A UK enterprise SOC weighing Splunk, Elastic Security and Rapid7 InsightIDR is not comparing three prices for the same thing. Splunk and Elastic charge for the data you feed in; Rapid7 charges mainly for the assets you monitor, within a monthly data cap. Elastic publishes its per-GB rate directly; Rapid7 publishes 12-month reference prices through a marketplace listing; Splunk publishes no price at all. Before you shortlist, work out which meter fits your log volume, then get a written quote in the currency and period you actually plan to buy.
Key pointers
- Splunk publishes no public per-GB or per-SVC price anywhere on its site; only the Ingest, Workload and activity-based pricing mechanics are public, not a rate card.
- Elastic Security Serverless is the only one of the three with a published, dated per-GB rate: from $0.09/GB ingested on the Essentials tier.
- Rapid7 InsightIDR bills primarily per monitored asset, but each published tier also carries a monthly data cap (0.5TB to 0.8TB), so volume is not entirely irrelevant.
- A noisy log source (firewalls, DNS, cloud audit trails) inflates Splunk and Elastic bills directly, and can push Rapid7 past its tier's monthly data cap even though assets, not gigabytes, set the base price.
- Splunk's ingest-priced Cloud subscription bundles roughly 90 days of storage; Elastic bills retention separately, every month, on top of ingest.
- Ask every shortlisted vendor to quote the same ingest volume and retention period, in writing, before you compare totals.
- Licence cost is reported to be well under half of total SIEM spend once staffing, storage, tuning and integration are added.
- None of the three publishes a GBP price list; get a written sterling quote through a UK reseller or cloud marketplace listing before budgeting.

What this decision means for a UK SOC
For a SOC manager, the platform choice sets two things at once: how much of the security budget scales with log volume, and how much of the operational load falls on your own analysts versus the vendor. Splunk and Elastic both bill primarily on data ingested, so a decision to onboard a new firewall, proxy or cloud audit-log source is also a pricing decision. Rapid7 InsightIDR bills on monitored assets instead, so ingesting more log detail from an existing asset does not move the licence cost, but adding servers, endpoints or cloud accounts does.
None of the three publishes a UK price list, and Splunk publishes no price at all. Splunk's pricing FAQ sets out the mechanics of Ingest, Workload and activity-based pricing but states no dollar figure for any of them. Rapid7 is more transparent than Splunk but not fully: its marketplace listing (detailed below) publishes three 12-month reference prices, each covering up to 500 monitored assets, which is a real number but not necessarily your number if your estate is larger or smaller. Elastic is the clearest of the three: its Serverless Security pricing page states an actual per-GB ingest rate and a per-GB retention rate, dated to take effect from 1 November 2025. That transparency gap matters for procurement: you can model Elastic's licence cost from the public page alone, and get close with Rapid7's published reference tiers, but Splunk needs a live quote before you can put a number in a business case.
Small and mid-sized UK organisations considering the same three platforms face a sharper version of this problem, because low log volumes do not always mean a low bill. A per-asset model like Rapid7's can suit a business with few servers but heavy logging needs; a per-GB model like Elastic's or Splunk's can suit a business with light logging but many devices. Model both against your actual log mix rather than against headcount alone.
How each platform prices ingestion
| Platform | Pricing metric | Reported or published rate | Source |
|---|---|---|---|
| Splunk Cloud Platform, Ingest model | GB indexed per day (annual subscription includes ~90 days storage) | Mechanics published; unit price not published, quote required | Splunk pricing FAQ (vendor) |
| Splunk Cloud Platform, Workload model | Splunk Virtual Compute (SVC) units, driven by search activity and ingest | Mechanics published; unit price not published, quote required | Splunk pricing FAQ (vendor) |
| Splunk Cloud Platform, activity-based model | Dual meter on ingest and search activity | Mechanics published; unit price not published, quote required | Splunk pricing page (vendor) |
| Elastic Security Serverless, Essentials tier | Per GB ingested, plus per GB retained per month | As low as $0.09/GB ingest, $0.017/GB/month retention | Elastic Serverless Security pricing (vendor), effective 1 November 2025 |
| Elastic Security Serverless, Complete tier | Per GB ingested, plus per GB retained per month | As low as $0.11/GB ingest, $0.019/GB/month retention | Elastic Serverless Security pricing (vendor), effective 1 November 2025 |
| Rapid7 InsightIDR Essential | Per monitored asset, 12-month term, up to 500 assets, 0.5TB/month data cap | $21,479 for the 12-month term (up to 500 assets) | AWS Marketplace listing (vendor) |
| Rapid7 InsightIDR Advanced | Per monitored asset, 12-month term, up to 500 assets, 0.6TB/month data cap | $33,682 for the 12-month term (up to 500 assets) | AWS Marketplace listing (vendor) |
| Rapid7 IDR Ultimate | Per monitored asset, 12-month term, up to 500 assets, 0.8TB/month data cap, includes ENTA and unlimited automation | $46,149 for the 12-month term (up to 500 assets) | AWS Marketplace listing (vendor) |
Worked example, Elastic only (the one platform with a published rate). A SOC sustaining 50 GB/day of ingest for a year sends 50 x 365 = 18,250 GB. On Security Analytics Essentials at $0.09/GB, ingest alone costs 18,250 x $0.09 = $1,642.50 for the year. On Complete at $0.11/GB, the same volume costs 18,250 x $0.11 = $2,007.50. Retention is billed separately, per GB stored per month, so a business retaining data for longer than the month it lands adds a second recurring line on top of these figures. This is an ingest-only estimate from Elastic's own published rate; it excludes retention, the AI SOC Engine add-on, egress above the free 50 GB, and any negotiated discount.
Splunk's ingest model works the same way in principle: a daily volume multiplied by a per-GB rate, with Enterprise Security, the module most genuine SOC deployments need, licensed separately on top. Because Splunk states no figure for either the per-GB rate or the SVC unit price, CTC could not independently verify third-party estimates of Splunk's ingest cost, including the range published by CIPHER's SIEM cost breakdown. Treat any reported Splunk number you encounter while shortlisting as an unconfirmed planning band rather than a quote, and get Splunk's own current rate for your actual ingest volume before budgeting against it.
Rapid7 works differently again. Its AWS Marketplace listing publishes a 12-month reference price for up to 500 monitored assets at each tier: $21,479 for Essential (0.5TB/month data cap), $33,682 for Advanced (0.6TB/month) and $46,149 for Ultimate (0.8TB/month, with ENTA and unlimited automation bundled in). Dividing the Essential figure across its bundled 500 assets and 12 months gives $21,479 / 500 / 12 = $3.58 per asset per month, at that reference volume; the same calculation on Ultimate gives $46,149 / 500 / 12 = $7.69 per asset per month. Because the meter is assets rather than gigabytes, adding log detail from an asset you already monitor does not move this bill, but each tier still caps the data it will accept per month, so a very noisy estate can force an upgrade regardless of asset count.
Splunk, Elastic Security and Rapid7 InsightIDR compared
| Criterion | Splunk Cloud Platform / Enterprise Security | Elastic Security (Serverless, Hosted or self-managed) | Rapid7 InsightIDR |
|---|---|---|---|
| Pricing basis | Ingest (GB/day), Workload (SVC/vCPU) or activity-based (ingest plus search activity); quote required | Ingest and retention per GB (Serverless), or resource/node-based (Hosted/self-managed) | Per monitored asset with a monthly data cap; published 12-month reference rate for up to 500 assets, per tier |
| Deployment options | Splunk Cloud (SaaS) or Splunk Enterprise (on-prem, term licence) | Serverless (fully managed), Hosted (Elastic-managed infrastructure) or self-managed (customer-run) | Cloud SaaS only, with an on-premises or dedicated Collector forwarding logs |
| Bill grows with | Data volume ingested, and search compute under Workload or activity-based pricing | Data volume ingested and retained; compute/node count on Hosted or self-managed | Number of monitored assets, with a monthly data cap (0.5TB to 0.8TB) per tier |
| UK region availability | AWS and Google Cloud, both in London | Serverless generally available on AWS, GCP and Azure; specific UK region availability needs checking against Elastic's current region list | SaaS platform hosted on AWS; specific UK data residency needs a direct question to Rapid7 |
| Who should not choose it | A team with a highly variable, unpredictable ingest volume and no budget headroom for a variable bill | A team that wants a single quoted number with no infrastructure or node-sizing decisions of its own | A team whose main cost driver is data volume rather than asset count, or that needs deep, Splunk-style custom search across years of history |
What to ask before you commit
- Ask each vendor for a written quote at your actual daily ingest volume (Splunk, Elastic) or asset count (Rapid7), not a list price.
- Ask what retention period is included, and what an extra month or year of retention costs on top.
- Ask whether Enterprise Security, UEBA, threat intelligence or other add-on modules are priced separately, and get that figure too.
- Ask which currency the contract is in, whether VAT is charged directly or reverse-charged, and whether a UK reseller can quote in sterling.
- Ask what happens to your historical data and searches if you leave: export format, retention after termination, and any exit fee.
- Confirm the actual UK region or data residency commitment in the contract, not just in marketing copy.
Editorial analysis
The reported numbers in this piece line up with a pattern the industry has settled into: per-GB pricing rewards a SOC that filters aggressively before ingest, and punishes one that does not. Splunk's model, even without a published rate, clearly scales with data volume the same way Elastic's does, so the practical lesson for a UK enterprise is the same for both: log-source selection and pre-ingest filtering are the highest-leverage cost control available, well before switching vendors. Rapid7's per-asset model removes that specific risk but trades it for a different one, in that a large or growing estate raises the bill even if logging stays modest. Given that none of the three publishes UK pricing and only Elastic publishes a rate at all, the honest advice for a UK SOC manager is to treat every published or reported figure here as a starting point for a quote conversation, not as a number to put directly into next year's budget.
Sources
- Splunk Platform Pricing FAQ - Splunk
- Serverless Pricing - Security - Elastic
- Pricing Hub - Elastic
- SIEM (InsightIDR) Overview - Rapid7
- AWS Marketplace: InsightIDR - Next-gen SIEM - Amazon Web Services / Rapid7
- How Much Does A SIEM Cost? 2026 Price Breakdown - CIPHER
- Introduction to logging for security purposes - National Cyber Security Centre