SIEM as a Service gives you centralised log collection, 12-month searchable retention, correlation rules and a 24/7 SOC that investigates what the SIEM finds, for a fixed monthly price instead of a six-figure platform project. ITSecOps runs SIEM as a Service on Microsoft Sentinel or the Sophos XDR data lake, monitored from Norway and India. Because we hold partnerships with every industry-standard vendor, the platform licence comes at partner pricing, cheaper than buying direct.
Updated September 4, 2026. The August 2026 Microsoft Entra ID vulnerability (CVE-2026-69836, unauthenticated remote code execution) and the Zimbra CVE-2026-73570 campaign that compromised at least 274 servers were both found first in sign-in and server logs, not by endpoint agents. Companies without log retention could not even tell whether they were affected. That is the gap a managed SIEM closes.
Managed SIEM pricing: what it actually costs in 2026
Managed SIEM pricing is the most searched question in this category, and most providers hide it. Here is the honest structure. Cost has three parts: the platform (priced per gigabyte of logs ingested per day or per device), the SOC service (priced per device or as a flat monthly fee) and one-time onboarding.
| Company profile | Typical log volume | Platform | Indicative total per month |
|---|---|---|---|
| 25 to 50 endpoints, Microsoft 365, 1 to 3 servers | 1 to 3 GB/day | Microsoft Sentinel (free M365 and Entra data connectors) or Sophos XDR data lake | $450 to $900 |
| 50 to 150 endpoints, firewall, 5 to 10 servers | 3 to 10 GB/day | Microsoft Sentinel with commitment tier | $900 to $2,200 |
| 150 to 500 endpoints, multiple sites, cloud workloads | 10 to 30 GB/day | Microsoft Sentinel with commitment tier, dedicated analyst hours | $2,200 to $5,500 |
| Compliance-only retention (NIS2, CMMC, ISO 27001 evidence) | Any | Sentinel basic logs / archive tier, monthly review | From $350 |
Compare that with an in-house SIEM: a platform licence of $20,000 to $60,000 per year, a dedicated engineer at $90,000 or more, and 6 to 9 months to reach useful detection coverage. Our 24/7 SOC monitoring cost guide has the full managed-versus-in-house comparison, and the cybersecurity price comparison lists platform prices side by side.
What is included
| Component | Details |
|---|---|
| Log sources | Microsoft 365, Entra ID, Google Workspace, Windows and Linux servers, EDR, firewalls (Sophos, Fortinet, WatchGuard, Cisco), VPN, Azure and AWS, SaaS apps |
| Retention | 90 days hot, 12 months searchable, optional 7 years archive for regulated clients |
| Detection content | Vendor analytics rules plus ITSecOps rules mapped to MITRE ATT&CK, tuned monthly |
| 24/7 SOC | 15-minute triage on high severity, active response through your EDR, incident timeline within 24 hours |
| Reporting | Monthly executive report, compliance evidence packs (NIS2 Article 21, CMMC AU controls, ISO 27001 A.8.15, SOC 2 CC7) |
| Onboarding | Connector deployment, parsing, baseline tuning, 2 to 4 weeks |
Custom-built open source SIEM: the answer above 50 GB per day
If you ingest more than about 50 GB of logs per day, every per-gigabyte SIEM (Microsoft Sentinel, Google Security Operations, SentinelOne Singularity Data Lake, Splunk, Sumo Logic) starts costing more than the analysts watching it. ITSecOps builds and runs a customised open source SIEM for exactly that situation: Wazuh or Elastic/OpenSearch for detection and search, hot storage sized for 90 days, object storage for 12 months or more, MITRE ATT&CK detection content we maintain, and the same 24/7 SOC on top. You pay for infrastructure and our service, not per gigabyte, which is what slashes the yearly cost.
| Daily ingestion | Per-GB SIEM, typical yearly cost (list) | ITSecOps custom open source SIEM, typical yearly cost | Typical saving |
|---|---|---|---|
| 50 GB / day | $55,000 to $90,000 (Sentinel pay-as-you-go to Splunk Cloud) | $30,000 to $42,000 including 24/7 SOC | 40 to 55 percent |
| 100 GB / day | $110,000 to $180,000 | $42,000 to $60,000 | 55 to 65 percent |
| 250 GB / day | $260,000 to $450,000 | $75,000 to $110,000 | 65 to 75 percent |
| 500 GB / day and up | $500,000 plus | Quoted; usually under 30 percent of the per-GB price | 70 percent plus |
What “custom-built” means in practice: log sources normalised to a common schema, noisy sources filtered before they are stored, detection rules mapped to MITRE ATT&CK and tuned to your environment, dashboards for auditors (NIS2, ISO 27001, CMMC, SOC 2), and immutable retention for evidence. It runs in your cloud (Azure, AWS, Hetzner, a Norwegian data centre) or ours, and nothing leaves your tenancy without your approval. Below 50 GB per day, Microsoft Sentinel with free Microsoft 365 connectors is usually still the cheapest option, and we tell you so.
Curious how a custom open source SIEM would work for you?
Bring your current daily log volume (or your last Sentinel, Splunk or Google SecOps invoice). In 30 minutes we show the architecture, the 12-month cost against what you pay today, and the migration path, with no obligation.
Book a consultation for a custom-built open source SIEM Or compare SIEM prices side by side →
SIEM or MDR: which do you need first?
If you have neither, start with MDR: it stops attacks on the endpoint and identity, where most incidents begin. Add SIEM as a Service when you need retention and reporting across every system, which usually means NIS2, CMMC, HIPAA or ISO 27001 obligations, more than about 100 endpoints, or an incident where you could not answer “what happened”. Many clients run both from ITSecOps under one contract, and the Security Stack Recommender tells you which applies to you.
Frequently asked questions
How much does a managed SIEM cost per month?
For a company with 25 to 50 endpoints on Microsoft 365, $450 to $900 per month including the platform and 24/7 SOC. Costs scale with log volume, not headcount, which is why we start every quote with a log-volume estimate.
Is Microsoft Sentinel cheaper than other SIEMs?
For Microsoft 365 companies, usually yes. Microsoft 365 audit, Entra ID sign-in and Defender alerts are ingested free of charge, and Microsoft 365 E5 tenants get a daily data grant. Non-Microsoft sources are billed per gigabyte, which we control with filtering and commitment tiers.
Can you use our existing SIEM?
Yes, for Sentinel, Sophos XDR, Elastic and Wazuh. We take over tuning and monitoring rather than migrating you.
Do you provide SIEM to MSPs under white label?
Yes. MSPs resell our SIEM as a Service and 24/7 SOC under their own brand. See white-label MSP support.
What evidence do I get for auditors?
Monthly reports, retention proof, detection rule inventory and incident timelines mapped to ISO 27001, SOC 2, NIS2 and CMMC control identifiers.
When is an open source SIEM cheaper than Microsoft Sentinel or Splunk?
Above roughly 50 GB of ingestion per day. Per-gigabyte pricing grows linearly with volume, while a custom open source SIEM (Wazuh, Elastic or OpenSearch) costs infrastructure plus a fixed service fee, so at 100 GB per day the saving is typically 55 to 65 percent and at 250 GB per day 65 percent or more.
Is an open source SIEM good enough for compliance?
Yes when it is built and operated properly: immutable retention, MITRE-mapped detections, audit dashboards and a 24/7 SOC. Auditors care about evidence, retention and monitoring, not the vendor logo.
Which open source SIEM do you build on?
Wazuh for endpoint-centric environments and compliance modules, Elastic or OpenSearch for high-volume search and custom pipelines, often combined. We choose per environment after seeing your log sources and volume.