Uniqcli

Cybersecurity

SIEM & Log Retention Storage

We do not sell or operate a SIEM. What we size and supply is the storage, compute and aggregation hardware a SIEM deployment consumes across its retention window — and the scanning licenses that feed it.

Category
The storage and compute tier underneath a log-retention requirement
What we quote
Arrays, drives, collector hosts and the network path between them
Sizing
Daily ingest multiplied by the retention window, plus index overhead
Boundary
We hold no SIEM software inventory and say so rather than substituting
Overview

The honest scope of this page

Log retention requirements are common — a year online, longer in archive, with the exact figure set by the framework or contract your program works to. What is less commonly costed is what that requirement weighs. A daily ingest measured in tens of gigabytes becomes tens of terabytes across a retention year, and the index overhead most platforms add on top of raw log volume is routinely a surprise rather than a plan. That storage, and the collector hosts and network path feeding it, is real infrastructure with a real price, and it is what we size and supply. What we do not do is sell SIEM software — we hold no priced inventory in that market, and rather than relabeling an adjacent product we say so and quote the layer we genuinely carry.

The moving parts

How a retention requirement turns into a capacity number

Start with daily ingest, measured rather than estimated — most programs are surprised in both directions once they instrument it. Multiply by the online retention window, then add index and metadata overhead, which varies by platform and is frequently a meaningful fraction of raw volume again. Then decide what happens after the online window: an archive tier that is cheaper per terabyte and slower to search, or deletion under a documented schedule. Both are legitimate; only one of them is a plan.

Then the collection path. Aggregation hosts or collectors sit between the sources and the platform, buffering when the platform is unavailable so events are not lost during a maintenance window. That buffer is a sizing decision too — how long an outage the design has to absorb without dropping events. And the network path between collection and storage has to carry sustained ingest alongside whatever search traffic the analysts generate.

Retention is a records decision as much as a technical one. How long logs are kept, and whether they are subject to hold, is determined inside your program under the authority that owns the requirement. We size to the number you give us.

Questions

Log retention questions

Do you sell SIEM software?

No. We hold no priced inventory for SIEM or SOAR platforms, and we do not present an adjacent product as one. What we supply is the storage, collection and compute hardware a SIEM deployment consumes, and the vulnerability-management licensing that often feeds it.

How much storage does a year of logs need?

Measured daily ingest, multiplied by the retention window, plus index and metadata overhead — which on many platforms is a substantial fraction of raw volume again. The figure that catches programs out is the overhead, because it is rarely in the requirement and always in the invoice.

Should logs stay online for the whole retention period?

Usually not, and that is the cheapest decision available. A shorter high-performance online window for active search, with an archive tier behind it for the remainder of the retention period, costs materially less than keeping everything searchable. Where the split falls is a program decision, and we size to it.

Do you operate log collection for us?

No. We size and supply the infrastructure and can deliver it racked and configured to your design. Running the platform, writing the detection content and reviewing the output stay with your security team or the provider you have engaged.

Ask AI about Uniqcli

SIEM & Log Retention Storage

Turn a retention requirement into a capacity plan

Send measured daily ingest, the retention window you are held to and whether an archive tier is in scope. We return a sized storage and collection quote with the platform's index overhead accounted for rather than assumed.