5,000GB / day · per year
  • CrowdStrike Next-Gen SIEM — third-party data(PAYG $5.95 / GB → list ~$2,700 / GB / day / yr; 10 GB / day included)$1,08,37,0331,34,73,000 ₹89,94,73,739₹1,11,82,59,000
  • Splunk Cloud platform(reported ~$750–1,620 / GB / day / yr, tapering with commit)$37,50,00081,00,000 ₹31,12,50,000₹67,23,00,000
  • Splunk Enterprise Security add-on(reported +$20–45 / GB / day / yr)$12,00,00027,00,000 ₹9,96,00,000₹22,41,00,000
  • SentinelOne AI SIEM(per GB, rates not published)Quote / other meter
  • FortiSIEM(GB / day subscription or device / EPS — quote)Quote / other meter
  • ManageEngine Log360(per source — $300 / $995 / $1,995 / yr entry tiers; not per GB)Quote / other meter
  • Kaspersky SIEM / KUMA(per EPS — quote)Quote / other meter
  • FortiAnalyzer(devices / GB — quote)Quote / other meter
The grid is the meter, not the bill. Per-GB lines exclude retention beyond the included window, premium support and the engineers; per-source and per-EPS products are deliberately not converted — a conversion would be fiction. Price Log360, FortiSIEM and KUMA on your source count and peak EPS.
Tier- and term-match. Splunk platform is not Splunk ES; Falcon Next-Gen SIEM’s included data is Falcon data plus 10 GB / day, not your firewall logs; AWS pay-as-you-go is not a three-year commit. Compare the same volume, the same retention, the same term.
The India line. Log360 is India-built with INR pricing by source; FortiSIEM Cloud and SentinelOne document Mumbai regions; on-prem (Splunk Enterprise, Log360, FortiSIEM, KUMA) keeps the logs in India by construction.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

Retention beyond the included window

Per-GB meters quote a retention (CrowdStrike 13 months PAYG; Splunk by tier); the mandate may want 180 days hot and years cold. Retention × volume is the part of the bill that grows after year one — and it multiplies at renewal.

The tuner

Detection engineering is a role at 2,000 endpoints and a team at a TB / day. Budget it beside the licence or buy the people through the MDR guide; a SIEM nobody tunes is an archive with a dashboard.

The rewrite

Leaving means rewriting every detection in the new language and keeping the old logs searchable for the mandate — the switching-cost section. Your rule count and months: [TechBag to confirm].

Before you commit

What goes wrong

Documented meter behaviour and programme failures, cross-checked against TechBag engagements before any becomes a named case. Most are visible in the quote if you know where to look.

Ingest costs multiplying after year one

Volume grew, retention stayed, the per-GB meter did what it said. Filtering and tiering at the source were never designed in.

Retention mandates discovered at audit

CERT-In's 180 days, RBI's and SEBI's retention — found when the regulator asked, after the cheapest retention tier was chosen.

No engineering capacity to write detections

Content shipped; nobody mapped sources or suppressed noise; the SIEM became a log archive with an invoice.

Alert fatigue at volume

Untuned detections at 500 GB a day outran the team; real alerts drowned. A staffing problem bought as a tool.

Migration meaning every detection rule rewritten

Years of tuning in one vendor's language; the new platform started empty. The exit nobody priced.

'Included' SIEM that wasn't

The platform's SIEM was free for the platform's data; the firewall and identity logs were the bill. Name the third-party volume before signing.

XDR sold as a SIEM replacement

Pre-tuned correlation from one vendor's sensors covered their stack; the regulator wanted everything, retained in India. Different scope.

SOAR over untuned detections

Playbooks automated the noise faster. Automate after the detections are good.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Security map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.