SIEM cost optimisation in 2026 amounts to a $5B annual problem for the enterprises running the legacy SIEMs, and a $1B annual problem for the enterprises that already moved to the cloud native SIEMs. The cost has not gone down, the data volumes have not gone down, the licensing model has gotten worse. The honest guide covers where the money goes, where the money can come back, and where the money cannot come back.
Splunk Enterprise charges by the GB ingested, with the average enterprise running 5-20 TB per day, the cost running at $1M-$4M per year. Microsoft Sentinel charges by the GB ingested and the GB analysed, with the typical enterprise paying $300K-$1M per year. The Elastic SIEM charges by the node, with the typical enterprise running 20-50 nodes, the cost running at $200K-$500K per year. The 2026 state of the SIEM cost market amounts to a market where every vendor has raised prices, every enterprise has tried to optimise, every optimisation has trade offs.
Where the money goes
Three categories, in roughly that order of how much of the SIEM bill they account for. The first runs as the data ingestion category, with the SIEM ingesting 5-20 TB per day from the endpoints, the network, the cloud, the identity systems, the application logs. The data ingestion typically accounts for 50-70% of the SIEM bill. The second runs as the storage category, with the SIEM storing the data for 30-90 days for the hot storage, and 1-7 years for the cold storage, with the storage costs typically running at 10-20% of the bill. The third runs as the processing category, with the SIEM running the correlation rules, the detection rules, the ML models on the ingested data, with the processing costs typically running at 10-20% of the bill. The three categories together account for the typical SIEM bill.
What the typical enterprise has tried
Three approaches, in roughly that order of how often they have failed. The first runs as the data reduction approach, where the enterprise turns off the noisy data sources (the endpoint telemetry, the verbose application logs, the proxy logs), the SIEM bill drops, the SOC loses the visibility the noisy data provided. The second runs as the tiered storage approach, where the enterprise moves the old data to the cold storage, the SIEM bill drops, the SOC cannot search the old data when the SOC needs to. The third runs as the SIEM replacement approach, where the enterprise migrates to a cheaper SIEM, the migration costs more than the savings, the enterprise ends up with two SIEMs running. The three approaches together produce the failure pattern that the typical enterprise has not escaped.
How to actually reduce the cost
Three moves if you are trying to reduce the SIEM cost without losing the visibility. Profile the data, because the data the SIEM ingests falls into the categories (security critical, useful, noise, redundant), and the profile shows you what to keep, what to drop, what to tier. The profile without the action amounts to a chart nobody uses. Negotiate the contract, because the SIEM vendors have pricing flexibility, the typical enterprise that runs 5+ TB per day can get 30-50% off the list price, the enterprise that does not negotiate pays the list price. Build the detection pipeline, because the detection that runs on the cheap storage (the cold storage, the data lake, the SIEM adjacent tool) costs less than the detection that runs on the SIEM. The enterprise that profiles, negotiates, and builds the detection pipeline stands as the enterprise that gets the SIEM cost under control.

The bottom line
SIEM cost optimisation in 2026 amounts to a $5B annual problem. The three categories (data ingestion, storage, processing) account for the bill. The three failed approaches (data reduction, tiered storage, SIEM replacement) do not solve it. The enterprise that profiles the data, negotiates the contract, and builds the detection pipeline stands as the enterprise that gets the cost under control.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



