TL;DR: Rising telemetry volumes and ingestion-based SIEM pricing are pushing organisations toward decoupled architectures that separate compute from storage, according to Anomali’s analysis and cited Software Analyst Cyber Research findings. Predictable visibility only matters if teams can retain searchable data, control access, and preserve governance without turning monitoring into an open-ended cost problem.
At a glance
What this is: This is an Anomali analysis of SIEM economics arguing that ingest-based pricing, long retention demands, and growing telemetry volumes are making decoupled data-lake architectures more attractive.
Why it matters: It matters because SOC, IAM, and GRC teams still need long-term searchable evidence, but storage economics and access governance now shape whether that visibility is sustainable.
By the numbers:
- Organizations can see an average 40 to 60% cost reduction while gaining full visibility across years of data.
- Pricing is positioned as 40 to 60% lower than comparable SIEMs, and because all data remains hot for seven plus years, customers avoid surprise retention costs.
👉 Read Anomali's analysis of SIEM ingest economics and decoupled visibility
Context
SIEM economics are no longer just a procurement issue. When telemetry volumes grow, retention requirements stretch into years, and ingest pricing scales with every new source, visibility itself becomes the budget constraint. That creates a governance problem for security teams that still need searchable evidence for investigations, compliance, and escalation. The primary issue is not whether organisations should collect data, but how they can retain it without making monitoring financially unsustainable.
The identity angle is indirect but real. SIEM platforms increasingly hold logs that include account activity, privileged actions, service account behaviour, and authentication traces, which makes access control, retention policy, and auditability part of the security model. For practitioners managing IAM, PAM, and NHI governance, the architectural question is whether visibility platforms preserve enough control over the data that supports incident response and access review.
Key questions
Q: How should security teams reduce SIEM costs without creating blind spots?
A: Security teams should move from ingest-everything thinking to governed data routing. Preserve full-fidelity logs for identity, access, and high-risk events, enrich and normalize data before it reaches the SIEM, and keep raw evidence in cheaper storage for audit and replay. The goal is to reduce noise and cost without losing investigative depth.
Q: Why do long-retention log platforms matter for IAM and NHI governance?
A: Because authentication, privileged access, and non-human identity activity are often only understood in context over time. Without long retention, teams lose the ability to reconstruct access paths, confirm unusual service account behaviour, or support audits. Long retention only helps, though, if access to the data is tightly controlled and the evidence remains searchable.
Q: What breaks when SIEM access controls are too broad?
A: Broad access turns the monitoring platform into a repository of sensitive operational evidence that too many people can query. That increases internal exposure, weakens audit discipline, and can leak identity-related traces such as tokens, service account usage, or privileged actions. SIEM governance has to cover the data itself, not just the logs being collected.
Q: Who should own decisions about SIEM retention and data access?
A: Ownership should sit jointly across security operations, IAM or PAM stakeholders, and governance leaders. SOC teams need the data for detection and investigation, while identity and governance teams should define who can view sensitive authentication and privilege logs. Shared ownership prevents retention decisions from becoming purely financial or purely technical.
Technical breakdown
Why ingest-based SIEM pricing breaks at scale
Ingest-based SIEM models charge for the volume of data written into the platform, so telemetry growth directly increases operating cost. That creates a structural mismatch between modern environments, which generate more logs, and security teams, which need broader visibility for detection and forensics. The problem is amplified when long retention periods are required, because organisations pay repeatedly for data that may only be queried occasionally. Decoupling ingestion from storage changes the economics, but it does not remove the need for sound data classification and retention design.
Practical implication: measure how much of your SIEM spend is driven by high-volume but low-value sources before expanding collection.
How decoupled storage and compute changes visibility
A decoupled SIEM architecture separates the layer that stores data from the layer that queries and analyses it. In practice, that means organisations can preserve years of searchable telemetry without forcing all workloads through a single costly processing path. Open data lake formats also reduce dependence on one storage model and can simplify scaling across clouds or business units. The technical tradeoff is that teams must manage governance, indexing, and performance more deliberately, because flexible storage only helps if data remains usable for investigation and response.
Practical implication: validate whether your architecture preserves query performance, retention controls, and access governance across the full data life cycle.
Why long-term retention is an evidence problem, not just a storage problem
Security teams often treat retention as an archival requirement, but in practice it is an evidence-management function. Long-lived log data supports compliance, incident reconstruction, insider threat analysis, and investigations into privileged or non-human identity behaviour. If retention is too expensive, teams truncate history and weaken detection context. If retention exists but is not governed, the organisation expands the blast radius of sensitive operational data. The right model balances searchable history, ownership, and control over who can access high-value logs.
Practical implication: align retention policy with investigation needs, especially for logs containing authentication, privilege, and NHI activity.
NHI Mgmt Group analysis
Visibility has become a governance cost, not just a technical capability. When SIEM spend rises with ingest volume, organisations begin rationing the very telemetry they depend on for compliance and detection. That creates a hidden risk: teams optimise for cost before they have proved what data is actually needed for investigations, access review, and privileged activity monitoring. Practitioners should treat visibility architecture as a governance decision, not a tooling preference.
Data-lake SIEM models shift the control problem from collection to stewardship. Decoupling storage and compute can improve cost predictability, but it also moves responsibility toward retention logic, access policy, and evidence integrity. For identity programmes, that matters because authentication logs, service account traces, and administrative activity often live inside the same data layer. Visibility stewardship: the new failure mode is not missing logs alone, but retaining them without enforceable ownership and review. Practitioners should evaluate whether the architecture supports durable auditability.
NHI and privileged identity telemetry are especially sensitive in a long-retention model. Logs that capture API keys, tokens, service account behaviour, and privileged actions can expose both attack paths and operational context. If organisations do not separate investigative access from general analyst access, long-term visibility can increase internal exposure even as it improves detection. The challenge is to keep years of searchable context without turning the telemetry store into an over-broad repository of identity evidence. Practitioners should tighten access boundaries around SIEM data itself.
This market shift validates a broader security trend toward cost-aware control design. Security platforms increasingly need to prove that they improve outcomes without creating uncontrolled operating expense. That is particularly relevant in regulated environments where visibility is mandatory but budget is finite. The signal for practitioners is that architecture choices now need to satisfy both security and finance, and any SIEM strategy that ignores one of those constraints will struggle to scale.
What this signals
SIEM architecture decisions are increasingly converging with identity governance because the logs that matter most often describe privileged, service, and non-human identity activity. That means teams should evaluate visibility platforms not only for search speed and retention cost, but also for whether they preserve access boundaries around sensitive identity evidence. The next control gap is likely to be data stewardship, not data collection.
Visibility stewardship: organisations will need clearer ownership of who can access long-retention security data, how that access is reviewed, and how evidence is exported during investigations. The operational question is whether the platform supports both detection and governance without creating a secondary sensitive-data problem.
Practitioners should expect budget pressure to keep pushing SIEM programmes toward architectures that separate storage from compute, but cost predictability is only useful if it preserves investigative utility. The most resilient programmes will align SIEM retention with IAM, PAM, and NHI audit needs rather than treating log storage as a generic infrastructure expense.
For practitioners
- Assess telemetry value before expanding ingest Classify log sources by investigative value, compliance necessity, and volume, then identify sources that drive cost without materially improving detection or auditability. Use that review to reduce low-value ingestion before adding new pipelines.
- Separate retention policy from hot-search design Define which data must stay queryable for active hunting and which can move to lower-cost retained storage, while preserving chain of custody and audit access. Tie retention periods to actual investigation needs rather than blanket retention defaults.
- Restrict access to identity-rich log data Limit who can query logs containing authentication events, privileged actions, and non-human identity traces, and review that access alongside broader IAM and PAM controls. Treat SIEM data as sensitive evidence rather than routine operational telemetry.
- Validate evidence usability across the full retention window Test whether older data can still be searched, correlated, and exported at the point where investigators would actually need it. If retrieval is slow, incomplete, or expensive, the retention model is failing its security purpose.
Key takeaways
- Ingest-driven SIEM pricing creates a governance problem because teams may under-collect the telemetry they need for detection, audit, and investigation.
- Decoupled storage and compute can reduce cost pressure, but only if retention, access control, and searchability remain usable over time.
- Identity-rich logs deserve the same access discipline as other sensitive evidence, especially where privileged and non-human activity is recorded.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Identity-rich log access needs least-privilege governance under the Protect function. |
| NIST SP 800-53 Rev 5 | AU-2 | This article centres on log collection, retention, and evidence usability. |
| ISO/IEC 27001:2022 | A.5.33 | The article treats retained logs as evidence that must remain governed and usable. |
Define audit-event scope in AU-2 so log collection stays tied to investigation and compliance needs.
Key terms
- SIEM ingest pricing: A pricing model that charges organisations for the volume of data sent into a security information and event management platform. It can make visibility expensive at scale because every additional log source increases cost, even when the data only exists to support compliance or rare investigations.
- Decoupled storage and compute: An architecture that separates where security data is stored from where it is analysed. This lets teams retain large volumes of telemetry more economically while scaling search and detection functions independently, but it also demands stronger governance over retention, access, and evidence usability.
- Visibility stewardship: The practice of treating security telemetry as governed evidence rather than undifferentiated operational data. It includes deciding what to retain, who may access it, how long it remains searchable, and how the organisation proves that the retained data is still useful for investigation and audit.
- Identity-rich logs: Log data that contains authentication, access, privilege, or non-human identity activity. These records are valuable for investigations because they show who or what performed an action, but they are also sensitive because they can expose tokens, administrative behaviour, and access paths if over-shared.
What's in the full article
Anomali's full post covers the operational detail this post intentionally leaves for the source:
- Cost and storage architecture discussion tied to decoupled compute and hot data retention
- How the vendor positions open data lake formats for long-term searchable telemetry
- The cited Software Analyst Cyber Research commentary on ingestion pricing and buyer behaviour
- The specific way Anomali frames continuous visibility for SOC and MSSP operating models
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to the operational realities that shape security programmes.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org