You are paying to index
data nobody will read.
Every major SIEM is licensed by volume ingested, which puts security visibility in direct conflict with the budget. The usual responses are to drop log sources, to shorten retention, or to buy a pipeline tool that trims the stream before it arrives.
Every one of those trades coverage for budget, because each asks somebody to decide in advance, without evidence, which telemetry is worth keeping.
There is a fourth option, and it is what this page is about. Do not decide in advance which events are valuable. Evaluate all of them, determine which structural changes are significant, route those to the SIEM, and retain everything else at full fidelity somewhere that costs almost nothing. Nothing is discarded, so no coverage is lost.
Why the bill scales with the wrong thing
Per-gigabyte licensing prices your telemetry by its size rather than its usefulness. A gigabyte of DNS logs nobody will ever query costs the same as a gigabyte of authentication events that matter, so the cost of visibility rises with every source you onboard whether or not that source ever contributes to an investigation.
The predictable consequence is that security teams make coverage decisions on price. Log sources get excluded, verbose sources get sampled, retention gets cut to the compliance minimum. Every one of those is a deliberate blind spot created by a pricing model rather than by a risk assessment.
The uncomfortable part is that most of it is genuinely never read. Not because it is worthless, but because nobody knows in advance which fraction will matter, so everything is indexed on the chance that some of it will.
The structural state decides what your SIEM sees.
SIET evaluates every event and folds it into the baselines. Events implicated in a structural departure, a newly appeared attribute or an active case go to the hot index. Everything else goes to cold storage at full fidelity.
This is not sampling. What skips the index is what the system has already understood and found unremarkable, so fidelity rises while indexed volume falls. Retention is unchanged: 100% of raw logs are still written, and can be replayed for a compliance audit.
Hot index
- Events implicated in a structural departure
- Newly appeared attributes with no prior history
- Events belonging to an active case walk
- Cases themselves, alerted on unconditionally
Archive
- 100% of raw logs at full fidelity
- Per-window summary metrics
- Glacier-class object storage, not a SIEM tier
- Replayable on demand for audit
This is the part that changes the bill
A pipeline tool trims your stream and sends what is left into the SIEM, where it is charged per gigabyte like everything else. You have made the expensive thing smaller. SIET does something different: what does not need indexing does not go to the SIEM at all. It goes to archive-class object storage.
A year of 1 TB/day is roughly 365 TB. Held in deep archive that costs on the order of £1,750 a year. Indexed in a SIEM at list price it is closer to £886,000. Same data, same retention, same fidelity. The only difference is which tier it lands in, and that decision is what SIET-Enterprise makes for you, event by event.
The obvious question: what if an analyst needs it?
They do not, and that is the whole point rather than a convenient answer. Every event was evaluated on the way through. What went to archive is what SIET read and found unremarkable, and anything implicated in a departure is in the hot index by definition, because being implicated is what put it there.
So an investigation works entirely from the indexed data. The archive is for compliance, audit and replay: planned work, on a timetable, where retrieval taking hours costs nothing. If you ever do want to search the archive directly, it is full-fidelity raw logs, so it can be replayed through the detector or loaded back into the SIEM. That is a decision you make deliberately, not something an incident forces on you at 3am.
What that does to the total
Telemetry pipeline tools cut your SIEM bill by dropping and trimming events on rules somebody writes. They work, and they are worth having. But whatever survives the rules still lands in the SIEM and is still charged per gigabyte, and how much survives depends on how much your team is willing to throw away unseen. In practice that lands somewhere around half.
So you buy a second product, and you still pay for the first one. Halving a £886,000 bill leaves £443,000, and the pipeline licence is on top of that.
SIET is not deciding what to throw away. It is deciding what needs to be searchable, and sending everything else somewhere that costs almost nothing. Below: 1 TB/day, twelve months retention, published per-GB list pricing. What matters is the last column, which is what you still owe your SIEM vendor at the end of the year.
| Approach | SIEM index | Storage and licence | Annual total |
|---|---|---|---|
| Everything indexed, as today | £886,000 | – | £886,000 |
| Add a telemetry pipelinerules discard half; the other half is still indexed per GB, and you now pay for the pipeline too | £443,000 | £77,000 | £520,000 |
| SIET-Enterprise0.6% indexed because that is what was implicated; everything else to deep archive, in full, nothing discarded | £5,300 | £1,750 | £7,100 |
The pipeline saves you £366,000. SIET saves you £879,000. The difference is not that SIET discards more aggressively, it is that SIET does not discard at all: every event is kept in full, and the decision being made is which tier it belongs in rather than whether you can afford to lose it. The 0.6% is the measured figure from the benign control day of the benchmark. Our fee is not in this table, and it is a share of what you save, so you can see the size of the thing being shared.
Measured forwarding rate, by day
Forwarding scales with how much is actually happening. A quiet estate forwards under 1%. A day containing a live DDoS forwards most of it, which is correct behaviour, because that traffic is the incident.
| Replay | Forwarded to SIEM | Avoided indexing |
|---|---|---|
| Benign control | 0.6% | 99.4% |
| Web attacks | 1.6% | 98.4% |
| Botnet C2 | 6.7% | 93.3% |
| Brute force | 9.9% | 90.1% |
| Infiltration | 30.7% | 69.3% |
| DoS | 41.6% | 58.4% |
| Port scan | 57.9% | 42.1% |
| DDoS | 71.6% | 28.4% |
| Full test week | 27.1% | 72.9% |
The week-wide figure is the floor, not the expectation. Seven of the eight replay segments in CICIDS2017 carry attack traffic by construction, and in two of them more than half of all flows are the attack. No production estate looks like that, which is why the benign control day is the closer analogue to a normal week on a real network.
Find your own volume.
The comparison above uses 1 TB/day as a worked example. This is the same arithmetic across a range of ingest volumes, so you can read off the row nearest your own rather than scaling ours. Measured forwarding rates applied at £1.98 per GB per day.
The low column uses the full test week, where nearly every segment carries a live attack. The high column uses the benign control day. A real estate sits nearer the high column, because a real estate is not under continuous attack.
| Raw ingest | Annual index spend | Saving, week-wide rate | Saving, benign rate |
|---|---|---|---|
| 250 GB/day | £185,000 | £135,000 | £183,000 |
| 500 GB/day | £369,000 | £269,000 | £367,000 |
| 1 TB/day | £738,000 | £538,000 | £734,000 |
| 2 TB/day | £1,476,000 | £1,076,000 | £1,467,000 |
| 5 TB/day | £3,691,000 | £2,691,000 | £3,669,000 |
How to read this table
- What is measured, and what is arithmetic. The forwarding rates come from the CICIDS2017 replay. The pounds are those rates applied to published per-GB list pricing, so substitute your own rate and volume and the shape of the answer holds.
- Cold storage is a real line item. Object storage for the full raw stream costs a fraction of hot indexing, and it is not netted off above. Retention itself does not change.
- The saving arrives as a curve. During warm-up everything is indexed and you pay your usual bill. The saving grows as the forwarded share falls, and you can watch it happen.
- We would rather measure it on your data. Run SIET alongside existing alerting, switch nothing off, and compare indexed volume after a month. If the reduction is not there, you will know before you have committed to anything.
What deployment looks like
How long until it is useful
Detection of novel structure works from day one. A machine doing something it has never done needs no baseline, only the absence of one. What takes time is the estate going quiet enough that a detection stands out.
We run in learning mode, watch the novelty curve, and switch to alerting when it flattens, typically after the first full business cycle. For planning purposes, two to four weeks. We will show you the curve as it develops rather than promise you a date.
You are never worse off while it learns
During warm-up you keep your full existing ruleset, so you have the same visibility you have today. Nothing is switched off. As SIET learns the estate it forwards less, the rules see less to fire on, and SIET takes over progressively.
If the estate is already compromised when SIET is switched on, that compromise is learned as normal. A beacon present through warm-up becomes part of the baseline. The moment the attacker does something new, it is a departure from a baseline that includes their own presence.
Measure it on your own data.
Every figure above comes from a public benchmark. The number that matters is yours: run SIET alongside your existing alerting, switch nothing off, and compare indexed volume after a month.