Executive Summary
Joint guidance from ASD's ACSC and CISA suggests that feeding a SIEM increasing amounts of log data is common practice to improve platform visibility, which concurrently increases cost. This tension highlights a key divergence between legacy and next-generation SIEMs regarding how they manage the ingestion of data. The decision involves balancing increased visibility against operational costs.
Modern SIEMs differ from legacy systems in that they aim to shift the operational burden onto the platform through automated detection and vendor-maintained rules, contrasting with legacy models where detection content largely rests with the user. A self-hosted model requires in-house capacity planning for collectors and storage, whereas a cloud-native approach removes these infrastructure burdens. Furthermore, data handling must account for time to detect threats, retention periods, and correlation across disparate data sources like identity, network, and endpoint logs. The cost structure shifts based on how services are packaged, moving from simple visibility/retention tiers to tiered models incorporating detection, investigation, and response capabilities.
Facts Only
* Personnel feed SIEMs increasing amounts of log data over time to improve platform visibility.
* Most SIEM pricing is based on ingested data volume.
* Ingesting more data raises the bill.
* Exploited vulnerabilities passed stolen credentials as the top entry point for a breach in Verizon's 2026 Data Breach Investigations Report, accounting for 31% of breaches.
* Catching this type of entry requires logs from multiple sources.
* A self-hosted SIEM requires the team to manage collectors, indexers, storage, capacity planning, and upgrades.
* Next-gen platforms ship detection content and pair rules with behavioral analytics.
* Ingesting too many logs can lead to false positive alerts and strain platform processing capacity.
* Retention periods must accommodate the mean time to detect threats, which can take up to 18 months.
* Correlation requires standardizing log fields like "srcip" across sources for effective analysis.
* Organizations should conduct exercises to test SIEM performance and incident response paths.
Full Take
The narrative positions the evolution of SIEMs not just as a technological shift but as a fundamental tension between operational necessity, cost structure, and accountability. The core conflict arises because increasing visibility—a security best practice—is directly penalized by an ingest-based pricing model, forcing an adverse relationship between security goals and budgetary reality. The pattern of accumulating unaddressed debt—where small decisions like suppression rules or log prioritization compound into a larger, auditable detection posture—suggests that the primary risk is not technical failure but organizational inertia enabled by complexity.
The shift from legacy to next-gen systems reflects a transition from a labor-intensive, manual ownership model to an automated service model. This move implies that true scalability for an MSP requires decoupling cost from client volume via multi-tenant architectures, where the operational burden of maintaining detection content and ensuring tenant isolation is absorbed by the platform. The implication is that for practitioners, the future lies in outsourcing the tedious, high-stress work of continuous tuning and response to a platform designed to handle it, rather than treating the SIEM merely as a data repository.
The challenge for human agency lies in navigating this transition without allowing implementation details to obscure the underlying security mandates. If organizations focus only on the immediate technical features—like ingestion volume or specific rules—they risk overlooking the systemic governance required to manage detection content, retention policies, and liability across a portfolio of clients. The question is whether the structure of the new service layer truly shifts responsibility or merely relocates it, and if financial incentives align with security outcomes, or if they perpetuate the legacy dynamic where visibility perpetually pulls against budget constraints.
Bridge Questions: How can organizations ensure that the cost-efficiency of a modern SIEM does not inadvertently permit the neglect of critical data sources? What governance mechanisms are necessary to prevent detection content drift across a multi-tenant environment, and how do risk assessments account for the latency introduced during platform migration? What is the long-term cost associated with deferring the full transition from ownership to service models?
From the original · Todyl Threat Research
Joint guidance from ASD's ACSC and CISA makes a plain observation: "it is common for personnel to feed a SIEM increasing amounts of log data over time to improve the platform's visibility." That is good practice.Read the full story at todyl.com
Sentinel — Human
This analysis synthesizes complex industry guidance into a cohesive argument about the economic and operational trade-offs in SIEM architecture, exhibiting high coherence indicative of human analytical writing.
