Skip to main content
Calcimator

SIEM Sizing Calculator

Size your SIEM deployment: calculate EPS capacity, storage, infrastructure nodes, and license costs by pricing model (Splunk, QRadar, Sentinel).

About this calculator

This calculator sizes a SIEM deployment from the bottom up, starting with events per second: log sources multiplied by average EPS per source. That EPS figure drives everything else. Daily ingestion assumes a 650-byte average event (a reasonable blend across firewalls, servers, and application logs), scaled to bytes per day and converted to GB. Because a SIEM must index data to make it searchable, storage is modeled at 1.5x the raw ingested volume, then multiplied by your online retention window to get total indexed storage in TB. Infrastructure follows common Elastic/Splunk cluster guidance: one indexer node (16 cores, 64 GB RAM) per 100 GB/day ingested, one search head (8 cores, 32 GB RAM) per 200 GB/day, plus a fixed management node.

License cost then depends on which pricing model you select — Splunk-style per-GB/day (roughly $1,800/GB/day annually), QRadar-style per-1000-EPS ($20k/year), or Sentinel-style per-GB-ingested ($2.46/GB) — and infrastructure cost is estimated separately using rough cloud-VM rates for compute and SSD storage. The two are summed into a total annual cost and a cost-per-EPS figure useful for comparing platforms on equal footing. The biggest input to get right is average EPS per source: firewalls and network gear can run 10-50 EPS while endpoints sit closer to 0.5-2, so a mixed environment needs a realistic blended estimate, not a single guess applied everywhere. Also budget headroom — real environments see EPS spikes during incidents or when onboarding new sources, and this model reflects steady-state averages only.

Inputs

Results

Total EPS

500

Annual license ($)

$47,073.00

Daily ingestion (GB)26.2
Indexed storage (TB)3.45
Server nodes3
CPU cores28
RAM (GB)112
Monthly total ($)$5,491.00
Cost per EPS ($/yr)$131.79
How to Use This Calculator
  1. Enter log sources and average EPS per source.
  2. Set online retention (days) and select pricing model (EPS-based, storage-based, or hybrid).
  3. Review total EPS, daily ingestion (GB), total storage (TB), and total nodes.
  4. Add 30-50% headroom for event spikes during incidents or initial onboarding of new log sources.
  5. Compare EPS-based to storage-based pricing -- high-volume/low-value sources favor storage pricing.

How the result changes with Log sources

Log sourcesTotal EPSAnnual license ($)
50250$23,536.00
75375$35,305.00
150750$70,609.00
2501,250$117,682.00

What each input means

Log sources
Total log-producing devices and applications (servers, firewalls, endpoints, SaaS apps).
Avg EPS per source
Average events per second per source. Firewalls: 10-50, servers: 1-10, endpoints: 0.5-2, apps: 1-5.
Online retention (days)
Days of searchable online retention. PCI requires 90 days online, 1 year total.
Pricing model (0-2)
0 = Per GB/day (Splunk ~$1,800/GB/day/yr), 1 = Per EPS (QRadar ~$20k/1000 EPS/yr), 2 = Per GB ingested (Sentinel ~$2.46/GB).

What each result means

Total EPS
Total events per second the SIEM must handle.
Daily ingestion (GB)
Raw data ingested per day before SIEM indexing.
Indexed storage (TB)
Total indexed storage needed for the retention period (1.5x raw for indexes).
Server nodes
Recommended SIEM cluster nodes (indexers + search heads + management).
CPU cores
Total CPU cores across all SIEM nodes.
RAM (GB)
Total RAM across all SIEM nodes.
Annual license ($)
Estimated annual SIEM software license cost based on selected pricing model.
Monthly total ($)
Monthly total including license and infrastructure.
Cost per EPS ($/yr)
Annual total cost divided by total EPS — useful for comparing SIEM platforms.

How this is calculated

Worked example, using the default values

  1. Identify Input Parameters
    4 parameters
    Log sources = 100, Avg EPS per source = 5, Online retention (days) = 90, Pricing model (0-2) = 0 = 4 input(s) provided
  2. Calculate Total EPS
    Total EPS = logSources * avgEPSPerSource
    500 = 500
  3. Calculate Annual license
    Annual license
    47073 = $47,073
  4. Calculate Daily ingestion
    Daily ingestion = rawBytesPerDay / (1024 * 1024 * 1024)
    26.2 = 26.2
  5. Calculate Indexed storage
    Indexed storage = totalIndexedStorageGB / 1024
    3.45 = 3.45

Engine last updated . Checked against 3 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.

Frequently Asked Questions

Why does average EPS per source matter so much more than log source count?

Total EPS is simply log sources multiplied by average EPS per source, and that single number drives every downstream calculation -- ingestion volume, storage, infrastructure nodes, and license cost under EPS-based pricing. A mixed environment where firewalls run 10-50 EPS and endpoints sit at 0.5-2 EPS needs a realistic blended average, because overestimating it inflates every cost line, while underestimating it under-sizes your indexer and search node counts.

Why is indexed storage 1.5x the raw ingested volume instead of 1:1?

Raw log data has to be parsed and indexed to become searchable, and that index structure (field extraction, time-series indexes, metadata) adds overhead on top of the original bytes. This calculator models that overhead as a flat 1.5x multiplier applied before multiplying by your retention window, so a 90-day retention on 100 GB/day raw ingestion becomes 13.5 TB of indexed storage, not 9 TB.

Which pricing model should I pick if I'm not sure how my vendor charges?

Per-GB/day (Splunk-style) is the most common model and scales with your daily ingestion volume regardless of how many log sources produce it. Per-EPS (QRadar-style) instead scales with event rate, which can be cheaper for high-volume-but-small-event sources like NetFlow. Per-GB-ingested (Sentinel-style) is similar to per-GB/day but often has a lower headline rate -- run all three with your own numbers since the cheapest model depends entirely on your event size and source mix.

Why does the calculator recommend indexer and search-head node counts separately?

Indexers do the heavy lifting of writing and storing indexed data, so they're sized at one node per 100 GB/day of raw ingestion with 16 cores and 64 GB RAM each. Search heads handle query load rather than ingestion, so they're sized more loosely at one per 200 GB/day with half the cores. A fixed management node is added on top of both, which is why total node count is never just ingestion divided by one ratio.

The questions that sit next to this one — chosen by subject, including calculators filed under a different category.

More in Technology & Computing.