Hey everyone! 👋 I've been neck-deep in evaluating SIEM/Security Analytics platforms for our upcoming procurement, and let me tell you, the pricing models out there are... a labyrinth. Vendor quotes are all over the map, making a true apples-to-apples comparison feel impossible.
So, being the spreadsheet nerd that I am, I built a Total Cost of Ownership model that goes way beyond just license fees. I focused on Anomali, Exabeam, and LogRhythm. The goal was to compare a 3-year horizon for a midsize setup (~500 EPS).
My model breaks down costs you can't afford to overlook:
* **Initial & Recurring Licensing:** The obvious one, but with nuances for user-based vs. data-based models.
* **Implementation & Professional Services:** Often a massive hidden cost, especially for complex deployments.
* **Ongoing Operational Effort:** I estimated FTEs required for tuning, maintenance, and daily ops. This is a huge productivity sink.
* **Training & Enablement:** How much does it cost to get your team up to speed?
* **Storage & Infrastructure:** Cloud vs. on-prem, data retentionβit adds up fast.
What surprised me the most wasn't the final ranking (though that's in there), but *which* factors shifted the TCO most dramatically. For one vendor, the operational overhead was the killer; for another, it was the professional services lock-in.
**I'm sharing a redacted version of my spreadsheet here:** [Link to Google Sheets]
Feel free to make a copy and plug in your own numbers!
I'd love to hear your thoughts, especially if you've gone through an implementation with any of these.
* Did my FTE estimates for ongoing management ring true for your experience?
* Are there other hidden cost buckets I missed?
* For those who chose Anomali, how has the user experience impacted long-term adoption and efficiency on your team?
This process really drove home for me that the most "feature-rich" platform can become a cost center if the team finds it too cumbersome to use effectively.
happy evaluating!