A darkened security operations centre at night, several analysts seated at curved desks facing a wall of monitoring dashboards showing line charts and log streams, blue and amber screen glow lighting

Splunk vs Elastic Security vs Rapid7 InsightIDR for UK SOC teams

10 min read

Splunk, Elastic Security and Rapid7 InsightIDR meter SIEM cost in three different ways, and only Elastic publishes its rate. This piece compares the published and reported pricing, sets out what each model rewards and punishes, and lists the questions a UK SOC manager should put to each vendor before budgeting.

Written by Andrew McLean Studio Director at Disruptive Live

A UK enterprise SOC weighing Splunk, Elastic Security and Rapid7 InsightIDR is not comparing three prices for the same thing. Splunk and Elastic charge for the data you feed in; Rapid7 charges mainly for the assets you monitor, within a monthly data cap. Elastic publishes its per-GB rate directly; Rapid7 publishes 12-month reference prices through a marketplace listing; Splunk publishes no price at all. Before you shortlist, work out which meter fits your log volume, then get a written quote in the currency and period you actually plan to buy.

Key pointers

  • Splunk publishes no public per-GB or per-SVC price anywhere on its site; only the Ingest, Workload and activity-based pricing mechanics are public, not a rate card.
  • Elastic Security Serverless is the only one of the three with a published, dated per-GB rate: from $0.09/GB ingested on the Essentials tier.
  • Rapid7 InsightIDR bills primarily per monitored asset, but each published tier also carries a monthly data cap (0.5TB to 0.8TB), so volume is not entirely irrelevant.
  • A noisy log source (firewalls, DNS, cloud audit trails) inflates Splunk and Elastic bills directly, and can push Rapid7 past its tier's monthly data cap even though assets, not gigabytes, set the base price.
  • Splunk's ingest-priced Cloud subscription bundles roughly 90 days of storage; Elastic bills retention separately, every month, on top of ingest.
  • Ask every shortlisted vendor to quote the same ingest volume and retention period, in writing, before you compare totals.
  • Licence cost is reported to be well under half of total SIEM spend once staffing, storage, tuning and integration are added.
  • None of the three publishes a GBP price list; get a written sterling quote through a UK reseller or cloud marketplace listing before budgeting.
How a SIEM pricing model shapes the bill
Splunk and Elastic charge for data ingested; Rapid7 charges for assets monitored, so the same log growth affects each bill differently.

What this decision means for a UK SOC

For a SOC manager, the platform choice sets two things at once: how much of the security budget scales with log volume, and how much of the operational load falls on your own analysts versus the vendor. Splunk and Elastic both bill primarily on data ingested, so a decision to onboard a new firewall, proxy or cloud audit-log source is also a pricing decision. Rapid7 InsightIDR bills on monitored assets instead, so ingesting more log detail from an existing asset does not move the licence cost, but adding servers, endpoints or cloud accounts does.

None of the three publishes a UK price list, and Splunk publishes no price at all. Splunk's pricing FAQ sets out the mechanics of Ingest, Workload and activity-based pricing but states no dollar figure for any of them. Rapid7 is more transparent than Splunk but not fully: its marketplace listing (detailed below) publishes three 12-month reference prices, each covering up to 500 monitored assets, which is a real number but not necessarily your number if your estate is larger or smaller. Elastic is the clearest of the three: its Serverless Security pricing page states an actual per-GB ingest rate and a per-GB retention rate, dated to take effect from 1 November 2025. That transparency gap matters for procurement: you can model Elastic's licence cost from the public page alone, and get close with Rapid7's published reference tiers, but Splunk needs a live quote before you can put a number in a business case.

Small and mid-sized UK organisations considering the same three platforms face a sharper version of this problem, because low log volumes do not always mean a low bill. A per-asset model like Rapid7's can suit a business with few servers but heavy logging needs; a per-GB model like Elastic's or Splunk's can suit a business with light logging but many devices. Model both against your actual log mix rather than against headcount alone.

How each platform prices ingestion

PlatformPricing metricReported or published rateSource
Splunk Cloud Platform, Ingest modelGB indexed per day (annual subscription includes ~90 days storage)Mechanics published; unit price not published, quote requiredSplunk pricing FAQ (vendor)
Splunk Cloud Platform, Workload modelSplunk Virtual Compute (SVC) units, driven by search activity and ingestMechanics published; unit price not published, quote requiredSplunk pricing FAQ (vendor)
Splunk Cloud Platform, activity-based modelDual meter on ingest and search activityMechanics published; unit price not published, quote requiredSplunk pricing page (vendor)
Elastic Security Serverless, Essentials tierPer GB ingested, plus per GB retained per monthAs low as $0.09/GB ingest, $0.017/GB/month retentionElastic Serverless Security pricing (vendor), effective 1 November 2025
Elastic Security Serverless, Complete tierPer GB ingested, plus per GB retained per monthAs low as $0.11/GB ingest, $0.019/GB/month retentionElastic Serverless Security pricing (vendor), effective 1 November 2025
Rapid7 InsightIDR EssentialPer monitored asset, 12-month term, up to 500 assets, 0.5TB/month data cap$21,479 for the 12-month term (up to 500 assets)AWS Marketplace listing (vendor)
Rapid7 InsightIDR AdvancedPer monitored asset, 12-month term, up to 500 assets, 0.6TB/month data cap$33,682 for the 12-month term (up to 500 assets)AWS Marketplace listing (vendor)
Rapid7 IDR UltimatePer monitored asset, 12-month term, up to 500 assets, 0.8TB/month data cap, includes ENTA and unlimited automation$46,149 for the 12-month term (up to 500 assets)AWS Marketplace listing (vendor)

Worked example, Elastic only (the one platform with a published rate). A SOC sustaining 50 GB/day of ingest for a year sends 50 x 365 = 18,250 GB. On Security Analytics Essentials at $0.09/GB, ingest alone costs 18,250 x $0.09 = $1,642.50 for the year. On Complete at $0.11/GB, the same volume costs 18,250 x $0.11 = $2,007.50. Retention is billed separately, per GB stored per month, so a business retaining data for longer than the month it lands adds a second recurring line on top of these figures. This is an ingest-only estimate from Elastic's own published rate; it excludes retention, the AI SOC Engine add-on, egress above the free 50 GB, and any negotiated discount.

Splunk's ingest model works the same way in principle: a daily volume multiplied by a per-GB rate, with Enterprise Security, the module most genuine SOC deployments need, licensed separately on top. Because Splunk states no figure for either the per-GB rate or the SVC unit price, CTC could not independently verify third-party estimates of Splunk's ingest cost, including the range published by CIPHER's SIEM cost breakdown. Treat any reported Splunk number you encounter while shortlisting as an unconfirmed planning band rather than a quote, and get Splunk's own current rate for your actual ingest volume before budgeting against it.

Rapid7 works differently again. Its AWS Marketplace listing publishes a 12-month reference price for up to 500 monitored assets at each tier: $21,479 for Essential (0.5TB/month data cap), $33,682 for Advanced (0.6TB/month) and $46,149 for Ultimate (0.8TB/month, with ENTA and unlimited automation bundled in). Dividing the Essential figure across its bundled 500 assets and 12 months gives $21,479 / 500 / 12 = $3.58 per asset per month, at that reference volume; the same calculation on Ultimate gives $46,149 / 500 / 12 = $7.69 per asset per month. Because the meter is assets rather than gigabytes, adding log detail from an asset you already monitor does not move this bill, but each tier still caps the data it will accept per month, so a very noisy estate can force an upgrade regardless of asset count.

Splunk, Elastic Security and Rapid7 InsightIDR compared

CriterionSplunk Cloud Platform / Enterprise SecurityElastic Security (Serverless, Hosted or self-managed)Rapid7 InsightIDR
Pricing basisIngest (GB/day), Workload (SVC/vCPU) or activity-based (ingest plus search activity); quote requiredIngest and retention per GB (Serverless), or resource/node-based (Hosted/self-managed)Per monitored asset with a monthly data cap; published 12-month reference rate for up to 500 assets, per tier
Deployment optionsSplunk Cloud (SaaS) or Splunk Enterprise (on-prem, term licence)Serverless (fully managed), Hosted (Elastic-managed infrastructure) or self-managed (customer-run)Cloud SaaS only, with an on-premises or dedicated Collector forwarding logs
Bill grows withData volume ingested, and search compute under Workload or activity-based pricingData volume ingested and retained; compute/node count on Hosted or self-managedNumber of monitored assets, with a monthly data cap (0.5TB to 0.8TB) per tier
UK region availabilityAWS and Google Cloud, both in LondonServerless generally available on AWS, GCP and Azure; specific UK region availability needs checking against Elastic's current region listSaaS platform hosted on AWS; specific UK data residency needs a direct question to Rapid7
Who should not choose itA team with a highly variable, unpredictable ingest volume and no budget headroom for a variable billA team that wants a single quoted number with no infrastructure or node-sizing decisions of its ownA team whose main cost driver is data volume rather than asset count, or that needs deep, Splunk-style custom search across years of history

What to ask before you commit

  • Ask each vendor for a written quote at your actual daily ingest volume (Splunk, Elastic) or asset count (Rapid7), not a list price.
  • Ask what retention period is included, and what an extra month or year of retention costs on top.
  • Ask whether Enterprise Security, UEBA, threat intelligence or other add-on modules are priced separately, and get that figure too.
  • Ask which currency the contract is in, whether VAT is charged directly or reverse-charged, and whether a UK reseller can quote in sterling.
  • Ask what happens to your historical data and searches if you leave: export format, retention after termination, and any exit fee.
  • Confirm the actual UK region or data residency commitment in the contract, not just in marketing copy.

Editorial analysis

The reported numbers in this piece line up with a pattern the industry has settled into: per-GB pricing rewards a SOC that filters aggressively before ingest, and punishes one that does not. Splunk's model, even without a published rate, clearly scales with data volume the same way Elastic's does, so the practical lesson for a UK enterprise is the same for both: log-source selection and pre-ingest filtering are the highest-leverage cost control available, well before switching vendors. Rapid7's per-asset model removes that specific risk but trades it for a different one, in that a large or growing estate raises the bill even if logging stays modest. Given that none of the three publishes UK pricing and only Elastic publishes a rate at all, the honest advice for a UK SOC manager is to treat every published or reported figure here as a starting point for a quote conversation, not as a number to put directly into next year's budget.

Sources

Data & Insights

Elastic Security Serverless published rates by tier

Elastic is the only one of the three vendors that publishes its ingest and retention rate, and Complete costs more per GB than Essentials on both.

Elastic Security Serverless published rates by tierElastic is the only one of the three vendors that publishes its ingest and retention rate, and Complete costs more per GB than Essentials on both.Ingest, $ per GBRetention, $ pe…US$0.00US$0.03US$0.05US$0.08US$0.10US$0.13EssentialsEssentialsCompleteCompleteEssentials, Ingest, $ per GB: US$0.09Complete, Ingest, $ per GB: US$0.11Essentials, Retention, $ per GB per month: US$0.02Complete, Retention, $ per GB per month: US$0.02
View the data
Elastic Security Serverless published rates by tier
CategoryIngest, $ per GBRetention, $ per GB per month
EssentialsUS$0.09US$0.02
CompleteUS$0.11US$0.02
Source: Elastic Serverless Security pricing, effective 1 November 2025

Frequently Asked Questions

Does Splunk publish a public price per gigabyte?

No. Splunk's own pricing FAQ describes Ingest (GB/day), Workload (SVC) and activity-based pricing mechanics but states no unit price for any of them; you need to contact Splunk sales for a quote specific to your deployment.

Is Elastic Security actually cheaper than Splunk?

Elastic publishes a rate and Splunk does not, so a direct comparison is only possible using an unverified third-party estimate for Splunk (set out and caveated above), rather than two figures CTC could confirm against both vendors' own pages. Even taking that estimate at face value, the two numbers are not measured the same way, because the reported Splunk rate is described as including roughly 90 days of storage while Elastic bills retention separately, per GB, per month. Get both vendors to quote the same ingest and retention scenario before comparing totals.

How does Rapid7 InsightIDR's per-asset pricing affect a growing UK business?

InsightIDR's published AWS Marketplace reference tiers cover up to 500 monitored assets for a 12-month term, at $21,479 (Essential), $33,682 (Advanced) or $46,149 (Ultimate). Because the primary meter is assets, adding log detail from a device you already monitor does not move the bill, but a business adding servers, endpoints or cloud accounts quickly should model that growth into the contract, and check each tier's monthly data cap (0.5TB to 0.8TB) against its actual log volume before signing.

Does a UK cloud region mean my SIEM data stays in the UK?

Not automatically. Splunk Cloud is available in AWS and Google Cloud regions in London, but a UK region choice is a hosting location, not a guarantee about which support staff, subcontractors or backup locations touch the data. Confirm data residency and processing terms in the contract, not from the regional availability list alone.

What does NCSC guidance say about how much to log?

NCSC's guidance on logging for security purposes, first published in 2018, recommends starting from the questions you would need answered during an incident, such as what happened and what the impact was, then working out which logs answer them and how long they need to be kept, rather than starting from a storage budget. That sequencing affects SIEM cost directly, since the logs you choose to keep are the ones you pay to ingest and retain.

Is the licence price the full cost of running a SIEM?

No. Industry reporting puts total cost of ownership at roughly two to three times the licence line once storage, integration, detection tuning and analyst staffing are added, with a single SIEM-focused analyst costing an estimated $130,000 to $240,000 fully loaded. Budget the licence as a starting point, not the total.