Cybersecurity
SIEM & Log Retention Storage
We do not sell or operate a SIEM. What we size and supply is the storage, compute and aggregation hardware a SIEM deployment consumes across its retention window — and the scanning licenses that feed it.

- Category
- The storage and compute tier underneath a log-retention requirement
- What we quote
- Arrays, drives, collector hosts and the network path between them
- Sizing
- Daily ingest multiplied by the retention window, plus index overhead
- Boundary
- We hold no SIEM software inventory and say so rather than substituting
The honest scope of this page
Log retention requirements are common — a year online, longer in archive, with the exact figure set by the framework or contract your program works to. What is less commonly costed is what that requirement weighs. A daily ingest measured in tens of gigabytes becomes tens of terabytes across a retention year, and the index overhead most platforms add on top of raw log volume is routinely a surprise rather than a plan. That storage, and the collector hosts and network path feeding it, is real infrastructure with a real price, and it is what we size and supply. What we do not do is sell SIEM software — we hold no priced inventory in that market, and rather than relabeling an adjacent product we say so and quote the layer we genuinely carry.
How a retention requirement turns into a capacity number
Start with daily ingest, measured rather than estimated — most programs are surprised in both directions once they instrument it. Multiply by the online retention window, then add index and metadata overhead, which varies by platform and is frequently a meaningful fraction of raw volume again. Then decide what happens after the online window: an archive tier that is cheaper per terabyte and slower to search, or deletion under a documented schedule. Both are legitimate; only one of them is a plan.
Then the collection path. Aggregation hosts or collectors sit between the sources and the platform, buffering when the platform is unavailable so events are not lost during a maintenance window. That buffer is a sizing decision too — how long an outage the design has to absorb without dropping events. And the network path between collection and storage has to carry sustained ingest alongside whatever search traffic the analysts generate.
Retention is a records decision as much as a technical one. How long logs are kept, and whether they are subject to hold, is determined inside your program under the authority that owns the requirement. We size to the number you give us.
The infrastructure a log platform consumes
Priced lines from the hub catalog, sized against your measured ingest and retention window. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.
Retention storage
Nexsan arrays and Western Digital drive lines for the online and archive tiers, sized against ingest multiplied by retention plus index overhead — and against the search performance the online tier has to sustain, which is what separates the two tiers.
Consolidated platforms
Cohesity where the design consolidates long-horizon retention with backup and archive rather than standing up a separate estate for each. Quoted as a platform with the capacity and retention policy sized together.
Collector and aggregation hosts
Lenovo server lines for the collection tier, sized with enough buffer to absorb a platform outage without dropping events. Racked, firmware-baselined and labeled before delivery.
Tenable, feeding the pipeline
Vulnerability scanner subscriptions whose findings commonly land in the same platform as the logs. Quoted per asset band against your anniversary, alongside the storage that holds the output.
Log retention questions
Do you sell SIEM software?
No. We hold no priced inventory for SIEM or SOAR platforms, and we do not present an adjacent product as one. What we supply is the storage, collection and compute hardware a SIEM deployment consumes, and the vulnerability-management licensing that often feeds it.
How much storage does a year of logs need?
Measured daily ingest, multiplied by the retention window, plus index and metadata overhead — which on many platforms is a substantial fraction of raw volume again. The figure that catches programs out is the overhead, because it is rarely in the requirement and always in the invoice.
Should logs stay online for the whole retention period?
Usually not, and that is the cheapest decision available. A shorter high-performance online window for active search, with an archive tier behind it for the remainder of the retention period, costs materially less than keeping everything searchable. Where the split falls is a program decision, and we size to it.
Do you operate log collection for us?
No. We size and supply the infrastructure and can deliver it racked and configured to your design. Running the platform, writing the detection content and reviewing the output stay with your security team or the provider you have engaged.
The solutions atlas
Every solution, one accountable partner.
UniQ platforms
By technology
By customer
- TAA & NDAA-889 Compliance Screening
- CMMC & CUI Solutions
- Federal & DoD
- State, Local & Education
- Healthcare
- Enterprise
- Rapid Procurement & GPC Buys
- Multi-Vendor Integration Projects
- eProcurement & Custom Catalogs
- FISMA Modernization
- CJIS-Compliant Justice Cloud & Local AI
- Federal Storage Modernization
- Government ERP & Business Systems Infrastructure
- Managed Procurement
- Secure AV & Conferencing
- Fiber Network Infrastructure
- Satellite & Resilient Connectivity
- Wavelength & Optical Transport
- Decentralized Data Centers
- Data Center Design & Build
Turn a retention requirement into a capacity plan
Send measured daily ingest, the retention window you are held to and whether an archive tier is in scope. We return a sized storage and collection quote with the platform's index overhead accounted for rather than assumed.