SIEM Sizing Calculator
Size your SIEM deployment: calculate EPS capacity, storage, infrastructure nodes, and license costs by pricing model (Splunk, QRadar, Sentinel).
About this calculator
This calculator sizes a SIEM deployment from the bottom up, starting with events per second: log sources multiplied by average EPS per source. That EPS figure drives everything else. Daily ingestion assumes a 650-byte average event (a reasonable blend across firewalls, servers, and application logs), scaled to bytes per day and converted to GB. Because a SIEM must index data to make it searchable, storage is modeled at 1.5x the raw ingested volume, then multiplied by your online retention window to get total indexed storage in TB. Infrastructure follows common Elastic/Splunk cluster guidance: one indexer node (16 cores, 64 GB RAM) per 100 GB/day ingested, one search head (8 cores, 32 GB RAM) per 200 GB/day, plus a fixed management node.
License cost then depends on which pricing model you select — Splunk-style per-GB/day (roughly $1,800/GB/day annually), QRadar-style per-1000-EPS ($20k/year), or Sentinel-style per-GB-ingested ($2.46/GB) — and infrastructure cost is estimated separately using rough cloud-VM rates for compute and SSD storage. The two are summed into a total annual cost and a cost-per-EPS figure useful for comparing platforms on equal footing. The biggest input to get right is average EPS per source: firewalls and network gear can run 10-50 EPS while endpoints sit closer to 0.5-2, so a mixed environment needs a realistic blended estimate, not a single guess applied everywhere. Also budget headroom — real environments see EPS spikes during incidents or when onboarding new sources, and this model reflects steady-state averages only.
Inputs
Results
Total EPS
500
Annual license ($)
$47,073.00
How to Use This Calculator
- Enter log sources and average EPS per source.
- Set online retention (days) and select pricing model (EPS-based, storage-based, or hybrid).
- Review total EPS, daily ingestion (GB), total storage (TB), and total nodes.
- Add 30-50% headroom for event spikes during incidents or initial onboarding of new log sources.
- Compare EPS-based to storage-based pricing -- high-volume/low-value sources favor storage pricing.
How the result changes with Log sources
| Log sources | Total EPS | Annual license ($) |
|---|---|---|
| 50 | 250 | $23,536.00 |
| 75 | 375 | $35,305.00 |
| 150 | 750 | $70,609.00 |
| 250 | 1,250 | $117,682.00 |
What each input means
- Log sources
- Total log-producing devices and applications (servers, firewalls, endpoints, SaaS apps).
- Avg EPS per source
- Average events per second per source. Firewalls: 10-50, servers: 1-10, endpoints: 0.5-2, apps: 1-5.
- Online retention (days)
- Days of searchable online retention. PCI requires 90 days online, 1 year total.
- Pricing model (0-2)
- 0 = Per GB/day (Splunk ~$1,800/GB/day/yr), 1 = Per EPS (QRadar ~$20k/1000 EPS/yr), 2 = Per GB ingested (Sentinel ~$2.46/GB).
What each result means
- Total EPS
- Total events per second the SIEM must handle.
- Daily ingestion (GB)
- Raw data ingested per day before SIEM indexing.
- Indexed storage (TB)
- Total indexed storage needed for the retention period (1.5x raw for indexes).
- Server nodes
- Recommended SIEM cluster nodes (indexers + search heads + management).
- CPU cores
- Total CPU cores across all SIEM nodes.
- RAM (GB)
- Total RAM across all SIEM nodes.
- Annual license ($)
- Estimated annual SIEM software license cost based on selected pricing model.
- Monthly total ($)
- Monthly total including license and infrastructure.
- Cost per EPS ($/yr)
- Annual total cost divided by total EPS — useful for comparing SIEM platforms.
How this is calculated
Worked example, using the default values
- Identify Input Parameters4 parametersLog sources = 100, Avg EPS per source = 5, Online retention (days) = 90, Pricing model (0-2) = 0 = 4 input(s) provided
- Calculate Total EPSTotal EPS = logSources * avgEPSPerSource500 = 500
- Calculate Annual licenseAnnual license47073 = $47,073
- Calculate Daily ingestionDaily ingestion = rawBytesPerDay / (1024 * 1024 * 1024)26.2 = 26.2
- Calculate Indexed storageIndexed storage = totalIndexedStorageGB / 10243.45 = 3.45
Engine last updated . Checked against 3 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
Why does average EPS per source matter so much more than log source count?
Total EPS is simply log sources multiplied by average EPS per source, and that single number drives every downstream calculation -- ingestion volume, storage, infrastructure nodes, and license cost under EPS-based pricing. A mixed environment where firewalls run 10-50 EPS and endpoints sit at 0.5-2 EPS needs a realistic blended average, because overestimating it inflates every cost line, while underestimating it under-sizes your indexer and search node counts.
Why is indexed storage 1.5x the raw ingested volume instead of 1:1?
Raw log data has to be parsed and indexed to become searchable, and that index structure (field extraction, time-series indexes, metadata) adds overhead on top of the original bytes. This calculator models that overhead as a flat 1.5x multiplier applied before multiplying by your retention window, so a 90-day retention on 100 GB/day raw ingestion becomes 13.5 TB of indexed storage, not 9 TB.
Which pricing model should I pick if I'm not sure how my vendor charges?
Per-GB/day (Splunk-style) is the most common model and scales with your daily ingestion volume regardless of how many log sources produce it. Per-EPS (QRadar-style) instead scales with event rate, which can be cheaper for high-volume-but-small-event sources like NetFlow. Per-GB-ingested (Sentinel-style) is similar to per-GB/day but often has a lower headline rate -- run all three with your own numbers since the cheapest model depends entirely on your event size and source mix.
Why does the calculator recommend indexer and search-head node counts separately?
Indexers do the heavy lifting of writing and storing indexed data, so they're sized at one node per 100 GB/day of raw ingestion with 16 cores and 64 GB RAM each. Search heads handle query load rather than ingestion, so they're sized more loosely at one per 200 GB/day with half the cores. A fixed management node is added on top of both, which is why total node count is never just ingestion divided by one ratio.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
Earnings Per Share (EPS) Calculator
Company net income divided by shares outstanding.
Security ToolsLog Retention Calculator
Calculate security log storage requirements from log sources, event rates, retention policy, and tiered storage costs. Supports PCI DSS, HIPAA, and SOX compliance planning.
Security ToolsEncryption Strength Calculator
Estimate brute-force time from key length and attacker computing power. Covers symmetric (AES) and asymmetric (RSA) algorithms with quantum threat modeling.
Security ToolsCertificate Expiration Tracker Calculator
Plan SSL/TLS certificate lifecycle management: renewal workload, annual costs, risk scoring, and alert thresholds based on your certificate portfolio.
More in Technology & Computing.