7 providers that publish a price at all · By location

Compare IT support prices

Managed SIEM: what a managed SIEM service collects, who reads the alerts, and what separates it from a tool with a dashboard

A SIEM collects logs from across an estate and raises alerts when patterns in them look wrong. Bought as software, it is a licence, a storage bill and a stream of alerts that nobody has time to read. Bought as a managed service, it is supposed to include the people who read them. That distinction is the whole purchase, and it is the one thing a vendor page is least likely to be specific about.

The question that separates the offers

Ask who looks at an alert at three in the morning, and what they are allowed to do about it. The honest answers range widely: a rota of analysts who investigate and then telephone you; a rota who investigate and can isolate a machine themselves; software that emails you and waits. All three get sold as managed detection. The middle one is what most buyers think they are getting and the third is what they often have.

Coverage is decided by what is actually plugged in

A SIEM sees only what sends it logs. Endpoints, servers, firewall, identity provider, mail platform and cloud services each need connecting, and each connection is work. A service priced attractively and connected to three of those six is cheaper because it is smaller. Get the list of sources in the contract, not in the proposal, and ask what happens when you add a system next year.

Retention is the line item that grows

Log storage is charged by volume and duration, and the volume rises every time somebody turns on more logging. A regime that requires twelve months of retention costs materially more than one satisfied with ninety days. Ask how retention is priced, what the assumed volume is, and what happens when you exceed it, because that is the clause that turns a predictable monthly fee into a variable one.

Where it sits against the rest of the contract

For most businesses under a few hundred staff, a managed SIEM is bought on top of a managed IT contract rather than instead of anything in it. The support provider keeps the estate running and patched; the SIEM service watches for the thing that gets in anyway. Buying the second while the first is neglected is the wrong order, because most incidents in small businesses start with something unpatched rather than something exotic.

Questions people ask about managed siem

What is a managed SIEM?

A service that collects logs from across an estate, alerts on suspicious patterns, and includes people to investigate those alerts. Without the people it is a log platform, not a service.

How is managed SIEM priced?

Usually on log volume and retention period, sometimes per device or per user on top. None of the providers read for this record publishes a rate for it.

Do I need SIEM if I already have endpoint protection?

They answer different questions. Endpoint protection tries to stop something running on a machine; a SIEM notices a pattern across several systems that no single machine can see. Most small businesses should get patching and endpoint protection right first.

Sources

Related answers

Get IT support quotesSee what providers publish