TL;DR: The price CrowdStrike quotes for ingestion and retention in their NG-SIEM product depends on how you buy it (i.e., with or without support/through a bundled deal) and on the amount of data you send to it. However, two independent sources put it at least $2,170 per GB/day per year for ingestion, plus a separate retention add-on. Realm can sit in front of NG-SIEM and cut the data volume reaching it by 50% to 70%. Realm customers typically see at least a 40% reduction in overall costs and avoid paying for unused data, and Detection Integrity proves the cut never cost them a detection.
CrowdStrike publishes list pricing for its Falcon endpoint tiers, but Falcon Next-Gen SIEM (NG-SIEM) isn’t included in any of them, and CrowdStrike doesn’t publish a price for it anywhere on its own website.
An AWS Marketplace listing and a UK government pricing framework give some indication of current NG-SIEM pricing. Just note that both figures should be viewed as rough indicators, as they are not official sources.
However, even without an exact number from CrowdStrike, we know how to bring CrowdStrike NG-SIEM pricing down. Realm is the SOC-aware security data pipeline. It sits upstream of your SIEM and cuts cost without costing you a detection, regardless of which platform you’re on. Customers typically see at least a 40% reduction in SIEM cost and a 50 to 70% reduction in ingested volume.
Below, we explain the factors that influence CrowdStrike NG-SIEM pricing.
CrowdStrike Falcon Next-Gen SIEM Pricing Explained
CrowdStrike’s pricing page is transparent for the endpoint side of the business, with three of the four tiers on CrowdStrike’s pricing page listing real numbers.
← Swipe to compare tiers →
| Falcon Go | Falcon Pro | Falcon Enterprise | Falcon Complete Next-Gen MDR | |
|---|---|---|---|---|
| Price | $59.99/device/year | $99.99/device/year | $184.99/device/year | Contact sales |
| Next-gen antivirus | Yes | Yes | Yes | Yes |
| Device control | Yes | Yes | Yes | Add-on |
| Firewall management | No | Yes | Yes | Add-on |
| Endpoint detection and response | No | No | Yes | Yes |
| Threat hunting & intelligence | No | No | Yes | Yes |
| Identity protection | No | No | No | Add-on |
| IT hygiene | No | No | No | Yes |
| Next-gen SIEM | No | No | No | Yes |
As you can see from the table above, CrowdStrike’s NG-SIEM only shows up under Falcon Complete, the fully managed MDR tier that requires a sales conversation.
Go, Pro, and Enterprise, the three tiers with real self-serve pricing, don’t include NG-SIEM at any price. That makes NG-SIEM a separate purchase from Go, Pro, and Enterprise specifically. It isn’t universally separate from CrowdStrike’s platform, though, as Falcon Flex can bundle it into the same credit pool as endpoint coverage, and existing Falcon Insight XDR customers get some NG-SIEM access included for free (both of which we come back to further down).
The Two Public Data Points on CrowdStrike NG-SIEM Pricing
CrowdStrike doesn’t list pricing for its NG-SIEM on its website. However, two independent sources provide estimates of its list rates.
The first is the AWS Marketplace, through which CrowdStrike sells its Falcon Next-Gen SIEM pay-as-you-go, billed as a flat $0.00595 per MB of non-Falcon data ingested, or $5.95/GB, with 13-month retention.
This is a consumption-based model rather than a GB/day capacity subscription, so it’s most useful for AWS-native environments that want to scale ingestion up or down without a fixed annual commitment.
The second is CrowdStrike’s pricing response to the UK Government’s G-Cloud 14 framework, which lists full rates for NG-SIEM and Logscale. Pricing is published in GBP.
The table below converts the published GBP rates to estimated USD at two points: the document’s May 2024 publication date, and current rates as of this writing.
← Swipe to see all rates →
| Service Item | Pricing Metric | Unit Price Per Annum (GBP) | Est. May 2024 USD Rate (~$1.26) | Est. July 2026 USD Rate (~$1.34) |
|---|---|---|---|---|
| Falcon Search Retention (180 days) | Per Endpoint | £38 | $47.88 | $50.92 |
| Falcon Next Gen-SIEM | Per GB/Day (3rd Party Data) | £2,000 | $2,520 | $2,680.00 |
| Falcon NG-SIEM Retention | Per GB/Day (Desired Retention) | £615 | $774.90 | $824.10 |
| Falcon Logscale Cloud | Per GB/Day (3rd Party Data) | £1,370 | $1,726.20 | $1,835.80 |
| Falcon Logscale Retention | Per GB/Day (Desired Retention) | £205 | $258.30 | $274.70 |
Note that the G-Cloud document is from May 2024, so we recommend treating the figures as directional for 2026 rather than considering them the current quote.
That said, the two sources (the AWS Marketplace listing and the G-Cloud document) are similar on a unit basis.
- £2,000 per GB/day per year converts to roughly $2,680 at current exchange rates.
- The AWS Marketplace rate of $5.95/GB, annualized over a full year of sustained 1 GB/day ingestion (365 GB), comes to about $2,170.
Those are two independently published numbers from two different sources, coming in within about 20% of each other, though, of course, we cannot guarantee that either reflects an accurate current price of CrowdStrike NG-SIEM.
How CrowdStrike NG-SIEM Is Priced for Ingestion vs Retention
CrowdStrike splits NG-SIEM cost the way most modern SIEMs do, into:
- How much data you send to it each day (ingestion): The ingestion metric is “GB/Day,” a measure of your average daily log volume from third-party sources, such as firewalls, cloud providers, and Windows event logs, sustained over a full year.
- How long you keep it searchable (retention): The base rate includes 7 days of search retention by default. Anything longer requires the separate retention add-on, priced per GB/day of the ingestion capacity you’ve already purchased.
Using CrowdStrike’s G-Cloud 14 list rates as a worked example, an environment generating 100 GB/day of third-party log volume that needs 90 days of retention for compliance would need a 100 GB/Day ingestion tier at £2,000/GB/day/year, plus a retention add-on at £615/GB/day/year to stretch the default 7-day window out to 90 days.
That’s £200,000 in ingestion plus £61,500 in retention, for a combined £261,500 per year (roughly $350,400 at current exchange rates), before support costs and before any volume discount CrowdStrike might apply at negotiation.
CrowdStrike notes that unless otherwise specified, customers pay for licenses upfront and don’t receive refunds for unused volume. If your usage exceeds the licensed amount, you’ll need to upgrade to the next tier or quantity at the current list price (unless you have agreed to different terms in writing). That said, it also states that it notifies customers when ingestion exceeds the licensed amount, potentially preventing them from incurring additional charges for ingestion.
Support Is Also a Separate Line Item
CrowdStrike’s G-Cloud 14 response also breaks out three support tiers, each priced as a percentage of software cost.
Express Support runs 12% of software cost, capped at £12,000 (roughly $16,080 at current rates), and is intended for organizations under 2,500 employees. Essential Support is also 12%, but with a £12,000 floor rather than a ceiling, for organizations above 2,500 employees. Elite Support, which includes a dedicated Technical Account Manager, runs 25% of the software cost with a £120,000 minimum (roughly $160,800).
Other Ways CrowdStrike NG-SIEM Gets Sold
A few other paths exist to acquiring CrowdStrike NG-SIEM.
A fully managed bundle through Microsoft Marketplace
A CrowdStrike reseller lists NG-SIEM bundled with a 24/7 managed SOC service on Microsoft Marketplace, packaged as 200 GB/day data ingestion, 12 months of retention, and managed SOC monitoring, starting at $169,000/year.
Falcon Flex
CrowdStrike also sells a portfolio-wide subscription called Falcon Flex, where customers buy a credit pool that can be spent across the full Falcon product line, including NG-SIEM, and swapped between modules during the agreement term. We were unable to find public pricing for Falcon Flex.
A free allowance for existing Falcon Insight XDR customers
Anyone already on Falcon Insight XDR gets NG-SIEM access inside the Falcon console, plus 10 GB/day of free third-party data ingestion included at no additional cost.
Data Volume Is the Biggest Driver of CrowdStrike NG-SIEM Costs
Regardless of how a vendor packages its SIEM pricing, most SIEM costs are based on data volume and retention.
The problem is that a large portion of the logs that organizations send to their SIEMs are low-value events that nobody investigates and that rarely contribute to detections. For example, health checks, debug logs, and routine authentication events. These logs generate little security value, but they still consume resources, so the SIEM vendor charges you the same rate for them as for high-value security events.
For organizations evaluating different SIEMs, the more important question is often not which platform to use, but which data is worth paying to ingest and retain at all.
CrowdStrike Onum acquisition
In August 2025, CrowdStrike acquired Onum, a real-time data observability and telemetry pipeline company, specifically to feed NG-SIEM and power the agentic SOC.
CrowdStrike’s own description of what Onum does is that it “transforms data in motion.” Rather than the traditional store-then-analyze approach, Onum filters, enriches, and optimizes telemetry in real time, as it streams.
The stated result is a reduction in data storage costs of up to 50% by eliminating noise and duplicate logs before they’re indexed.
We find this notable because CrowdStrike itself appears to acknowledge that the biggest cost savings come from reducing data before it enters a SIEM platform, rather than trying to manage or optimize it after it’s already been ingested.
Realm’s platform is based on this exact idea that organizations should reduce unnecessary data before it reaches the SIEM. Unlike features built into a specific SIEM vendor’s platform, Realm does this independently and can work with multiple SIEMs and storage destinations.
How Realm Reduces CrowdStrike NG-SIEM Costs
Realm Security sits in front of CrowdStrike NG-SIEM and routes data to multiple destinations simultaneously without reconfiguring the source integration.
High-signal detection data goes into NG-SIEM, while lower-value hunting, forensics, and compliance data can be routed to Realm Data Haven or another storage destination in parallel.
Since filter and routing rules are recommended by Realm Clarity AI, the platform’s intelligence layer, all your team has to do is review and approve them rather than create them from scratch. Every recommendation comes with a written justification. Nothing ships until Detection Integrity checks it against the detections you actually run, so events a detection depends on are never filtered out.
With CrowdStrike’s pricing model, where extended retention is purchased against your ingestion capacity, reducing data volume lowers a) ingestion costs and b) retention costs.
This is because a smaller ingestion tier requires a smaller retention entitlement.
| Before Realm | ✦ After Realm |
|---|---|
| 500 GB/day ingestion | 300 GB/day ingestion |
| Retention priced on 500 GB/day | Retention priced on 300 GB/day ingestion |
| Higher cost | Lower cost |
Note: The benefits of reducing data volume extend beyond traditional GB/day licensing. In credit-based models such as Falcon Flex, using something like Realm helps preserve credits for other uses. In bundled licensing models, it helps organizations stay within their purchased capacity and avoid costly tier upgrades.
Data Haven is the searchable retention layer that sits alongside NG-SIEM. What you cut from the SIEM lands there as a complete, searchable copy, so you keep full access to your history at a fraction of SIEM cost.
Data Haven plugs into the Realm Platform, so only high-signal alerts go into NG-SIEM, while full raw and normalized logs stream into Data Haven automatically, with no storage setup, routing rules, or manual tuning needed.
Default retention is one year, scaling to five.
When an investigation needs historical data, analysts can use a guided resupply workflow to pull a narrowed dataset of specific IPs, users, or hostnames back into an NG-SIEM index in minutes.
And because logs are normalized to OCSF on ingestion, Data Haven stays portable if you ever switch SIEMs.
Ready to See What You’d Actually Save with Realm?
Schedule a demo of Realm.Security, and we’ll walk you through how much you could cut from your next CrowdStrike NG-SIEM invoice without giving up a single detection.