Two honest quotes. Three times apart.
SIEM vendors meter different things, so two quotes can both be accurate and still not be comparable. This page is about what moves the number, which is more useful at this stage than a number you cannot act on.
Managed SIEM pricing is driven by six things: daily ingest volume, retention period, whether older data stays instantly searchable, how much you filter before storage, the number of sources and the parser work they need, and whether somebody operates the platform or only licenses it.
Vendors meter different combinations of those, which is why two honest quotes are frequently not comparable. Fix your own numbers first, then ask each vendor to price that exact scenario.
Vijilan does not publish rates, because they are channel rates behind partner verification. The pricing wizard scopes a real number against a verified work email.
The structural point: on an ingestion-priced platform, every improvement in coverage raises the bill. Index-free retention breaks that link, which is why ThreatLog™ ships in every ThreatRespond™ tier rather than being priced separately.
Six drivers, in rough order.
Daily ingest volume
The headline meter almost everywhere. Worth knowing before you shop: most organizations cannot estimate it within a factor of two, and a quote built on a guess gets revised the month after go-live.
Retention period
How long data stays queryable, and usually where the real money is. A compliance framework requiring a year of retrievable logs prices very differently from thirty days, and the requirement is frequently discovered after the platform is chosen.
Hot versus cold
Whether older data is instantly searchable or has to be rehydrated. Cheap cold storage looks like a saving until an incident investigation needs ninety days of history on a Friday night.
What you send, and what you drop
Pipeline tooling filters, reduces and routes before storage, which on a per-gigabyte model is the single largest lever on the bill. It is also the lever most likely to be pulled too hard, because the data you dropped is the data you do not have during an investigation.
Number of sources and parser work
Sources with a purpose-built connector are quick. The ones without consume engineering time nobody budgeted, and they are usually the interesting ones: the line-of-business application, the OT segment, the appliance from 2014.
Operated, or just licensed
A SIEM license and a SIEM somebody runs are different purchases. Detection engineering, tuning and 24/7 triage are the larger number for most teams, and they do not appear on a platform quote at all.
The pricing model changes your behavior, which is the real cost.
On a per-gigabyte platform, connecting a source makes you safer and more expensive at the same time. Nobody decides to have worse security; they decide not to connect one more firewall this quarter, and then again next quarter. The gap shows up during an investigation, as evidence that was never collected.
Two things address it. Pipeline tooling filters and routes deliberately before storage, with a record of what was dropped and why. And index-free retention removes the escalation, so keeping twelve months is a decision about usefulness rather than about budget.
Including why we will not print a rate.
How much does a managed SIEM cost?
We do not publish rates, because they are channel rates that sit behind partner verification. That is less evasive than it sounds: the useful thing at this stage is not a number you cannot act on, it is understanding why two quotes for apparently the same thing differ by a factor of three. That difference is almost always retention, what counts as ingest, and whether operation is included.
Why is SIEM pricing so hard to compare?
Because vendors meter different things. Per gigabyte ingested, per user, per node, per daily ingest ceiling, per workload, or a commitment tier that discounts one of those. Two quotes can be honest and still not be comparable. The only reliable method is to fix your own numbers first, meaning volume, retention and sources, and then ask each vendor to price that exact scenario.
What is the per-gigabyte problem?
On an ingestion-priced platform, every improvement in coverage raises the bill. Connecting the firewall, turning on verbose authentication logging, adding the SaaS application: each one makes you safer and more expensive. Over time that quietly rewards collecting less than you should, and the gap only becomes visible during an investigation where the evidence is missing.
What does index-free change?
It breaks the link between retention and price escalation, which is what makes long retention affordable rather than aspirational. ThreatLog™ is index-free and ships in every ThreatRespond™ tier rather than arriving as a separate purchase; NextDefend™ is managed CrowdStrike Falcon® Next-Gen SIEM, also index-free, where a customer wants the platform in their own name.
Should we filter data to reduce cost?
Some, deliberately, with a record of what you dropped and why. Pipeline tooling like Cribl Stream and Falcon Onum exists for exactly this. The failure mode is filtering to hit a budget rather than to remove genuine noise, which produces a cheaper platform and a worse investigation, and nobody discovers which until an incident.
Is a managed SIEM cheaper than running our own?
On license alone, often not. On total cost, usually, because the comparison people forget is the detection engineering and the 24/7 rotation. A SIEM with nobody writing and maintaining detection content is an expensive log archive, and that is the most common way SIEM spend disappoints.
How do we get an actual number?
The pricing wizard takes a work email and routes MSPs to the partner portal and enterprises to a scoped conversation. Before that, the more useful preparation is knowing your daily volume, your retention requirement and your source list, because a quote built on estimates gets revised the month after go-live.
Bring your volume,
retention and source list.
With those three numbers a quote is a short conversation. Without them it is an estimate that gets revised the month after go-live, which helps nobody.