TL;DR: An example $8 billion enterprise running Google SecOps (previously Chronicle) can expect to pay about $500,000 a year in licensing, according to a Forrester study commissioned by Google, or $575,000 once risk-adjusted for factors like data volume and package tier. That figure is all we’ve got to go on, since Google doesn’t publish rates and quotes are built around data volume, retention, and deployment scope instead. That’s a change from Chronicle’s original pricing, which was a flat per-employee fee with unlimited log ingestion. Realm sits in front of Google SecOps and cuts ingested data by 50% to 70%, which makes your ingestion credits last longer, lowers retention costs, and shrinks any Assured Workloads surcharge that scales with SecOps spend. Get a 7-day cost savings assessment.
Google Security Operations (SecOps), formerly known as Chronicle, comes in three packages: Standard, Enterprise, and Enterprise Plus, all sold on a “contact sales for pricing” basis with no published rates and the actual number depending on data volume, retention, and which package tier you’re on.
That’s different from how Chronicle used to be sold. For years, Chronicle marketed itself as a SIEM that charged a flat fee based on employee count, not on how much data you sent it. The idea was that a security team could collect and analyze as many logs as they wanted without worrying about every extra GB and its impact on the bill.
A 2020 economic study by Enterprise Strategy Group, paid for by Google and hosted on Chronicle’s own site, described the model as an “all-you-can-eat data analysis engine” that “encourages rather than limits” the collection of security data.
Google’s current pricing page for SecOps states that pricing for all three packages is “based on ingestion” volume. SecOps now works the same way as most other SIEMs, i.e., the more data you send it, the more you pay.
Google SecOps Pricing Explained
Google Security Operations (SecOps) offers 3 pricing tiers: Standard, Enterprise, Enterprise Plus.
← Swipe to compare packages →
| Package | What’s included | Pricing |
|---|---|---|
| Standard | Core data ingestion, threat detection, investigation and response. 12 months hot data retention. Access to 700+ parsers and 300+ SOAR integrations. One environment with a remote agent. Detection engine caps at 1,000 single-event and 75 multi-event rules. Bring your own threat intel. Basic tools for filtering and modifying log data before it’s ingested. | Contact sales |
| Enterprise | Everything in Standard, plus unlimited environments with remote agent, a detection engine up to 2,000 single-event and 125 multi-event rules, UEBA through YARA-L, curated open source threat intel, Google’s curated detections, and Gemini in security operations. Basic tools for filtering and modifying log data before it’s ingested. | Contact sales |
| Enterprise Plus | Everything in Enterprise, plus a detection engine up to 3,500 single-event and 200 multi-event rules, full Google Threat Intelligence including Mandiant, advanced data pipeline management with routing to Google, and free BigQuery storage for SecOps data exports. Advanced filtering, redaction, transformations, and routing to Google Cloud destinations, plus up to 12 months of routing to another destination to support SIEM migrations. | Contact sales |
All three tiers include 12 months of hot data retention at no extra cost. Beyond that window, retention is billed separately based on how much data you’re keeping.
How Google SecOps Credits Work
While Google does not publish fixed public pricing for SecOps licenses, we can get an understanding of its billing structure, which follows a clear model when purchased as the unified SecOps package.
When you buy a Google SecOps package (Standard, Enterprise, or Enterprise Plus), your account gets a prepaid credit balance in gigabytes. Every gigabyte of data you send to Google SecOps is deducted from your prepaid data allowance. You can monitor this ongoing consumption directly within your billing console under the Bytes of data ingested SKU.
For Google SecOps to bill correctly, your SecOps project must be linked to the billing account that bought the subscription, and your contract must specify the deployment region because prices differ by region.
A few extra charges only apply if you meet specific conditions.
If your ingestion exceeds your commitment and you’ve used up your credits, you go into overage, billed monthly at your negotiated rate. If you keep data past the 12-month default retention window, that’s billed separately too, calculated on total data volume and billed a month in arrears. And if your organization deploys Google SecOps in a Google Cloud Assured Workloads environment using a Premium control package (for example, FedRAMP High), you’ll pay an additional percentage uplift on the cost of all Google Cloud services running in that Assured Workloads folder, including Google SecOps. The uplift appears as a separate line item on your invoice.
Separately, if your contract lapses before renewal, Google SecOps automatically enters a temporary grace period. This prevents service disruption and keeps your security coverage active while you complete your contract or offboard.
During this grace period, all usage and data ingestion are billed monthly in arrears at the standard list price on a pay-as-you-go basis. Negotiated discounts, custom pricing, and unused credits from your expired contract do not apply. Once you renew, your new contract terms and pricing take effect immediately on the start date of the booked agreement.
None of this is unusual for a SIEM, but it’s interesting that this is the opposite of how Chronicle was sold originally.
The Google SecOps Data Benefit Program (Free Ingestion, with Conditions)
Google also has a Data Benefit Program that lets you send certain types of security data into Google SecOps for free. That data doesn’t reduce your prepaid ingestion allowance. Eligible sources include GCP cloud audit logs and Google Workspace logs, both free up to 10GB a day, plus GCP CNAPP alerts, Chrome Enterprise logs, GCP context data, and approved third-party EDR alerts, all free with no stated cap.
You qualify for the Data Benefit Program if you sign a new or renewal SecOps order on or after February 1, 2026, you’re on the Enterprise or Enterprise Plus tier, and your subscription clears Google’s minimum annual contract value threshold for the program.
In other words, the free ingestion is a benefit for organizations on higher-tier plans that commit to spending at least a minimum amount with Google, and Google can change that minimum spend requirement over time.
Agentic SOC and Security Tokens
Google SecOps also has a separate unit called Security Tokens, used to meter its Agentic SOC features, meaning automated alert triage, investigation, and detection engineering done by AI agents rather than analysts.
Running these workflows consumes tokens based on the AI processing involved. Enterprise Plus customers get a daily complimentary allotment, which resets at midnight UTC and doesn’t roll over. Standard Enterprise customers don’t get a daily allotment at all.
Beyond whatever’s included, organizations buy a paid token subscription to keep using the agentic features.
What a Real Google SecOps Deployment Reportedly Costs
If you’ve read any of our other SIEM pricing breakdowns, you’ll know that actual figures are hard to come by (though that doesn’t stop us from trying to figure them out anyway!)
Like most other SIEM providers, Google doesn’t publish rates. However, we did find a Forrester Consulting study from July 2025, commissioned and paid for by Google (i.e., read this as vendor-commissioned research, not independent benchmarking).
The study modeled an example organization built from five customer interviews: a global enterprise with $8 billion in annual revenue, 20,000 employees, and a 25-person SecOps team.
For that composite, baseline licensing came to $500,000 a year, with Forrester then applying a 15% risk adjustment (to account for variables like customer-specific pricing, pricing package chosen by the customer, volume of data, and scope of implementation), bringing the figure to $575,000 a year, or $1.725 million over three years.
On top of licensing, the example company spent $156,170 upfront on implementation labor and $86,250 a year afterward on ongoing maintenance.
Here’s a three-year total cost summary (risk-adjusted):
← Swipe to see all years →
| Cost Category | Initial | Year 1 | Year 2 | Year 3 | 3-Year Total | Present Value (10%) |
|---|---|---|---|---|---|---|
| Licensing Fees (15% Uplift) | $0 | $575,000 | $575,000 | $575,000 | $1,725,000 | $1,429,940 |
| Internal Labor | $156,170 | $86,250 | $86,250 | $86,250 | $414,920 | $370,661 |
| Total Costs | $156,170 | $661,250 | $661,250 | $661,250 | $2,139,920 | $1,800,601 |
Though the above numbers only describe one fictional organization (even if based on the experiences of five real customers), the cost figures are still useful.
Because Google doesn’t publish pricing for Google SecOps, the licensing and labor costs in the study are one of the few publicly available pricing references and suggest the deployment was for Enterprise or Enterprise Plus rather than the Standard tier.
Reduce Google SecOps Costs with a Security Data Pipeline
Google SecOps bills by ingestion volume now, so the same rule that applies to pretty much every other SIEM applies here too. Send it less low-value data, and the credit balance will last longer, overage will arrive later, and retention will cost less if you extend past 12 months.
Reducing the amount of data sent to Google SecOps has three cost-saving effects.
- Your prepaid ingestion credits last longer. Google SecOps gives you a prepaid allowance for ingesting data. If you filter out unnecessary logs, you use those credits more slowly, and you’re less likely to exceed your allowance and incur overage charges.
- Your extended retention costs are lower. If you pay Google to retain data for longer than the standard period, those charges are based on how much data you ingest into SecOps. Sending less data into SecOps means there’s less data to retain, so your retention bill is lower.
- Your Assured Workloads surcharge is lower. If you use Google Assured Workloads, Google charges an additional percentage on top of the cost of eligible Google Cloud services, including SecOps. Because that surcharge is calculated as a percentage of your SecOps spend, a lower SecOps bill also means a lower Assured Workloads surcharge.
Doesn’t Google already offer a feature that reduces data intake?
Google’s pricing page lists data pipeline management, meaning filtering and transformation of log data before ingestion, on all three tiers: limited filtering and transformations on Standard and Enterprise, advanced filtering, redaction, and transformations on Enterprise Plus.
This appears to be the same capability Google documents in more technical detail elsewhere as Data Processing Pipelines, built on Bindplane, which lets you filter, transform, and redact log events before they reach SecOps for parsing.
Google’s own documentation on that tool is explicit that the point is cost reduction, dropping high-volume, low-value events so you only pay to ingest what’s actually relevant to security operations.
But the setup guide for that same tool states it’s available for Google SecOps Enterprise and Enterprise Plus users only, which doesn’t match the pricing page listing some form of filtering for Standard too.
Since Google’s own materials don’t seem to fully agree on this, it’s worth confirming directly with Google which filtering capability, if any, comes with Standard before assuming it matches what Enterprise gets.
There are also a few other things you should know about Google’s Data Processing Pipelines before assuming it replaces a dedicated pipeline layer.
One is that it’s still in Preview. The setup guide notes that the feature is covered by Pre-GA Offerings Terms, and that pre-GA features might have limited support and might not be compatible with other pre-GA versions.
It’s also built and maintained by your own team, regardless of whether you set it up through the Bindplane console or directly through the API. Google’s optimization guide has you start by analyzing your own ingestion metrics to figure out which log types and sources are driving cost before you build any of this.
And finally, it only covers Google SecOps, so if you ever want to move SIEMs, you’ll need to build the same kind of filtering setup over again on whatever platform you move to.
So, Google’s tool can reduce your bill, but it requires engineering time to build and only works if you stay on SecOps. For many teams, a security data pipeline that’s independent of the SIEM and provides you with tailored optimizations is a better option.
How Reducing Ingestion With Realm Lowers Your Google SecOps Bill
Realm Security is the SOC-aware security data pipeline that sits between your data sources and Google SecOps, ensuring only the logs you need for security monitoring are sent to the SIEM.
Less important or low-value data is kept out of SecOps, reducing ingestion and storage costs. Instead, it is stored in Realm Data Haven, a lower-cost log repository. There, the logs remain in their full, normalized form for compliance and audit requirements, forensic investigations, and historical searches if you need them later. By default, logs are retained for one year, with the option to extend retention to five years.
Realm Detection Integrity removes entire low-value log events only after confirming they aren’t needed by any detection rules in SecOps. If a log is required to detect threats, it is always kept and sent to the SIEM unchanged.
Most Realm customers see the effect within the first week. Typical outcomes are a 40%+ reduction in SIEM cost and a 50% to 70% reduction in ingested volume, with time back for analysts.