SIEM cost compared: Sentinel vs Security Lake vs Chronicle
SIEM cost is dominated by data ingestion: Microsoft Sentinel bills per GB ingested (with commitment tiers), AWS Security Lake centralizes data in S3 with usage-based analytics, and Google Chronicle prices differently. Ingestion volume drives all. This compares them.
Quick answer
SIEM cost is dominated by data ingestion. Microsoft Sentinel bills per GB ingested (pay-as-you-go or cheaper commitment tiers) plus the underlying Log Analytics. AWS Security Lake centralizes security data in your S3 (you pay S3 plus the analytics tools you query it with). Google Chronicle uses volume- or size-based pricing decoupled from per-GB ingestion. Across all, filtering what you ingest is the dominant lever, since ingestion volume is the cost.
A security information and event management (SIEM) platform ingests security logs and events for detection and investigation, and on every option the cost is dominated by how much data you ingest. The models differ in shape, per-GB, storage-plus-analytics, or decoupled volume pricing, but the lever is the same: ingest less, or ingest cheaper.
Three approaches to SIEM cost
| Platform | Model |
|---|---|
| Microsoft Sentinel | Per GB ingested (PAYG or commitment tiers) + Log Analytics |
| AWS Security Lake | S3 storage + the analytics tools you query with |
| Google Chronicle | Volume/size-based, decoupled from per-GB ingestion |
Microsoft Sentinel bills per gigabyte ingested, with commitment tiers cheaper than pay-as-you-go, on top of the underlying Log Analytics workspace, as in Sentinel. AWS Security Lake centralizes security data in your own S3 in a normalized format, so you pay S3 storage plus whatever analytics tools (Athena, OpenSearch, partners) you query it with. Google Chronicle historically priced on a volume or per-employee basis decoupled from raw per-GB ingestion.
Which is cheaper
Because ingestion dominates, the cheapest depends on your data volume and how each model prices it. Per-GB (Sentinel) is predictable and its commitment tiers reward steady high volume; Security Lake's storage-plus-analytics can be cheaper if you store a lot but query selectively; Chronicle's decoupled pricing can favor very high ingestion volumes where per-GB would be punishing. So model your ingestion volume against each shape.
The dominant lever: ingest less
On every SIEM, filter what you ingest to security-relevant data rather than everything (much raw log volume has no security value), route high-volume low-value logs to cheaper storage and ingest only what detection needs, use commitment tiers if your volume is steady and high, and set retention deliberately. Since ingestion is the cost, the filter-before-ingest discipline is the whole game, identically across platforms.
Choosing on cost
Pick the SIEM whose pricing shape fits your ingestion profile (per-GB with commitments for steady volume, storage-plus-analytics if you retain a lot but query narrowly, decoupled pricing for very high volume), use the one native to your cloud where it reduces data-movement cost, and above all filter ingestion to security-relevant data. The platform matters less than how much you feed it, so control ingestion first.
FAQ
Which SIEM is cheapest, Sentinel, Security Lake, or Chronicle?
It depends on your ingestion volume and how each prices it. Sentinel's per-GB model with commitment tiers rewards steady high volume; Security Lake's S3-storage-plus-analytics can be cheaper if you store a lot but query selectively; Chronicle's decoupled pricing can favor very high volumes where per-GB would be punishing. Model your ingestion against each shape.
What dominates SIEM cost?
Data ingestion. On every SIEM platform, how much security data you ingest dominates the bill, since detection and retention scale with volume. The pricing models differ in shape (per-GB, storage-plus-analytics, decoupled volume), but the lever is the same across all: ingest less, or ingest cheaper.
How do I reduce SIEM cost?
Filter what you ingest to security-relevant data rather than everything (much raw log volume has no security value), route high-volume low-value logs to cheaper storage and ingest only what detection needs, use commitment tiers if your volume is steady and high, and set retention deliberately. Since ingestion is the cost, filtering before ingest is the dominant lever.
How do SIEM pricing models differ?
Microsoft Sentinel bills per GB ingested (pay-as-you-go or cheaper commitment tiers) plus the underlying Log Analytics. AWS Security Lake centralizes data in your S3, so you pay S3 storage plus the analytics tools you query with. Google Chronicle historically priced on volume or size decoupled from raw per-GB ingestion. All are dominated by ingestion volume.
Do commitment tiers reduce SIEM cost?
Yes, for steady high volume. Sentinel's commitment tiers charge a lower effective per-GB rate in exchange for committing to a daily ingestion volume, cheaper than pay-as-you-go when your ingestion is predictable and high. If your volume is steady enough to fill a tier, committing reduces the per-GB cost meaningfully.
Does C3X estimate SIEM cost?
SIEM cost is driven by data ingestion volume, a usage input. C3X prices the surrounding infrastructure, including the Log Analytics or S3 storage backing the SIEM, and you model your security-log ingestion volume to estimate the platform charges and compare the pricing shapes.
What to do next
Estimate the infrastructure behind your SIEM before you deploy. C3X reads your Terraform and prices your resources against a live catalog. Start with the quickstart.
Share this post
Try C3X on your own Terraform
Free and open source. No API key required. One command to install, one command to estimate.