SIEM log volume estimator

    Source type Count Events/day GB/day
    Total โ€” โ€”
    How would you like to enter your rate?
    events per second
    Average event size
    bytes
    Typical values: Windows events ~500 bytes ยท Firewall logs ~300 bytes ยท Proxy logs ~800 bytes
    Compression ratio Most SIEMs compress log data before storage
    1:1 20:1 :1
    10:1 is a typical default. Structured logs compress more; raw syslog compresses less.
    Enter your source counts above to see volume estimates.
    Advertisement

    How SIEM log volume is estimated

    SIEM platforms ingest logs from across an organisation's infrastructure and store them for detection, investigation, and compliance โ€” the volume they receive and store has a direct impact on licensing costs, storage requirements, and query performance. This tool estimates that volume either from the number and type of log sources you have, or from a directly entered event rate.

    Per-source event rates

    Each log source type in the "By source" table uses a typical events-per-day figure and average event size drawn from real-world SIEM deployments โ€” a firewall, for example, generates far more events per day than a handful of Active Directory servers, and at a smaller average size per event. Add a count for each source type you actually have deployed; anything not listed can be entered as "Other / custom" with its own EPS and average event size.

    Why compression matters for storage sizing

    Most SIEM platforms compress log data before writing it to disk, typically achieving ratios of 8:1 to 12:1 depending on data type โ€” structured JSON logs compress well, while raw syslog compresses less predictably. The compression slider lets you match the estimate to your own platform's typical ratio; 10:1 is a reasonable default if you don't know it yet.

    EPS and SIEM licensing

    EPS (events per second) is shown because it's the metric most SIEM vendors use to size and licence their platforms, alongside or instead of GB/day. If you already have a vendor's licensing quote in EPS, switch to "By rate" mode and enter it directly to see the equivalent ingestion and storage volume.

    Limitations

    These are estimates based on typical event rates and average event sizes, not a substitute for a real ingestion audit. Actual volumes vary significantly with environment configuration, logging verbosity, retention policy, and the specific security tooling in use โ€” treat these figures as a starting point for capacity planning and licensing conversations, not a guarantee.