When the SIEM bill tripled, the team needed to cut cost without gambling coverage.
Over three years, the firm’s Microsoft Sentinel spend grew from $75K to $200K. Most of the growth came from high-volume sources, firewall and proxy logs that filled storage without improving what the team could detect. A roughly 40-hour manual filtering effort the year before had barely moved the number.
Leadership handed the security team a clear mandate: bring the cost down without weakening the detections the business depended on. The obvious lever, cutting log volume, was exactly the one the SOC was afraid to pull. The team owned those detections, and if a reduction silently broke one, they would be the ones held responsible.
A SOC-managed platform that checks every cut against live detections
The firm evaluated Cribl first, but the technical team saw that the effort to deploy would negate the savings. They turned to Realm for a SOC-managed platform that reduces volume before ingestion into Sentinel and, critically, checks each cut against the detections actually running on that data. Realm calls this Detection Integrity.
Critically, reduced data is not dropped. The firm’s three-year retention requirement was addressed by Data Haven, Realm’s fully-managed retention layer. Data Haven retains a complete, searchable copy outside the SIEM, offsetting the storage portion of the Azure Sentinel bill, roughly a third of the total, before filtering savings even factored in.
“[We] selected Realm for effectiveness of reduction capabilities and modern, fully managed architecture.”
Earning trust, not asking for it
The real obstacle was never the math. It was trust: if an operator approved a filtering change and a downstream detection quietly broke, that operator would own the failure. So Realm did not ask the team to take filtering on faith.
Parity, Proven
The team handed Realm rules from their CrowdStrike rule set and asked it to prove parity. Realm validated each reduction against those detections before anything changed.
Fields Protected
Realm protected the exact fields each detection depends on, so cutting high-volume noise could not silently strip the data a rule needs to fire.
Reasoning Visible, Call Left to the Team
Realm produced a report showing what was cut and what stayed covered. Not a black box telling the team to trust it, but a method to manage the risk, with the decision theirs.
48 Hours to Confirmed Savings
The prior year’s 40-hour manual effort produced modest savings and no way to show coverage held. With Realm, the proof of concept went from start to confirmed savings in 2 days.
86% Less High-Volume Log Data, Zero Detection Gaps
Realm filtered high-volume noise before ingestion into Sentinel and validated every reduction against the team’s own detection rules, cutting Fortinet and Zscaler log volume 86% while proving, on their data, that coverage held. Data Haven solved the three-year retention requirement, and shaved roughly a third off of Azure Sentinel data storage costs.
By the numbers
Built to keep paying off
Filtering before ingestion did more than lower a bill. With less routine noise reaching Sentinel, analysts spent their time on signal instead of high-noise volume. And because the reduction is validated against live detections rather than configured once and forgotten, the coverage check the team had been going without is there to run again whenever rules change.
Months after deployment, the firm is extending the same approach to additional log sources, treating the first rollout as the template for the rest of its estate. Each new source follows the same sequence: filter before ingestion, validate cuts against live detections, and confirm coverage before the change goes live.