Guide
SIEM pricing models, explained
Six ways this software gets metered. In five of them, the thing that increases your invoice is something your security team should be doing more of. Here is how each one works, what actually moves the bill, and what to get in writing before you sign.
The meter is a policy, whether or not anyone meant it to be
Every pricing model is a sentence about what the vendor thinks is scarce. Per gigabyte says storage and processing are scarce. Per user says people are. Credits say compute is. Whatever the sentence, the organisation buying it will — rationally, and usually within a quarter — start economising on whatever the meter reads.
That is fine when the metered thing is something you are happy to have less of. It is a problem when the metered thing is evidence. A team that responds to a per-gigabyte invoice by dropping a log source has not made a purchasing decision; it has made a detection-coverage decision, using a spreadsheet, months before the incident that needed those logs.
So the useful question about a pricing model is not "is it expensive?" It is: what behaviour does this make expensive?
The six models
Described as mechanics rather than as vendors, because mechanics are checkable and do not go stale when somebody reprices.
Per gigabyte ingested
- Metered on
- Volume of data accepted, quoted per GB/day on an annual commitment or per GB per month.
- What moves the bill
- Adding a log source. A chatty device. Turning up logging verbosity during an incident — exactly when you need the detail most.
- The pressure it creates
- Teams drop or sample log sources to hold the number down, which turns a budget constraint into a coverage decision. The evidence you did not collect is the evidence you cannot investigate with later.
- Who it suits
- Small, stable estates with well-understood volume, where the convenience of a single obvious unit outweighs the coupling.
Per event per second
- Metered on
- Sustained event rate, sized against a peak rather than an average.
- What moves the bill
- Bursts. A scan, an outage, an attack — the same events that make a peak worth capturing are the ones that set the tier you buy.
- The pressure it creates
- You size and pay for the peak all year to survive the few hours it happens, and filtering at the edge to stay under the ceiling drops the burst itself.
- Who it suits
- Predictable, steady-state environments where peak and average are close together.
Per user or per employee
- Metered on
- Headcount, sometimes limited to monitored identities.
- What moves the bill
- Hiring. Acquisitions. Contractors and seasonal staff.
- The pressure it creates
- Genuinely predictable, and decoupled from data — but decoupled in both directions. A 200-person manufacturer with tens of thousands of sensors pays as though it had 200 things to watch, and the vendor eventually has to price for that mismatch somewhere.
- Who it suits
- Office-shaped organisations where headcount really does approximate the attack surface.
Per endpoint or per asset
- Metered on
- Count of devices, servers or workloads sending data.
- What moves the bill
- Growing the estate. Autoscaling. Short-lived cloud instances and containers.
- The pressure it creates
- Ephemeral infrastructure makes the count a moving target, and how a vendor counts a container that lived for four minutes is a question worth settling before signing, not after.
- Who it suits
- Stable, countable estates — and it reads naturally to anyone who already buys EDR this way.
Workload or credit consumption
- Metered on
- A pool of credits drawn down by ingestion, searching, alerting and — increasingly — AI features on their own separate meter.
- What moves the bill
- Using the product. Running a broad hunt, re-running it with a corrected filter, backfilling a year to answer an auditor.
- The pressure it creates
- The hardest model to forecast, because consumption depends on how the team works rather than on what the estate emits. It also puts a price on thoroughness: the analyst who checks one more hypothesis spends budget doing it.
- Who it suits
- Teams with elastic, spiky workloads who would rather pay for a quiet month than carry a fixed ceiling.
Per appliance, flat rate
What WitFoo does- Metered on
- The number of appliances deployed. Data rates are unlimited and uncharged.
- What moves the bill
- Deploying another appliance — a decision the organisation makes deliberately, at a moment of its choosing.
- The pressure it creates
- The coupling between cost and evidence is cut, so adding a log source, raising verbosity or backfilling history is a capacity question rather than a purchasing one. The trade is that capacity is a real constraint: an appliance has a size, and growth eventually means another one.
- Who it suits
- Organisations that want coverage decisions made on security grounds, and a number they can put in a budget a year ahead.
Six questions to get answered in writing
Each of these is a place where a quoted price and a first invoice can legitimately diverge. None of them is a trick question, and a vendor who cannot answer one plainly has told you something.
-
What exactly is metered, and measured where?
Raw bytes at the collector, or the reduced set that lands in storage? The same estate can differ several-fold between those two points.
-
Is the meter read on average or on peak?
A peak-based tier means one bad afternoon sets the price you pay for the rest of the term.
-
What happens when we exceed it?
Overage billing, throttling and a hard stop are three very different outcomes. One costs money; the others cost visibility during the hours you can least afford to lose it.
-
Is retention charged separately?
Ingest and retention are often two meters. A year of retention for compliance can cost more than the ingestion that produced it.
-
Are AI or search features on their own meter?
An assistant billed by consumption makes asking questions a budget line, which is a strange incentive to put on an analyst.
-
Is this a published list price, or is every deal negotiated?
If no price is public, you cannot benchmark your renewal against anything except last year — which is exactly the position that makes renewals expensive.
What WitFoo charges, in public
One annual fee per appliance. Unlimited data rates, no per-GB charge, no per-event charge, no separate meter for AI. The list is published so a renewal can be benchmarked against something other than last year's invoice.
Conductor
$15K
from, per appliance per year
3 tiers, up to $60K. About Conductor
Reporter
$20K
from, per appliance per year
2 tiers, up to $50K. About Reporter
Analytics
$25K
from, per appliance per year
3 tiers, up to $120K. About Analytics
Multi-appliance orders discount automatically, and government, nonprofit and education pricing stacks on top. The full schedule and every tier is on the pricing page.
Questions
- What are the common SIEM pricing models?
- Six are in general use: per gigabyte ingested, per event per second, per user or employee, per endpoint or asset, workload or credit consumption, and flat rate per appliance. The first five meter something that grows as you collect more security data; the sixth does not.
- Why does per-GB SIEM pricing cause teams to drop log sources?
- Because the invoice is a direct function of how much evidence you keep. When a new log source has a visible annual cost attached to it, the decision to collect it stops being a security decision and becomes a budget decision — and the data you chose not to collect is not available later, when an investigation needs it.
- How much does a SIEM cost?
- Under a metered model there is no answer independent of your data volume, which is why most vendors quote per deal rather than publish a list. WitFoo publishes its list prices: Conductor from $15,000, Reporter from $20,000 and Analytics from $25,000 per appliance per year, with unlimited data ingestion and no per-GB charges.
- Is flat-rate pricing always cheaper?
- No. At low, stable volumes a metered contract can cost less, and an appliance has real capacity limits that eventually mean deploying another one. What flat rate changes is the shape of the curve: cost steps when you add capacity rather than rising every time you add evidence. The calculator lets you model both against your own numbers.
- What should I ask a SIEM vendor about pricing?
- Whether the meter reads raw or post-reduction data, whether it is based on average or peak, what happens at overage — billing, throttling or a hard stop — whether retention is a separate meter, whether AI and search features consume their own budget, and whether the price is published or negotiated per deal.
Put your own numbers in.
The calculator is ungated — no form, no email. Enter your volume, your growth and your own contract rate, and compare the curves over three years.