Microsoft Sentinel vs Splunk Enterprise Security vs Google Security Operations: Real AI SIEM Cost per GB
Short answer
These three SIEMs don't just charge different rates — they charge on entirely different bases, which matters far more than any single per-GB number. Microsoft Sentinel has a genuinely public, confirmed per-GB rate ($4.30/GB pay-as-you-go, dropping with volume commitments). Splunk Enterprise Security has no published per-GB rate at all for the security layer specifically. Google Security Operations does something structurally different from both: it's reported to price per employee per year with effectively unlimited ingestion bundled in — under that reported model, Google's cost is modeled here as flat with respect to ingestion volume, a genuinely different economic model, not just a different number, though the underlying pricing itself is reported rather than officially published. In SIEM specifically, the "AI" layer is close to a rounding error next to what telemetry ingestion itself costs.
Pricing at a glance
| Microsoft Sentinel | Splunk Enterprise Security | Google Security Operations | |
|---|---|---|---|
| Pricing basis | Per GB ingested (confirmed, official) | Ingest-based or Splunk Virtual Compute (SVC)-based; no published per-GB rate for the Enterprise Security layer specifically | Per employee per year, with ingestion volume theoretically a factor but reportedly bundled as "effectively unlimited" in practice |
| Public rate card | Yes — Azure's own pricing page | No — quote-only for the security-specific application layer | No — Standard, Enterprise, and Enterprise Plus packages are all quote-only |
| Pay-as-you-go rate | $4.30/GB (East US) to $5.59/GB (West US), regional | Reported base ingest ~$100–180 per GB/day of committed capacity, plus a reported $20–45/GB/day premium specifically for adding Enterprise Security | Not applicable — doesn't bill per GB |
| Volume commitment discount | Yes, published tiers at 100/200/300/400/500 GB/day, 1 TB/day, and 2 TB/day; effective rate drops to $2.48/GB at the 1 TB/day tier | Reported enterprise negotiated discounts of 35–40% at very high volume (1,000+ GB/day) | N/A — per-employee rate doesn't change with volume |
| Notable free/bundled ingestion | Azure Activity logs, Office 365 audit logs, and Microsoft Defender alerts ingest free; Entra ID sign-in logs do not | Not reported | Effectively unlimited ingestion bundled into the per-employee rate |
| Alternative billing model | Data lake tier for cold/secondary storage: $0.05/GB ingestion, $0.026/GB/month storage (6:1 compression), $0.005/GB scanned for queries | Splunk Virtual Compute (SVC) units, reported ~$55,000–75,000/SVC/year, for workload-based rather than ingest-based billing | Free Chronicle SOAR Community Edition exists for automation only, not full SIEM ingestion |
What headline pricing excludes
Splunk requires Enterprise Security as a separate license on top of the base Splunk platform for full SIEM functionality — the reported $20–45/GB/day premium for adding it isn't optional if the goal is genuine SIEM detection capability, not just log search. A cost comparison that only prices base Splunk ingestion without this add-on is comparing the wrong product.
Microsoft Sentinel's free ingestion for certain Microsoft-native log sources is a real, meaningful discount for Microsoft-shop SOCs — but it's selective, not blanket. Azure Activity, Office 365 audit logs, and Defender alerts ingest free; Entra ID sign-in logs, notably, do not. A company assuming "everything Microsoft-native is free" will be surprised by which specific log sources are and aren't included.
Google's per-employee pricing model means the headline number has almost nothing to do with your actual log volume — this cuts both ways. A company with unusually high log volume relative to its headcount gets a great deal on Google; a company with low log volume relative to headcount is effectively overpaying for ingestion capacity it doesn't need, since the per-employee rate doesn't flex downward either.
Hidden costs
- Microsoft Sentinel's commitment tiers charge for the full committed volume whether or not you use it — unused capacity below a commitment tier is not refunded, and overage above the commitment bills at the same effective per-GB rate as the tier itself (not a punitive higher rate), which is a genuinely fairer overage mechanism than many SaaS pricing models use.
- Sentinel's Basic Logs tier is cheaper to search ($0.005/GB scanned) but cannot run detection or analytics rules against it — primary security telemetry that actually needs real-time threat detection has to stay in the standard (more expensive) analytics tier; routing security-critical logs to Basic Logs to save money would silently disable detection on that data.
- Splunk's workload-based (SVC) pricing can be cheaper or more expensive than ingest-based pricing depending on your specific search-to-ingest ratio — a deployment with very high ingest but relatively light search activity may save money on SVC pricing, while a deployment doing heavy, frequent searching against a smaller data volume may find ingest-based pricing cheaper. There's no universal answer; it depends on actual usage patterns.
- Google's Enterprise and Enterprise Plus tiers include Data Processing Pipelines (pre-ingestion filtering and redaction) — a capability that could reduce a company's effective ingestion volume if used to filter out low-value logs before they count against any usage metering, though Google's per-employee model may make this less financially consequential than it would be under a strict per-GB competitor.
Worked scenarios
Splunk's lack of a published per-GB rate for Enterprise Security specifically means its figures below are estimated extrapolations from reported anchor points, clearly labeled as such.
100 GB/day
| Estimated annual cost | |
|---|---|
| Microsoft Sentinel (100 GB/day commitment tier) | Roughly $130,000–155,000/year, estimated by interpolating between the confirmed pay-as-you-go rate ($4.30/GB) and the confirmed 1 TB/day commitment rate ($2.48/GB) |
| Splunk (base ingest + Enterprise Security) | No confirmed rate at this volume; extrapolating from a confirmed 50 GB/day anchor point (~$175,000–215,000/year before discount) suggests a range well above Sentinel's cost at this volume, though Splunk's actual negotiated rate could differ substantially |
| Google Security Operations (per-employee, illustrative 1,000-employee organization) | Reported ~$60,000–95,000/year — and 100 GB/day is reported to be roughly the volume at which Google's per-employee math starts to clearly beat Sentinel's commitment-tier pricing for an organization of this size |
This is the volume at which, under the reported pricing assumptions used here, Google's structurally different pricing model would begin to show an advantage for a mid-sized organization — not because Google is cheaper in general, but because its modeled cost stops scaling with ingestion right around this point.
500 GB/day
| Estimated annual cost | |
|---|---|
| Microsoft Sentinel (500 GB/day commitment tier) | Roughly $500,000–550,000/year, estimated from the same interpolation method above |
| Splunk (base ingest + Enterprise Security) | Not confirmed at this volume; likely well into seven figures based on the scaling pattern from lower-volume anchor points, though large-volume negotiated discounts (reported 35–40% at very high volume) could reduce this meaningfully |
| Google Security Operations (same illustrative 1,000-employee organization) | Still reported at roughly $60,000–95,000/year — under the reported per-employee pricing model, this figure is modeled as not moving even though ingestion volume is now 5x the 100 GB/day scenario |
At 500 GB/day for a 1,000-employee organization, Google's reported flat per-employee cost would be dramatically cheaper than Sentinel's under the modeling assumptions used here — an illustration of how completely the two pricing philosophies diverge once volume climbs well past the crossover point, though this rests on the reported Google figures being accurate.
1 TB/day (1,000 GB/day)
| Estimated annual cost | |
|---|---|
| Microsoft Sentinel (1 TB/day commitment tier, confirmed rate) | 1,000 × 365 × $2.48 = ~$905,200/year |
| Splunk | Not confirmed; at this scale, reported negotiated Enterprise Agreement discounts of 35–40% become available, which could bring Splunk's effective cost closer to Sentinel's, but no confirmed figure exists to calculate this precisely |
| Google Security Operations | Per-employee rate remains a function of headcount, not ingestion volume — for the same illustrative 1,000-employee organization, still in the reported $60,000–95,000/year range, now a small fraction of Sentinel's confirmed cost at this volume |
Break-even and crossover
Under the reported per-employee pricing assumptions used here, the illustrative crossover is roughly this: an organization needs to ingest somewhere around 80–100 GB per day per 1,000 employees before Google Security Operations' reported per-employee pricing model would beat Microsoft Sentinel's confirmed commitment-tier pricing. Below that ratio, Sentinel's confirmed per-GB model is likely cheaper for a Microsoft-shop organization (especially accounting for its free ingestion of certain Microsoft-native log sources). Above it, Google's reported flat per-employee cost would increasingly dominate under the modeling assumptions used in this article, since it's modeled as not moving with ingestion volume the way Sentinel's or Splunk's confirmed or reported ingest-based pricing does — though this entire crossover rests on Google's per-employee pricing being reported accurately, which this article cannot independently confirm.
Who pays more, and when
- A Microsoft-shop organization with moderate, predictable log volume benefits from Sentinel's free ingestion of Microsoft-native sources and its transparent, published commitment-tier pricing — the easiest of the three to model and budget confidently.
- An organization with unusually high log-volume-per-employee (verbose logging, extensive third-party telemetry, high transaction volume relative to headcount) should seriously evaluate Google Security Operations' per-employee model, which can become dramatically cheaper than either per-GB competitor once volume crosses the reported 80–100 GB/day-per-1,000-employees threshold.
- A large, established SOC with existing Splunk expertise and infrastructure, particularly one needing on-premises or air-gapped deployment for regulatory reasons, may find Splunk Enterprise Security's negotiated enterprise pricing worthwhile despite the lack of published rates — self-managed deployment flexibility is a real value that a pure per-GB comparison doesn't capture.
- An organization with low log-volume-per-employee (a lean, low-transaction-volume business with a large headcount) is likely to overpay under Google's per-employee model relative to what it would pay per-GB elsewhere, since that model doesn't flex downward for lower actual usage.
Limitations and uncertainty
Microsoft Sentinel's pricing is the only fully confirmed, official rate card among the three, sourced directly from Azure's own pricing page. Splunk Enterprise Security's cost figures in this article are estimated extrapolations from a small number of reported anchor points (a confirmed-sounding $175,000–215,000/year range at 50 GB/day) rather than a published rate, and should be treated as directional, not precise — Splunk's actual negotiated enterprise pricing varies significantly by contract terms, committed volume, and multi-year discounts that aren't publicly itemized. Google Security Operations' per-employee figures are reported rather than officially published, and the specific 1,000-employee example used throughout this article's scenarios is illustrative — actual per-employee rates likely vary by package tier (Standard, Enterprise, Enterprise Plus) and negotiated contract terms not disclosed publicly.
Official sources
- azure.microsoft.com/en-us/pricing/details/microsoft-sentinel/ (the source of Sentinel's confirmed rates)
- Splunk does not publish a per-GB rate for Enterprise Security specifically; figures here are reported/third-party estimates
- Google does not publish pricing for Security Operations (Standard, Enterprise, or Enterprise Plus); figures here are reported/third-party estimates