Tools

SIEM / SOAR Sizing Calculator

Estimate storage, compute, RAM, and infrastructure sizing for SIEM and SOAR deployments using a clean architecture-first workflow.

Answer First

How do you size SIEM ingestion?

SIEM ingestion is sized by estimating events per second, daily gigabytes, source mix, parsing overhead, retention period, search concurrency, and growth. The practical target is not only storage; it is a platform that can ingest, correlate, search, and retain evidence during real investigations.

Recommended approach

Inventory high-value log sources first, measure or estimate EPS and average event size, then model retention and search workload. Keep noisy sources separate from detection-critical sources so cost control does not remove the evidence analysts need.

Decision area
Use this guidance
Watch closely
Ingestion
Estimate EPS and GB/day by source type, then add growth and parsing overhead.
Burst traffic, duplicate logs, verbose cloud events, and normalization failures.
Retention
Separate hot searchable data, warm investigation data, and cold compliance storage.
Regulatory minimums, incident lookback needs, and restore time.
Compute
Model correlation, dashboards, searches, and report generation against analyst concurrency.
Slow searches, dropped events, queue depth, and peak-hour alert delays.

Frequently asked

What metrics drive SIEM sizing?

Events per second (EPS), average event size, daily ingest in GB/day, retention period, and the mix of log sources feeding the platform.

How much retention should I plan for?

Match retention to compliance and investigation needs, and separate hot (searchable) from cold (archive) storage to control cost while meeting audit requirements.

Does this replace a vendor SIEM quote?

No. It is a deterministic estimator for planning; confirm final sizing and licensing with your SIEM vendor.

SIEMSOARSOCXDRCortex XDRCortex XSOARLog retentionThe Cyber AdviserAttique Bhatti

SOC Architecture

Built for security engineers and solution architects

Use this calculator to estimate ingestion footprint, storage retention, and node topology across common SIEM and SOAR platforms. The implementation mirrors the public reference flow while keeping the code modular and editable.

Related Tools

Prisma Access Sizing Calculator

Estimate logging, bandwidth, and deployment planning for Prisma Access workshops.

Unified Migration

Convert and validate firewall configurations across vendors from a dedicated migration workspace.

Free Tool
Beta

SIEM Sizing Calculator

Estimate the storage, compute, and cost requirements for your SIEM or SOAR deployment. Designed for SOC architects and security engineers.

Platform

Choose the SIEM or SOAR platform profile to apply the right ingestion and agent coefficients.

Total employees in scope for endpoint and user-centric telemetry assumptions.

Firewalls, switches, routers, proxies, access points, and similar network sources.

Transparent sizing assumptions are stored in reusable platform config and a pure calculation engine, so you can tune formulas later without rewriting the UI.
Recommended Architecture

Distributed

A distributed architecture is recommended to separate control, indexing, and presentation roles as ingest and resilience requirements increase.

1

Master node

1

Indexer nodes

1

Dashboard nodes

0

Worker nodes

Estimated agents

54

Estimated daily volume

15.0 GB

Estimated storage (90 days)

192.9 GB

Infrastructure Summary

ComponentQtyvCPURAMDisk
Master node148.0 GB50.0 GB
Indexer nodes148.0 GB193.0 GB
Dashboard nodes124.0 GB50.0 GB
Total31020.0 GB293.0 GB
Need more precision? Switch to Advanced mode for per-source configuration and retention tuning.

How sizing is calculated

Daily volume is modeled from source counts and platform coefficients. Storage is estimated as daily ingest multiplied by retention and divided by the compression ratio.

Start a conversation

Whether you are planning an implementation, migration, security architecture review, or operational optimization, let us discuss your requirements.