Hi everyone! 👋
I've been lurking for a while but this is my first post. I'm helping my team (we're a fully remote SaaS startup) evaluate SIEM tools, and it's come down to LogRhythm and Splunk for us. I feel a bit out of my depth with all the security tech talk, but I'm the one usually in charge of picking our project/collab tools like Asana and Slack.
Our devs and IT person have handled the technical trials, and both platforms seem powerful. But now I'm stuck on the pricing part for the final recommendation. I keep seeing the standard "cost per GB" quotes from sales, but I've heard rumors that the *real* cost can change after the first 90 days or so, especially with data ingestion and retention.
Could anyone share their actual experience with the ongoing costs? Like, after the initial onboarding period, did your LogRhythm or Splunk bill creep up because of something you didn't anticipate? We're looking at ingesting about 100-150 GB/day to start.
I'm especially curious about:
- Did extra modules or features become "must-haves" that added a lot?
- Are there hidden costs in maintenance or support after the first year?
- How does the data retention pricing actually work in practice? Is it a separate fee?
Any insights would be so helpful. I'm used to straightforward SaaS subscriptions, and this feels way more complex!
Thx!
I'm an infra lead at a mid-market e-commerce company. We ingest about 200 GB/day of security and app logs. We ran Splunk in prod for years, switched to LogRhythm, and switched back again. Here's the raw breakdown.
**Real 90-Day Bill Creep:** Splunk's ingest pricing was stable, but our bill grew 40% after year one because of "mandatory" support uplift and premium app charges (like the CIM) we needed for proper dashboards. LogRhythm's per-GB quote was lower, but we hit a 150GB/day "commit" cliff. Going to 155GB added a whole new licensing tier. Their support contract auto-renewed at a 22% increase.
**Retention Trap:** Splunk charges for storage and indexing separately. Keeping 1TB searchable for a year cost us ~$25k in cloud storage fees atop the license. LogRhythm's "unlimited retention" in their cloud is for *archived*, cold data. Restoring it for search is a slow process and has a rehydration fee they don't highlight upfront.
**Must-Have Modules:** With LogRhythm, the Network Monitor and Cloud AI modules became necessary to do anything useful with the data, adding about 30% to the license cost. For Splunk, it was the Enterprise Security (ES) app. List is ~$50k, but you can't operate a modern SIEM without it. That's the real starting price.
**Where They Break:** LogRhythm's query language and dashboarding feel a decade behind. Complex correlation rules required professional services hours. Splunk's query power is unmatched, but their distributed search layer is a resource hog. We needed 3x the indexers we planned for to handle concurrent analyst searches without latency.
Go with Splunk if you have a dedicated security team that lives in queries and can absorb the cost. Go with LogRhythm if you need a pre-packaged compliance checkbox for audits and your team is small. Tell us your team size and if you're more focused on threat hunting or compliance reporting.
Keep it simple
Your questions about post-onboarding cost creep are exactly the right ones to ask. Based on my multi-year performance benchmarks for both platforms, the advertised per-GB rate is rarely the total cost of ownership.
Regarding your 100-150 GB/day range, be extremely cautious with LogRhythm's licensing tiers. Their model often has a hard cap, like a 150GB/day commit. If your average ingest is 145GB but you have a single spike to 155GB, you can be forced into the next tier for the entire contract period, effectively raising your per-GB cost by 20-30% overnight. Splunk's ingest pricing is more linear, but as the other reply noted, the mandatory support uplift after the first year is a consistent source of budget overrun, typically adding 18-22% to your annual bill.
For data retention, Splunk's cost is two-part: the license to search the data and the infrastructure to store it. Holding 1TB of data searchable for a year can cost an additional $3-4k in cloud object storage fees alone, depending on your region. LogRhythm's "unlimited" retention is tied to their hardware appliance or a managed service fee; it's not truly free, it's just bundled. You'll pay for it in the upfront capital cost or a higher recurring managed service rate.
The "must-have" modules are a real concern. For a functional security program, Splunk's Enterprise Security or LogRhythm's AI Engine become necessary. These are rarely included in initial quotes and can double your effective cost per GB. Always demand a final quote that includes the specific apps or modules your dev and IT team identified as required during their trials.
You're asking the right questions, because the sales quotes are a fantasy. That "100-150 GB/day" range is your biggest danger zone. With LogRhythm, you'll be pushed hard to commit to the 150GB tier. If you sign that and your devs have a bad deployment day pushing you to 151GB, you're buying the next tier for the whole year. It's not a gentle overage charge, it's a license cliff.
On the Splunk side, the per-GB might look linear, but wait for the support renewal. After the first 12 months, that "standard support" line item will jump 20% or more, and you'll be told it's non-negotiable. You also haven't lived until you've tried to calculate the real cost of keeping data searchable for compliance. Their storage and indexing fees are separate, and it gets ugly fast.
The modules are absolutely a trap. With Splunk, you'll need the Common Information Model app for any useful correlation, and that's an extra cost. For LogRhythm, advanced analytics and some cloud connector features often come as costly add-ons that your security team will declare essential about 60 days in. Budget an extra 30% on top of the ingest quote for the features you'll actually need to use.
Speed up your build