Simplicalcs

    SIEM log volume estimator

    Source type Count Events/day GB/day
    Total โ€” โ€”
    How would you like to enter your rate?
    events per second
    Average event size
    bytes
    Typical values: Windows events ~500 bytes ยท Firewall logs ~300 bytes ยท Proxy logs ~800 bytes
    Compression ratio Most SIEMs compress log data before storage
    1:1 20:1 :1
    10:1 is a typical default. Structured logs compress more; raw syslog compresses less.
    Enter your source counts above to see volume estimates.
    Advertisement

    SIEM platforms ingest logs from across an organisation's infrastructure and store them for detection, investigation, and compliance. The volume of data they receive โ€” and store โ€” has a direct impact on licensing costs, storage requirements, and query performance. This tool estimates ingestion volume from the number and type of log sources in an environment, using typical event rates drawn from real-world SIEM deployments. The compression estimate reflects the fact that most platforms compress log data before writing it to disk, typically achieving ratios of 8:1 to 12:1 depending on data type โ€” structured JSON logs compress well, while raw syslog compresses less predictably. EPS (events per second) is included because it is the metric most SIEM vendors use to size and licence their platforms.