Tools
SIEM / SOAR Sizing Calculator
Estimate storage, compute, RAM, and infrastructure sizing for SIEM and SOAR deployments using a clean architecture-first workflow.
Answer First
How do you size SIEM ingestion?
SIEM ingestion is sized by estimating events per second, daily gigabytes, source mix, parsing overhead, retention period, search concurrency, and growth. The practical target is not only storage; it is a platform that can ingest, correlate, search, and retain evidence during real investigations.
Recommended approach
Inventory high-value log sources first, measure or estimate EPS and average event size, then model retention and search workload. Keep noisy sources separate from detection-critical sources so cost control does not remove the evidence analysts need.
Frequently asked
What metrics drive SIEM sizing?
Events per second (EPS), average event size, daily ingest in GB/day, retention period, and the mix of log sources feeding the platform.
How much retention should I plan for?
Match retention to compliance and investigation needs, and separate hot (searchable) from cold (archive) storage to control cost while meeting audit requirements.
Does this replace a vendor SIEM quote?
No. It is a deterministic estimator for planning; confirm final sizing and licensing with your SIEM vendor.
SOC Architecture
Built for security engineers and solution architects
Use this calculator to estimate ingestion footprint, storage retention, and node topology across common SIEM and SOAR platforms. The implementation mirrors the public reference flow while keeping the code modular and editable.
Related Tools
Prisma Access Sizing Calculator
Estimate logging, bandwidth, and deployment planning for Prisma Access workshops.
Unified Migration
Convert and validate firewall configurations across vendors from a dedicated migration workspace.
SIEM Sizing Calculator
Estimate the storage, compute, and cost requirements for your SIEM or SOAR deployment. Designed for SOC architects and security engineers.
Platform
Choose the SIEM or SOAR platform profile to apply the right ingestion and agent coefficients.
Total employees in scope for endpoint and user-centric telemetry assumptions.
Firewalls, switches, routers, proxies, access points, and similar network sources.
Distributed
A distributed architecture is recommended to separate control, indexing, and presentation roles as ingest and resilience requirements increase.
1
Master node
1
Indexer nodes
1
Dashboard nodes
0
Worker nodes
Estimated agents
54
Estimated daily volume
15.0 GB
Estimated storage (90 days)
192.9 GB
Infrastructure Summary
| Component | Qty | vCPU | RAM | Disk |
|---|---|---|---|---|
| Master node | 1 | 4 | 8.0 GB | 50.0 GB |
| Indexer nodes | 1 | 4 | 8.0 GB | 193.0 GB |
| Dashboard nodes | 1 | 2 | 4.0 GB | 50.0 GB |
| Total | 3 | 10 | 20.0 GB | 293.0 GB |
How sizing is calculated
Daily volume is modeled from source counts and platform coefficients. Storage is estimated as daily ingest multiplied by retention and divided by the compression ratio.