Skip to content
Logmetry

SIEM pricing models: Splunk vs Microsoft Sentinel vs Elastic

Splunk sells ingest, workload, or activity-based pricing with no public list prices, Microsoft Sentinel bills per GB into the workspace with commitment tiers, and Elastic prices on resources rather than ingest.

What actually differs

The unit each option charges on, and who owns what afterwards, matter more than any single quoted figure.

Where each SIEM meter sitsSplunk and Microsoft Sentinel meter the pipe on the way in: Splunk per GB into the index with ingest, workload, or activity pricing, Sentinel per GB into the Log Analytics workspace with an analytics tier and a data lake tier and commitment tiers reserving daily volume. Elastic meters the deployment itself, CPU and RAM, not the ingest.SPLUNKPER GB INTHE INDEXPriced on ingest, workload,or activity. No public rates,every path ends at sales.MICROSOFT SENTINELPER GB INANALYTICS TIERDATA LAKE TIERLOG ANALYTICSPer GB into the workspace.Commitment tiers reservedaily volume at a discount.ELASTICCPU + RAMTHE DEPLOYMENTPriced on the resources thedeployment holds, not onthe ingest that flows in.
Where each meter sits. Splunk and Sentinel read the pipe on the way in, Elastic reads the size of the deployment. The unit decides what behaviour gets expensive.

The three platforms charge on different units, which is why comparing quotes line by line misleads. An ingest-priced SIEM bills on what flows in whether or not anyone reads it. A resource-priced platform bills on the compute and memory the deployment holds. The unit decides what behaviour gets expensive, and therefore what behaviour the vendor's pricing quietly encourages.

None of the three publishes a full rate card on its top pricing page, so every real decision runs through a quote or an estimator. What can be compared honestly is the mechanics: the unit, the commitment structure, and what is published. That is what the table below holds, each cell sourced from the vendor's own page with the date we checked it.

Side by side, sourced

Every cell in this table carries the vendor's own page as its source and the date it was checked, and a cell without a source does not ship.

SplunkMicrosoft SentinelElastic
Pricing unitIngest, workload, or activity-based pricing, with unlimited users on each model. Splunk Enterprise offers data-ingest or workload pricing.Splunk pricing page, checked 2026-08-24Per GB ingested, with an analytics tier for full detection and query capability and a data lake tier for low-cost long-term storage.Microsoft Sentinel pricing page, checked 2026-08-24Resource-based on Elastic Cloud hosted, usage-based on serverless, and node plus RAM licensing self-managed. Not priced on ingest.Elastic pricing page, checked 2026-08-24
Commitment mechanicsTerm contracts negotiated through sales. The pricing page offers no self-service commitment structure, only a quote request.Splunk pricing page, checked 2026-08-24Commitment tiers reserve 100 GB to 50,000 GB per day at fixed rates, with savings Microsoft states as up to 52% against pay-as-you-go, and a 31-day minimum before downgrading.Microsoft Sentinel pricing page, checked 2026-08-24Pay as you go monthly or prepaid, on both hosted and serverless. Four support tiers follow the subscription tier.Elastic pricing page, checked 2026-08-24
What is publishedNo list prices for the platform on the pricing page. Every path ends at a sales contact.Splunk pricing page, checked 2026-08-24No per-GB rates on the pricing page. Microsoft points at the cost estimator and notes actual pricing varies by agreement, date, currency, and taxes.Microsoft Sentinel pricing page, checked 2026-08-24No rate card on the top pricing page. Per-solution pricing pages and sales handle specifics.Elastic pricing page, checked 2026-08-24

When each is the right answer

Every option in this comparison is the right answer for somebody, and saying when is the part most comparisons leave out.

Splunk

The right answer when your detection content, SPL expertise, and app ecosystem investment run deep, and when on-prem or hybrid constraints matter. The mature estate is the asset, and governing its ingest is cheaper than abandoning it.

Microsoft Sentinel

The right answer for Microsoft-heavy estates where Defender, Entra, and Office signals arrive already integrated, and where commitment tiers fit a predictable volume. Cloud-native consolidation with real discounts for committed daily ingest.

Elastic

The right answer for engineering-led teams that want resource-based economics instead of an ingest meter, self-managed control, and search-centric workloads where the same platform serves security and observability.

Asked about this comparison

Why do none of these vendors publish full list prices?

Because enterprise SIEM deals are negotiated on volume, term, and bundling, and a public rate card would anchor every negotiation. The practical consequence is that the pricing unit and commitment mechanics, which are published, matter more to your planning than any single quoted figure.

Which pricing model is cheapest?

The one whose unit matches your data behaviour, governed. Ingest pricing punishes verbose sources, so it rewards a control layer that filters upstream. Resource pricing punishes heavy queries and retention. The honest answer comes from modeling your own volumes, which is what the architecture review does.

Does a control layer change which SIEM wins?

It changes the stakes. With routing in front, every SIEM receives only what earns its tier, full history lands in storage you own, and switching later becomes a routing change. That makes the SIEM decision reversible, which is worth more than any single discount.

Model it against your estate

The comparison that matters is the one run on your volumes and your contracts. The review reads them with you, and you leave with your version of the Logmetry Blueprint. No system access, no obligation.