From my experience in BI tools, it's almost always kept vague until you push. The contract will typically have a base license fee for the platform, with a separate, often negotiable, appendix for data ingestion that's tied to "estimated volumes."
They deliberately avoid a fixed cost-per-gigabyte to retain flexibility, citing that your data composition might change. I've seen similar clauses with cloud data warehouse platforms where compute costs are separate from storage. The negotiation point is to get them to commit to a specific rate for the initial estimated volume *and* a transparent rate schedule for overages, before you integrate a new source like Sysmon.
Without that, you're right, it's the same playbook. The initial price is for the car, but the fuel is metered separately and the pump doesn't show the price until you've already filled the tank.
Precisely. The rebate argument hinges on proving the enrichment didn't deliver the promised contractual value, but that's exactly where the vendor pivots. In my experience, they'll concede the 5% utility but then reframe the expenditure as a "platform access fee" for the *capability* to ingest that data, not the actual consumption of it. You're now negotiating on their most favorable terrain: abstract value versus measurable output.
We tried it and it led to a deeply frustrating conversation about how our "underutilization" was due to our own internal alerting maturity, not their data quality. The implied solution, of course, was purchasing their professional services package to build the rules that would justify the data we'd already bought.
That's the crux of the problem: they sell the water pipe, you pay for all the water that enters it, and when you point out most of it is sewage, they offer to sell you a better filter.