← Operational tools
UTIOM · Threat Visibility

Log volume & cost model

EPS in, GB/day and euros out. Sizes ingest, storage, bandwidth and cost across on-prem, cloud-native and hybrid collection. Vendor-neutral — you set the rates.

Sources

Every value is editable
Source typeOrigin UnitsEPS / unit Bytes / eventGB / day

Pipeline

What you drop before it lands
Dropped or trimmed in transit. Typical 20–60%.
Remainder lands in archive or a lake.
Burst over average. Sizes links, not cost.

Destination

Where it lands, for how long
Collectors on site, SIEM in cloud. Bandwidth, buffering and egress all apply.
Indexed size vs raw.
Compressed, no index.
Local disk to survive a WAN break.
Sustained, per forwarder.

Prices

EUR
Convert credit or SVC pricing to an effective rate first.
Zero if bundled into ingest.
Only on cloud-origin logs leaving that cloud. Sending on-prem logs up is free.
Raw at source—
Hot SIEMArchiveDropped
Average EPS
—
Peak EPS
—
Ingested
— GB/day
Run rate
—/yr
Capacity & transport
Hot tier at full retention—
Archive at full retention—
Uplink, peak—
Collector buffer disk—
Collectors at peak—
Monthly cost
Hot ingest—
Hot retention—
Archive storage—
Cloud egress—
Total per month—
If you dropped nothing—
Saved by filtering—
Planning figures, not a quote. Bytes per event decides everything downstream and swings by an order of magnitude between estates. Sample seven days of real traffic per source type before you sign anything.
Ingested
—
Run rate
—

This calculator runs entirely in your browser. Nothing you enter is sent anywhere, stored, or logged. Figures are indicative and depend on your own contracts, compression ratios and retention obligations — treat them as a starting point for a conversation with your provider, not a quotation.