SECURITY OPERATIONS | SIEM
12 min read

Cut SIEM Ingestion Costs 60% Without Creating Detection Blind Spots: A Log Rationalization Methodology

Sources:Alert Fatigue Is Becoming a Security Threat of Its Own - SecurityWeek|Splunk Cloud Ingestion Cost Reduction Best Practices|SANS SOC Survey 2025
960 alerts/day
average daily alert volume for SOC teams — 40% are never investigated due to volume
29 products
average number of security monitoring tools used by enterprise organizations — most generating logs sent to a SIEM
500+ alerts/day
reported by some practitioners for public cloud environments alone, before other log sources are added
60-80%
typical SIEM volume that can be eliminated by pre-filtering high-volume, low-signal log sources without losing meaningful detection coverage

SponsoredRetool

Retool's new app builder is where AI-generated code ships safely

Building apps with AI is easy. Getting them to production safely is another story.

Start building for free today

SIEM costs scale with data volume. Security telemetry scales with infrastructure. The math eventually breaks: a 50-person company with 300 cloud workloads, endpoint agents on every machine, and network flow logging enabled generates more data than its security budget can support at full SIEM indexing costs.

The standard response — cutting log sources without a framework — creates detection blind spots. The principled response — tiering log sources by detection value — reduces costs 40 to 60 percent while maintaining coverage for the attack scenarios that matter.

This guide provides the tiering framework and the specific log source decisions across common categories.

The tiering model: three buckets for every log source

Every log source in your environment falls into one of three tiers based on its detection value density — the ratio of security-relevant events to total events generated.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Category-by-category tiering decisions

The following decisions apply to the most common log source categories. Your environment may have additional context that shifts specific sources between tiers.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Pre-SIEM filtering architecture

The tiering decisions above require a filtering layer between your log sources and your SIEM. Without this layer, you pay ingestion costs for everything before you have the opportunity to filter.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The bottom line

The SIEM cost reduction decision is ultimately a detection coverage prioritization exercise. Every log source you cut should be cut because you have made a conscious decision that the detection scenarios it supports are either covered by other sources or acceptable to lose visibility on — not because you ran out of budget and started deleting things. The tiering framework above provides the structure for making those decisions explicitly and documenting them in a way that is defensible to auditors and incident debrief reviewers.

Frequently asked questions

Which SIEM events are absolutely required for detection and cannot be cut?

The non-negotiable list: authentication events (success and failure) from all identity systems, process creation and network connection events from endpoint agents (EDR telemetry), cloud management plane audit logs (CloudTrail management events, Azure Activity Log), and all security tool alerts (EDR detections, WAF blocks, IPS alerts). These sources cover the attack stages — initial access, execution, lateral movement, privilege escalation — that define the majority of detection use cases. Cutting any of them creates detection blind spots for common attack patterns.

Can sampling break detection rules that depend on complete log data?

Yes — detection rules that look for individual events (a specific login, a specific file creation) break with sampling. Detection rules that look for statistical patterns (anomalous volume, frequency above baseline) work well with sampling. Before enabling sampling on a log source, audit which active detection rules depend on it and verify they function correctly with the sampling rate you plan to apply. Alert-based detection rules and threshold-based anomaly rules respond differently to incomplete log data.

What is the difference between hot, warm, and cold SIEM storage tiers?

Hot storage is indexed and searchable in real time — queries return results in seconds. It is the most expensive tier. Warm storage is indexed but on slower media — queries may take minutes. Cold storage is compressed and not indexed — retrieval requires decompression and may take hours. Most compliance use cases require retention but not necessarily fast retrieval, making cold storage appropriate for logs that must be kept but are rarely queried.

How do I measure the detection coverage impact of removing a log source?

Map the log source to the ATT&CK techniques its events detect before removing it. For each technique covered by the source, determine whether another source in your environment also provides coverage for that technique. If the log source is the only coverage for a technique that is relevant to your threat model, do not remove it — reduce its volume through filtering instead. SIEM vendors and the MITRE ATT&CK data source mapping documentation provide technique-to-data-source mapping for common log types.

Sources & references

  1. Alert Fatigue Is Becoming a Security Threat of Its Own - SecurityWeek
  2. Splunk Cloud Ingestion Cost Reduction Best Practices
  3. SANS SOC Survey 2025

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Black Hat Giveaway

Win a $2,495 Black Hat pass.

Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.

Joins Decryption Digest daily briefing. Unsubscribe anytime.

Giveaway: Black Hat USA 2026 Full-Access Pass ($2,495 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $2,495 Black Hat USA 2026 pass.