Customer Story

A global consulting firm reins in
runaway Sentinel costs
without losing a single detection

How a regulated consulting and advisory firm watched its Microsoft Sentinel SIEM bill nearly triple, and within two days used Realm to cut high-volume log data 86% with zero detection gaps.

When the SIEM bill tripled, the team needed to cut cost without gambling coverage.

Over three years, the firm’s Microsoft Sentinel spend grew from $75K to $200K. Most of the growth came from high-volume sources, firewall and proxy logs that filled storage without improving what the team could detect. A roughly 40-hour manual filtering effort the year before had barely moved the number.

Leadership handed the security team a clear mandate: bring the cost down without weakening the detections the business depended on. The obvious lever, cutting log volume, was exactly the one the SOC was afraid to pull. The team owned those detections, and if a reduction silently broke one, they would be the ones held responsible.

A SOC-managed platform that checks every cut against live detections

The firm evaluated Cribl first, but the technical team saw that the effort to deploy would negate the savings. They turned to Realm for a SOC-managed platform that reduces volume before ingestion into Sentinel and, critically, checks each cut against the detections actually running on that data. Realm calls this Detection Integrity.

Critically, reduced data is not dropped. The firm’s three-year retention requirement was addressed by Data Haven, Realm’s fully-managed retention layer. Data Haven retains a complete, searchable copy outside the SIEM, offsetting the storage portion of the Azure Sentinel bill, roughly a third of the total, before filtering savings even factored in.

“[We] selected Realm for effectiveness of reduction capabilities and modern, fully managed architecture.”
Security Operations LeadershipGlobal Consulting & Advisory Firm

Earning trust, not asking for it

The real obstacle was never the math. It was trust: if an operator approved a filtering change and a downstream detection quietly broke, that operator would own the failure. So Realm did not ask the team to take filtering on faith.

Parity, Proven

The team handed Realm rules from their CrowdStrike rule set and asked it to prove parity. Realm validated each reduction against those detections before anything changed.

Fields Protected

Realm protected the exact fields each detection depends on, so cutting high-volume noise could not silently strip the data a rule needs to fire.

Reasoning Visible, Call Left to the Team

Realm produced a report showing what was cut and what stayed covered. Not a black box telling the team to trust it, but a method to manage the risk, with the decision theirs.

48 Hours to Confirmed Savings

The prior year’s 40-hour manual effort produced modest savings and no way to show coverage held. With Realm, the proof of concept went from start to confirmed savings in 2 days.

86% Less High-Volume Log Data, Zero Detection Gaps

Realm filtered high-volume noise before ingestion into Sentinel and validated every reduction against the team’s own detection rules, cutting Fortinet and Zscaler log volume 86% while proving, on their data, that coverage held. Data Haven solved the three-year retention requirement, and shaved roughly a third off of Azure Sentinel data storage costs.

By the numbers

Measure Before Realm After Realm Result
Fortinet + Zscaler log volume Full ingest Filtered at source 86%
Detections validated against reduction None Every rule in scope 0 gaps
3‑year historical data retention Stored in Sentinel Retained in Data Haven 1/3 the cost

Built to keep paying off

Filtering before ingestion did more than lower a bill. With less routine noise reaching Sentinel, analysts spent their time on signal instead of high-noise volume. And because the reduction is validated against live detections rather than configured once and forgotten, the coverage check the team had been going without is there to run again whenever rules change.

Months after deployment, the firm is extending the same approach to additional log sources, treating the first rollout as the template for the rest of its estate. Each new source follows the same sequence: filter before ingestion, validate cuts against live detections, and confirm coverage before the change goes live.

Pick one source.
We'll prove it on your data in days.

The 7-Day Data Assessment. You pick a source, usually firewall logs. We do everything else, and deliver your reduction, detection integrity, and ROI on your own data in a week.

Start a 7-Day Data Assessment