Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
A SIEM is paid for by what you feed it — gigabytes a day, sources, or events per second — for as long as a regulator says you must keep it, and it only detects what someone tuned it to detect. The meter and the tuner decide the cost; the feature list does not.
Splunk Cloud is reported at roughly $1,000 per GB / day per year at 50 GB / day; ManageEngine Log360 starts at $300 a year priced by log sources. Same logs, two different bills — and the second does not grow with volume.
Already decided — before the PoC
Still yours to weigh
A place where the logs from everything — endpoints, firewalls, identity, cloud, mail, applications — land, are kept for as long as policy and the regulator require, and are searched and correlated: this login, from that country, after this alert, touching that server. The correlation rules are detections; the things they raise are cases; the team that reads them is the SOC. Log management is the first half (collect, keep, search); SIEM is the second (correlate, detect, investigate).
Three things cost money and the feature grid shows none of them: the meter (gigabytes a day, sources, events per second, or compute), the retention the regulator mandates, and the people who tune it. An untuned SIEM is an expensive log archive. A SOAR beside it automates whatever the detections raise — good or noise. The MDR guide is where the people come from if you do not have them.
The meter decides more than any feature
Ingest-based vs node-based vs flat pricing decides total cost more than any capability. Per-GB grows with volume forever; per-source and per-EPS flatten; workload compute sits in between. Estimate your daily volume and your retention before you read a datasheet.
Often confused withEndpoint Protection / XDR — both claim correlation, differently →·Managed Detection & Response — the people who read what the SIEM raises →·Cloud & Workload Security — where cloud logs join the picture →
Four terms this buyer confuses, and nothing more. They are adjacent and widening scopes — each one records more or acts more, costs more, and needs more people to run. None is a better version of another.
Log management
Collect, keep, search. The storage and the retention mandate live here; so does the first half of every meter. Splunk's platform, FortiAnalyzer, Log360's entry tiers. Not a SIEM until correlation, detections and cases sit on top.
SIEM
Log management plus correlation across sources, detection content, cases and compliance reporting. Vendor-neutral by design — it ingests everything you run. Splunk ES, Log360, FortiSIEM, Falcon Next-Gen SIEM, SentinelOne AI SIEM, KUMA. Needs a tuner or it is an archive.
XDR
Correlation too — but from one vendor's sensors (endpoint, email, cloud, identity) inside their platform, pre-tuned by them. Narrower than a SIEM, far less work; the 'X' often means 'our stack'. Platform vendors sell XDR as the reason you do not need a SIEM; regulators and third-party logs often disagree.
SOAR
Automation and case management over whatever raises alerts: playbooks that enrich, contain, notify, close. Adjacent, not a SIEM — it acts on detections, it does not make them. Included at CrowdStrike and SentinelOne; separate at Splunk and Fortinet; workflow-grade inside Log360 and KUMA.
Six variables decide this purchase. The instrument tests the meter, deployment, automation and the India line; retention, content and who tunes it are prose because the honest answers are “your mandate”, “everyone ships content” and “your headcount”.
Ingest-based vs node-based vs flat pricing
Per GB / day grows with volume forever (Splunk, CrowdStrike, SentinelOne, FortiSIEM's GB option); per source, device or EPS flattens (Log360, FortiSIEM, KUMA); workload compute (Splunk SVCs) sits between. Decides total cost more than any feature.
Log retention requirements
CERT-In's 180 days in India; RBI and SEBI CSCRF add theirs; your sector may add more. Retention × ingest is the cloud bill; retention × disk is the on-prem one.
Detection content out of the box vs built by you
Every SIEM ships content; the gap between a SIEM and an archive is who tunes it against your estate.
Who tunes it
The headcount that decides whether you bought a SIEM or a log archive. If nobody, the MDR guide — or a platform-native XDR — is the honest purchase.
SOAR and automation depth
Included (CrowdStrike Fusion, SentinelOne Hyperautomation), workflow-grade (Log360, FortiSIEM, KUMA) or a separate SKU (Splunk SOAR, FortiSOAR). Automation over untuned detections automates noise.
Deployment model and India residency
On-prem (Splunk Enterprise, Log360, FortiSIEM, FortiAnalyzer, KUMA) satisfies residency by definition; documented India cloud regions are FortiSIEM Cloud and SentinelOne (Mumbai) and Log360 Cloud; CrowdStrike is announced.
Set what holds for you. Products that fail a constraint fade with the reason on them; SOAR-only and log-only products fade when a chip is about the SIEM itself. Unset a chip and everything returns.
India
Pricing model
What you are buying
Deployment
Automation
Data volume
Retention mandates, detection content and India cloud regions are in the notes below, not chips — every product retains and ships content, and on-prem satisfies residency by definition.

per GB / day / year reported (platform $100–180 + ES $20–45) on Splunk Cloud or Enterprise; or workload pricing (SVCs ~$55–75k / yr each); ESCU detection content
SOCs that want the reference SIEM — the deepest search language, the largest content and integration ecosystem, on-prem or cloud — and have the engineers to run it.
The catch: The licence is the small number: ingest grows, SOAR is a separate product, and an untuned Splunk is the most expensive log archive there is; India cloud region not documented.

per GB / day / year reported; the data platform under ES, ITSI and Observability
Teams that need log search and analytics at scale without the SIEM application on top — yet.
The catch: Log management and analytics, not a SIEM until you add Enterprise Security (and its price); the same ingest economics apply.

per user / per action; playbooks and case management over ES or other SIEMs
SOCs automating triage and response around Splunk (or another SIEM).
The catch: A separate SKU from ES; automation only — it is not a SIEM; quote-only.

per year entry tiers (Basic $300 · Standard $995 · Professional $1,995; MSSP $194 / mo); priced by log sources, unlimited users; Zoho-hosted cloud with India data centres
Mid-market and regulated Indian estates that want a SIEM with UEBA and compliance reports priced by sources, not gigabytes, from an India-built vendor.
The catch: Predictable and cheap until the source count climbs; SOAR is built-in workflows rather than a full automation platform; documented scale tops out below the hyperscale SIEMs.

per device / EPS or per GB / day subscription; appliance, VM or FortiSIEM Cloud (Mumbai region); FortiSOAR separate
Fortinet Security Fabric estates that want SIEM plus CMDB-style asset context, on appliances or in a Mumbai-hosted cloud.
The catch: Full SOAR is FortiSOAR (separate); strongest inside a Fortinet estate; quote-only across several meters.

appliance / VM / cloud licensed by devices and GB / day; Fortinet-centric logging, analytics and playbooks
Fortinet estates that need fabric logging, reporting and automation before (or instead of) a full SIEM.
The catch: Log analytics for the Fortinet fabric — third-party breadth and SIEM correlation are FortiSIEM's job.

AWS Marketplace pay-as-you-go $5.95 / GB (13-month retention); list reported ~$2,700 per GB / day / year for third-party data; 10 GB / day of third-party data included with Falcon Insight; Fusion SOAR included
Falcon estates that want SIEM on the data already in the platform, with third-party ingestion priced per GB and SOAR in the box.
The catch: Cloud-only; third-party ingest beyond the included 10 GB / day is where the bill lives; India in-country cloud announced, not yet documented live.

agentic automation over Falcon Next-Gen SIEM and Fusion workflows
Falcon SOCs pushing triage and response automation beyond playbooks.
The catch: Falcon-only; quote-only; not a SIEM on its own.

consumption per GB / day of ingested data (rates not published); Singularity Data Lake; Hyperautomation (SOAR) and Purple AI included in platform packages; Mumbai region
SentinelOne estates that want SIEM on the Singularity Data Lake with automation and an AI analyst in the same console, with a Mumbai data region.
The catch: Rates are not published — the per-GB consumption is a quote; cloud-only; strongest when SentinelOne is already the agent.

licensed by events per second (EPS); on-prem; documented 300,000+ EPS per correlation node
Estates that want a high-throughput on-prem SIEM priced by EPS rather than gigabytes, with Kaspersky's detection content.
The catch: Procurement-sensitive in some sectors and countries (check your regulator); automation is playbook-grade rather than a full SOAR; quote-only.
India-built vendorRules out Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Splunk SOAR, Fortinet FortiSIEM, Fortinet FortiAnalyzer, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA) — not an India-built vendor. That leaves ManageEngine Log360 (on-prem) / Log360 Cloud.
Ingest-based pricingRules out Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM; ManageEngine Log360 (on-prem) / Log360 Cloud and Kaspersky SIEM (KUMA) — priced per source / EPS, not by data volume. That leaves Splunk Enterprise Security, Fortinet FortiSIEM, CrowdStrike Falcon Next-Gen SIEM and SentinelOne Singularity AI SIEM. It flags Splunk Enterprise Security — Also offers workload (compute) pricing and Fortinet FortiSIEM — GB / day subscription is one of its meters; device / EPS is the other — marked on the cards, not removed.
Per source / device / EPS pricingRules out Splunk Enterprise Security, CrowdStrike Falcon Next-Gen SIEM and SentinelOne Singularity AI SIEM — ingest or workload-compute pricing, not per source; Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM. That leaves ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM and Kaspersky SIEM (KUMA). It flags Fortinet FortiSIEM — Device / EPS meter available; GB / day is the other — marked on the cards, not removed.
A full SIEMRules out Splunk Platform (Enterprise / Cloud) and Fortinet FortiAnalyzer — log management / analytics without SIEM correlation and case management; Splunk SOAR and CrowdStrike Charlotte Agentic SOAR — automation (SOAR), not a SIEM. That leaves Splunk Enterprise Security, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, CrowdStrike Falcon Next-Gen SIEM, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA).
Self-hosted or on-premRules out CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR and SentinelOne Singularity AI SIEM — cloud-only. That leaves Splunk Enterprise Security, Splunk Platform (Enterprise / Cloud), Splunk SOAR, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, Fortinet FortiAnalyzer and Kaspersky SIEM (KUMA).
SOAR includedRules out Splunk Enterprise Security and Splunk Platform (Enterprise / Cloud) — SOAR is a separate product from this vendor. That leaves Splunk SOAR, ManageEngine Log360 (on-prem) / Log360 Cloud, Fortinet FortiSIEM, Fortinet FortiAnalyzer, CrowdStrike Falcon Next-Gen SIEM, CrowdStrike Charlotte Agentic SOAR, SentinelOne Singularity AI SIEM and Kaspersky SIEM (KUMA). It flags ManageEngine Log360 (on-prem) / Log360 Cloud — Built-in workflows / playbooks rather than a full SOAR platform, Fortinet FortiSIEM — Built-in workflows / playbooks rather than a full SOAR platform, Fortinet FortiAnalyzer — Built-in workflows / playbooks rather than a full SOAR platform and Kaspersky SIEM (KUMA) — Built-in workflows / playbooks rather than a full SOAR platform — marked on the cards, not removed.
Above 1 TB / dayRules nothing out on published terms. It flags ManageEngine Log360 (on-prem) / Log360 Cloud — Documented scale is mid-market — marked on the cards, not removed.
India data residency (cloud)Documented: FortiSIEM Cloud (Mumbai region), SentinelOne Singularity (Mumbai), ManageEngine Log360 Cloud (Zoho India data centres). CrowdStrike's India in-country cloud is announced (January 2026), not yet documented live; Splunk Cloud publishes no Mumbai region; Kaspersky SIEM is on-prem. Nothing is ruled out on it — on-prem satisfies residency by definition, which is half the reason Log360, FortiSIEM and KUMA are on Indian shortlists.
Detection content out of the box vs built by youRules nothing out: every SIEM here ships detection content (Splunk ESCU, Log360 correlation rules and UEBA, FortiSIEM rules, Falcon detections, SentinelOne content, Kaspersky rules). What differs is who tunes it against your estate — and an untuned SIEM is an expensive log archive. The tuning headcount is the variable, and it is prose because it is yours.
Log retention mandatesNot a chip — retention is a configuration and a storage bill, not a capability: CERT-In's 2022 directions require 180 days of ICT logs in India; RBI and SEBI CSCRF add their own. Every product here retains; what you pay is ingest × retention (cloud) or disk (on-prem). Confirm the mandate before the ingest estimate, not at the audit.
Each shortlist begins with how you will pay (gigabytes, sources, EPS) and where the logs may live. The feature list comes after.
Why: Per-source or per-EPS pricing, on-prem or an India-hosted cloud, compliance reports for the Indian regulators — and an India-built vendor in Log360.
The trade-off: Documented scale tops out below the hyperscale SIEMs; SOAR is built-in workflows rather than a platform; KUMA carries procurement caveats in some sectors.
Why: Falcon data is already in the platform; 10 GB / day of third-party data is included with Insight, Fusion SOAR is in the box, and the per-GB meter is published on AWS Marketplace.
The trade-off: Third-party ingest beyond the included volume is the bill; cloud-only; India in-country cloud announced, not yet live.
Why: Singularity Data Lake with AI SIEM, Hyperautomation and Purple AI in the same console, and a Mumbai data region.
The trade-off: Consumption rates are not published — the per-GB price is a quote; one survivor here is the platform answer, not a gap. Splunk or Log360 remain the vendor-neutral alternatives.
Why: Splunk ES is the reference — SPL, ESCU content, the integration ecosystem — with SOAR alongside; Falcon Next-Gen SIEM is the platform-native alternative for Falcon estates.
The trade-off: Splunk's ingest economics and the tuning headcount are the contract; without engineers it is the most expensive archive in security.
Why: FortiAnalyzer for fabric logging and playbooks; FortiSIEM for correlation, CMDB context and third-party sources, on appliances or in the Mumbai cloud region.
The trade-off: Strongest inside Fortinet; full SOAR is FortiSOAR, separate; several meters to match at quote.
Why: Search and retention at scale without the SIEM application's price — Splunk's platform, FortiAnalyzer for Fortinet estates, Log360's entry tiers for everyone else.
The trade-off: A log platform is not a SIEM until correlation, detections and cases are on it — and the ingest meter is the same.
Why: Meters that are not gigabytes: per source (Log360), per EPS (KUMA), per device (FortiSIEM) — the cost curve flattens as volume grows.
The trade-off: Predictable meters trade volume risk for scale ceilings and narrower ecosystems; the honest alternative is filtering and tiering data before a per-GB SIEM, not abandoning it.
Why: Splunk SOAR over ES or another SIEM; Charlotte Agentic SOAR and SentinelOne Hyperautomation included with their platforms.
The trade-off: Automation needs the detections to be good first — SOAR over an untuned SIEM automates noise.
Every SIEM quote is a bet on your data growth. The meter decides who wins that bet.
Meter 1
Ingest — per GB / day
You pay for volume, forever, times retention. Splunk Cloud is reported near $1,000 per GB / day / year at 50 GB / day (tapering with commit); CrowdStrike publishes $5.95 / GB pay-as-you-go with 13-month retention and includes 10 GB / day of third-party data with Falcon Insight; SentinelOne meters per GB but does not publish rates. Year-one cheap, year-three expensive unless you filter at the source.
Meter 2
Workload — compute (SVCs)
Splunk's alternative: pay for search and indexing compute (~$55–75k per SVC per year reported) rather than volume. Flattens the data bet, moves it to a usage bet; suits estates that ingest a lot and search predictably.
Meter 3
Sources, devices, EPS
Log360 per log source with unlimited users ($300 → $1,995 / year entry tiers); FortiSIEM per device / EPS or per GB / day; KUMA per EPS. The curve flattens as volume grows; the trade is a scale ceiling and a narrower ecosystem.
Meter 4
Flat / included
SOAR included with a platform (Fusion, Hyperautomation), or the SIEM sold as part of a platform commit. The cheapest line is the one you already pay for — until the third-party data arrives.
Retention and residency
The mandate is a storage bill with a regulator attached.
Who tunes it
An untuned SIEM is an expensive log archive.
SIEMs scale by data, not by seats. Each step changes which meter survives and how many people the detections need.
The meter is the constraint
Put this in your PoC
Estimate your real volume from a week of sources; price it at 180 days and at your mandate; compare per-GB against per-source with the same sources.
Tuning and filtering are the constraint
Put this in your PoC
Measure alerts per analyst per day for a month; ask each vendor what the bill is with 30% of volume filtered or tiered.
Architecture and sovereignty are the constraint
Put this in your PoC
Load-test your peak EPS; confirm region sharding and retention tiers in writing; price the exit.
Splunk, CrowdStrike, SentinelOne, FortiSIEM and KUMA document very large deployments (KUMA 300,000+ EPS per node); Log360’s documented scale is mid-market — flagged, not ruled out. Where a specific console strains for your volume: [TechBag to confirm].
Sources re-point in weeks. The detections, the parsers, the dashboards and the years of logs under a retention mandate are what make a SIEM migration a year, not a quarter.
Sources and collectors
Re-point syslog, agents and API connectors; re-parse each source's format for the new platform. Weeks per estate, scriptable in parts.
Detections and dashboards
Every correlation rule, every tuned exclusion and every compliance dashboard is rewritten in the new language — SPL is not KQL is not Log360's rules. The year.
Retained logs
Logs under a mandate must stay searchable for the mandate; either keep the old SIEM in read-only for the period or export and re-index. Both cost.
Playbooks and integrations
SOAR playbooks, ticketing and MDR integrations are rebuilt; the MDR may have to re-onboard the new SIEM as a source.
Detection-rewrite months and retained-log strategy for your estate: [TechBag to confirm] — TechBag scopes it from your rule count, sources and mandate.
What you may already hold, the meters compared in USD and INR at three daily volumes, and what the licence leaves out — retention, tuning, and the exit.
Four places a SIEM — or enough of one — may already be on your invoice.
If the logs you must keep are already sitting somewhere you pay for, we say so — and then price what it costs to keep them for the mandate.
Reported and published rates per meter (INR for scale), then worked at 50 / 500 / 5,000 GB a day. Per-source and per-EPS products cannot be expressed per gigabyte — the grid says so rather than inventing a conversion.
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
Per-GB meters quote a retention (CrowdStrike 13 months PAYG; Splunk by tier); the mandate may want 180 days hot and years cold. Retention × volume is the part of the bill that grows after year one — and it multiplies at renewal.
Detection engineering is a role at 2,000 endpoints and a team at a TB / day. Budget it beside the licence or buy the people through the MDR guide; a SIEM nobody tunes is an archive with a dashboard.
Leaving means rewriting every detection in the new language and keeping the old logs searchable for the mandate — the switching-cost section. Your rule count and months: [TechBag to confirm].
Documented meter behaviour and programme failures, cross-checked against TechBag engagements before any becomes a named case. Most are visible in the quote if you know where to look.
Ingest costs multiplying after year one
Volume grew, retention stayed, the per-GB meter did what it said. Filtering and tiering at the source were never designed in.
Retention mandates discovered at audit
CERT-In's 180 days, RBI's and SEBI's retention — found when the regulator asked, after the cheapest retention tier was chosen.
No engineering capacity to write detections
Content shipped; nobody mapped sources or suppressed noise; the SIEM became a log archive with an invoice.
Alert fatigue at volume
Untuned detections at 500 GB a day outran the team; real alerts drowned. A staffing problem bought as a tool.
Migration meaning every detection rule rewritten
Years of tuning in one vendor's language; the new platform started empty. The exit nobody priced.
'Included' SIEM that wasn't
The platform's SIEM was free for the platform's data; the firewall and identity logs were the bill. Name the third-party volume before signing.
XDR sold as a SIEM replacement
Pre-tuned correlation from one vendor's sensors covered their stack; the regulator wanted everything, retained in India. Different scope.
SOAR over untuned detections
Playbooks automated the noise faster. Automate after the detections are good.
Vendor-neutral. No gated content.