The Logs You Can Afford To Lose: A Practical Guide To Reviewing Your SIEM Ingest
Every security team has a SIEM bill that only ever seems to go up. More sources, more endpoints, more cloud services, and the ingest volume climbs month after month. The instinct is to keep everything, because nobody wants to be the person who dropped the one log that turned out to matter. That instinct is understandable. It is also the reason so many teams are paying a great deal for data they will never look at.
This post is a practical way to review what you are ingesting and decide, source by source, what earns its place. It is not an argument for blanket cuts. It is about knowing the security value of each log against what it costs you to keep, then making a deliberate choice rather than defaulting to everything.
Why Ingest Everything Became The Default
Three things push teams towards keeping it all. The first is pricing. Most traditional SIEM platforms charge by the volume you ingest, so the very thing you want, more visibility, is the thing that costs you more. Over time that quietly turns your detection strategy into a budgeting exercise.
The second is fear of the missing log. When an incident happens, the last thing anyone wants is to discover the relevant data was never collected. So sources get added and almost none get removed. The third is ownership. Ingest tends to grow because lots of people can add a source and nobody is responsible for reviewing whether it still belongs there. Left alone, the pipeline only ever gets bigger.
Start With What The Data Is Actually For
Before you judge any source, be clear on its purpose. Most logs serve one of a few jobs: real time detection, investigation during and after an incident, compliance and audit, or longer term threat hunting. A log that feeds an active detection rule is a very different thing from one you are keeping in the expensive tier just in case. Sorting your sources by purpose is the fastest way to see where money is going on data that no rule, report or analyst is actually using.
Score Each Source On Value And Cost
With purpose established, score each source on a few simple measures. You do not need a complex model, just honest answers.
- Detection value. Does anything actually alert on this source, or does it simply sit there?
- Investigation value. Would you genuinely reach for it during an incident, and how often have you in the past year?
- Compliance requirement. Are you obliged to keep it, and for how long, or is that an assumption nobody has checked?
- Volume and cost. How much of your bill does this one source represent?
Those answers point to one of four outcomes for each source: keep it in the hot, queryable tier where detection needs it, move it to cheaper storage for the long tail you might need later, reduce it by filtering or sampling before it lands, or drop it altogether. The point is that every source gets a decision rather than a free pass.
The Sources People Are Often Surprised To Be Paying For
I want to be careful not to make sweeping claims about your environment, because every estate is different. That said, a few patterns come up often enough to be worth checking. Verbose debug logging that was switched on during a project and never switched off. The same source feeding two tools and being paid for twice. High volume, low value telemetry sitting in the expensive tier when it rarely drives a detection. Development and test systems logging into the same platform as production. None of these are certainties, but each is worth a look when you run your review.
Where A Security Data Lake Changes The Maths
Here is the shift that matters most. The choice is not really keep versus delete. With a tiered approach you can keep the data and still lower the bill, by putting it in the right place. Detection grade data stays in the SIEM where it needs to be fast and queryable. The long tail that you keep for hunting or compliance moves to lower cost storage such as a security data lake, where it is still available when you need it but is not priced like live detection data.
This is the heart of a modern security data foundation. It lets you say yes to retention and yes to cost control at the same time, rather than trading one against the other. Done well, it is often where the largest and most sustainable savings come from, without giving up the visibility your team relies on.
One Thing Worth Protecting
There is a sensible caution to hold alongside all of this. Some sources look quiet right up until the day you need them. Authentication logs, records of privileged activity and the audit trail around your most sensitive systems may generate very little in the way of daily alerts, yet they are exactly what an investigator will ask for first when something goes wrong. When a source scores low on day to day detection but high on the what happens if we miss it test, that is usually a signal to keep it, even if you move it to cheaper storage. The aim of the review is to spend less on data that does nothing, not to quietly bin the records that would save you in an incident. A good review sharpens your visibility. It does not hollow it out.
A Review You Can Actually Run
Keep the process light so it actually happens. List your sources. Tag each one by purpose. Pull the volume and cost per source from your platform. Score them on the measures above. Make a keep, move, reduce or drop decision for each, and write down why. Then put a recurring review in the calendar, quarterly is usually enough, because ingest drifts and today’s sensible pipeline becomes next year’s bloated one if nobody looks again.
None of this needs to be a grand transformation programme. The teams that keep their SIEM costs under control are rarely the ones with the cleverest tooling. They are the ones who treat ingest as something to be reviewed on purpose, with a named owner and a regular slot, rather than something that simply grows in the background until the finance team asks a difficult question. A short honest review once a quarter will tell you more about your spend than any vendor dashboard, and it puts the decisions back where they belong, with you.
Get In Touch
If you would like a second pair of eyes on your ingest, or help designing a tiered approach that protects your visibility while lowering your bill, we would be happy to help. Email the HOOP Cyber team at and we will be glad to talk it through with you.