| Source type | Count | Events/day | GB/day |
|---|---|---|---|
| Total | โ | โ | |
SIEM platforms ingest logs from across an organisation's infrastructure and store them for detection, investigation, and compliance โ the volume they receive and store has a direct impact on licensing costs, storage requirements, and query performance. This tool estimates that volume either from the number and type of log sources you have, or from a directly entered event rate.
Each log source type in the "By source" table uses a typical events-per-day figure and average event size drawn from real-world SIEM deployments โ a firewall, for example, generates far more events per day than a handful of Active Directory servers, and at a smaller average size per event. Add a count for each source type you actually have deployed; anything not listed can be entered as "Other / custom" with its own EPS and average event size.
Most SIEM platforms compress log data before writing it to disk, typically achieving ratios of 8:1 to 12:1 depending on data type โ structured JSON logs compress well, while raw syslog compresses less predictably. The compression slider lets you match the estimate to your own platform's typical ratio; 10:1 is a reasonable default if you don't know it yet.
EPS (events per second) is shown because it's the metric most SIEM vendors use to size and licence their platforms, alongside or instead of GB/day. If you already have a vendor's licensing quote in EPS, switch to "By rate" mode and enter it directly to see the equivalent ingestion and storage volume.
These are estimates based on typical event rates and average event sizes, not a substitute for a real ingestion audit. Actual volumes vary significantly with environment configuration, logging verbosity, retention policy, and the specific security tooling in use โ treat these figures as a starting point for capacity planning and licensing conversations, not a guarantee.