observabilitysecuritycost-optimizationcompliance

Security log retention cost: paying for a year of data nobody queries

Security logs have the longest retention requirements and the lowest query rate of any telemetry you keep. That combination makes them the single best candidate for tiering, and the most commonly mishandled.

The C3X Team··7 min read

Quick answer

Security logs typically require 12 months of retention with 90 days hot, and they are queried for roughly 0.1% of the stored volume in a normal year. Keeping 12 months of 60 GB/day in a hot SIEM tier at $2.50 per GB ingested plus retention costs well over $50,000 per month. Keeping 90 days hot and routing the remaining 9 months to S3 Glacier Instant Retrieval at $0.004 per GB-month drops the archive portion to roughly $65 per month. The discipline: separate the compliance requirement (retain) from the detection requirement (query fast), and price them differently.

Security telemetry has an unusual shape. The retention requirement is long, often 12 months and sometimes seven years. The query rate is extremely low: outside of an active investigation or an audit, almost nobody touches data older than a few weeks. And the volume is high, because you are keeping authentication events, network flow records, API calls, DNS queries, and endpoint telemetry from every system you own. Long retention plus low query rate plus high volume is precisely the profile that tiering was invented for.

What security telemetry actually costs in a hot tier

SourceTypical volumeHot tier cost at $2.50/GB ingest
VPC Flow Logs (500 ENIs)~25 GB/day$1,875 / month
CloudTrail data events~12 GB/day$900 / month
Authentication and IdP logs~3 GB/day$225 / month
DNS query logs~8 GB/day$600 / month
Endpoint / EDR telemetry~10 GB/day$750 / month
WAF and edge logs~2 GB/day$150 / month
Total60 GB/day$4,500 / month

That is ingestion only. Add retention: 12 months of 60 GB/day accumulates 21,900 GB. At a SIEM retention price of $0.10 to $0.20 per GB-month, the stored volume alone costs $2,190 to $4,380 per month by the end of year one, and the ingestion charge repeats every month. The all-in figure for a fully hot 12-month security data estate routinely exceeds $8,000 to $12,000 per month for a mid-sized organization, and considerably more once flow log volume grows with the network.

The tiering model

TierAgeStorage price21.9 TB at that price
Hot SIEM (indexed, sub-second)0 to 90 days~$0.15 / GB-month$821 (5.4 TB)
S3 Standard (Athena queryable)90 to 180 days$0.023 / GB-month$124 (5.4 TB)
S3 Glacier Instant Retrieval180 to 365 days$0.004 / GB-month$44 (11.1 TB)
S3 Glacier Deep Archive1 to 7 years$0.00099 / GB-month$152 (153 TB)

The arithmetic is not subtle. Holding the 180-to-365-day slice in Glacier Instant Retrieval costs $44 per month; holding the same slice in a hot SIEM tier costs roughly $1,665. The 38x difference is why every mature security data architecture has a cold tier, and why the ones that do not are the ones with six-figure annual line items nobody can justify.

Query economics in the cold tier

The objection is always "but we need to search it during an investigation". You do, occasionally, and it is affordable. Athena charges $5.00 per TB scanned. Querying the full 11.1 TB cold slice costs $55.50, and with Parquet formatting plus date and account partitioning a realistic investigative query scans perhaps 200 GB and costs $1.00. Even ten investigations a month touching a terabyte each is $50.

Glacier Instant Retrieval adds a retrieval charge of $0.03 per GB, so scanning 200 GB adds $6. Glacier Deep Archive requires a restore taking 12 hours at $0.02 per GB for bulk, which is fine for a compliance audit and wrong for an active incident. That is the whole reason the 180-to-365-day slice sits in Instant Retrieval rather than Deep Archive: you are buying the option to investigate at normal speed.

Storage format matters more than most teams expect. Converting JSON security logs to Parquet with appropriate partitioning typically reduces scanned bytes by 80% to 95% for selective queries, because Athena reads only the needed columns and partitions. That turns $55 full-table scans into $2 ones, which changes the cold tier from theoretically queryable to routinely queryable.

What must stay hot

Not everything can be tiered. Real-time detection rules need to evaluate events as they arrive, so the detection pipeline consumes the live stream regardless of where the data lands afterwards. Correlation rules with a 30-day lookback need 30 days accessible at low latency. Threat hunting workflows generally work over 90 days. Beyond that, the access pattern is audit and investigation, which tolerates seconds instead of milliseconds.

So the design is: stream everything through the detection engine, index 30 to 90 days in the hot tier based on your correlation window, and land the full stream in object storage in Parquet from day one so the archive is complete and queryable without a re-ingestion step. Costs for SIEM platforms vary widely, but this architecture is platform-independent.

Reducing the volume itself

Before tiering, trim. VPC Flow Logs in the default format include fields most detections never use, and switching to a custom format with only the needed fields cuts volume 30% to 40%. Aggregating flow logs at a 10-minute interval instead of 1 minute cuts records by up to 90% for steady connections, at the cost of timing granularity. CloudTrail data events for high-traffic S3 buckets can be scoped to sensitive prefixes rather than every object. Each of these removes cost at the most expensive meter.

Flow log configurations, CloudTrail trails, S3 lifecycle rules, and Glue catalogs are all Terraform, so the tiering architecture is code you can price. Run the plan against the resource catalog and the difference between a fully hot estate and a tiered one shows up as a number before you commit to twelve months of it.

FAQ

Why are security logs so expensive to retain?

They combine long retention requirements, typically 12 months and sometimes seven years, with high volume from flow logs, audit trails, DNS queries, and endpoint telemetry, and a very low query rate. A mid-sized organization generating 60 GB/day accumulates 21,900 GB in a year. Held entirely in a hot SIEM tier at around $2.50 per GB ingested plus $0.15 per GB-month retention, that routinely exceeds $8,000 to $12,000 per month.

How much does tiering security logs save?

Roughly 38x on the cold slice. Holding 11.1 TB covering days 180 to 365 in S3 Glacier Instant Retrieval at $0.004 per GB-month costs $44 per month; the same data in a hot SIEM tier at $0.15 per GB-month costs about $1,665. Across a full 12-month estate, tiering typically drops storage cost from several thousand dollars per month to a few hundred, with ingestion unchanged.

Can I still investigate incidents using cold security logs?

Yes, at modest cost. Athena charges $5.00 per TB scanned, so a full 11.1 TB scan costs $55.50, and a realistic partitioned investigative query scanning 200 GB costs $1.00. Glacier Instant Retrieval adds $0.03 per GB retrieval, so that 200 GB query adds $6. Ten investigations per month touching a terabyte each totals around $50, which is negligible against hot-tier retention savings.

Which tier should long-term security logs sit in?

Days 0 to 90 in the hot indexed tier to cover detection correlation windows and threat hunting. Days 90 to 180 in S3 Standard at $0.023 per GB-month for Athena querying. Days 180 to 365 in Glacier Instant Retrieval at $0.004 per GB-month, which keeps investigation at normal speed. Beyond a year, Glacier Deep Archive at $0.00099 per GB-month, accepting a 12-hour restore that suits audits but not active incidents.

How do I reduce security log volume before tiering?

Switch VPC Flow Logs to a custom format carrying only the fields detections actually use, cutting 30% to 40%. Use a 10-minute aggregation interval instead of 1 minute, which can cut records up to 90% for steady connections at the cost of timing granularity. Scope CloudTrail data events to sensitive S3 prefixes rather than every object. And convert archived logs to Parquet, which cuts scanned bytes 80% to 95% on selective queries.

How does C3X help with security log cost?

Flow log configurations, CloudTrail trails, S3 buckets and their lifecycle rules, Glue catalogs, and Firehose delivery streams are all Terraform resources. C3X prices that architecture from the plan, so the difference between a fully hot 12-month estate and a tiered one is a number visible in the pull request, before you commit to a storage design you will live with for a compliance cycle.

What to do next

Design security log tiering with real prices. C3X reads your Terraform and prices buckets, trails, and lifecycle rules against a live catalog. Start with the quickstart.

Try C3X on your own Terraform

Free and open source. No API key required. One command to install, one command to estimate.