Editorially independent. Sponsors are disclosed and never influence our analysis.
Independent research, supported bycriblSponsor
Vendor / Gravwell

Gravwell pricing in 2026: the node-based, unlimited-ingest model

The independent Gravwell pricing reference. The indexer/node-based meter explained (unlimited ingest, retention, search and users, with no per-GB charge), the free 2 GB/day Community Edition, the Professional, Enterprise and Cloud tiers, why paid pricing is sales-quoted, and what happens to a node-metered bill when log volume doubles. Built from Gravwell's published pricing and product pages. Updated August 2026.

Pricing model
Node-based
Priced by indexer count
Community tier
Free
2 GB/day ingest, full platform
Data ingest
Unlimited
No per-GB meter, per indexer
Paid tiers
Sales-quoted
Professional / Enterprise / Cloud

All figures from gravwell.io/pricing and Gravwell's product and blog pages, verified 17 August 2026. Gravwell publishes the model and the free-tier limit but no dollar figures for the paid tiers; those are quoted by sales, and this page does not extrapolate numbers the vendor has not published.

What Gravwell is, and how node-based pricing works

Gravwell is a security data and data-fusion platform. It ingests data from any source in raw, unstructured form, structure-on-read, with no schema or normalisation required at intake, and unifies logs, metrics and security data in one system that runs on-premises, in the cloud or hybrid. It serves both cyber-security investigation and threat hunting and operational-technology use cases. It was co-founded by Corey Thuen (CEO) and Kris Watts, is based in Idaho, and raised a $15.4 million Series A led by Two Bear Capital. The positioning is built around collecting everything without a volume penalty, and the pricing model is where that shows up most concretely.

The meter is indexers, not ingest. Gravwell's pricing page states the model directly: pricing is based on the number of indexers in the cluster, and each indexer has unlimited ingest capacity. Its cost-series blog is blunter still, that it does not price based on data rates and that every deployment includes unlimited data, it is your storage, use it. Among the vendors this site tracks, that makes Gravwell a third distinct pricing shape. Splunk and Sentinel meter ingested volume; storage-model vendors meter what you retain; Gravwell meters neither and instead prices the infrastructure, the indexer nodes, you stand up to search and keep the data.

The published structure has a free tier and three commercial options. Community Edition is free, capped at 2 GB/day of real ingest, and includes the full platform, all search modules, ingesters and orchestration, aimed at home use and individual analysts. The commercial tiers are Professional and Enterprise, both self-hosted, and Cloud, a Gravwell-managed deployment. All three advertise the same unlimited feature set: unlimited data ingestion, unlimited retention, unlimited search count, unlimited users and unlimited automations, with tiered storage and cloud archive on the managed option.

What is not published matters as much. Gravwell lists no dollar figure for any paid tier. The pricing page carries the model and the tier names but routes to a request-pricing form, so the commercial number arrives through a sales conversation sized on indexer count and deployment. The only dollar amount on a Gravwell pricing page is a competitor illustration in the cost blog, a $600 per GB/day/year scenario attributed to ingest-priced tools, which is not Gravwell's own price. This page reflects the model Gravwell publishes and does not invent the tier figures it withholds.

Gravwell tier reference

TierPriceWhat is published
Community EditionFreeCapped at 2 GB/day of real ingest. Full platform: all search modules, ingesters and orchestration. Aimed at home use and individual analysts.
Professional (self-hosted)Sales-quotedPriced by indexer count. Unlimited data ingestion, retention, search count, users and automations. Runs in your own infrastructure.
Enterprise (self-hosted)Sales-quotedPriced by indexer count, with enterprise features on top of Professional. Same unlimited-data feature set. Self-hosted.
Cloud (managed)Sales-quotedGravwell-hosted managed deployment. Same unlimited-data model plus tiered storage / cloud archive. No public rate card.

Source: gravwell.io/pricing and the Community Edition announcement, verified 17 August 2026. Community Edition publishes an exact limit (free, 2 GB/day ingest). The three commercial tiers publish the model and feature set but no dollar figures; pricing is quoted by sales on indexer count. This page reflects the listed model and deliberately does not fill the gaps with invented numbers.

The doubling test: what happens when a new service doubles your logs

The cleanest way to see what a node model changes is to run the same event through both meters: your platform team ships a new service and raw log volume doubles overnight.

On an ingest meter
Sentinel PAYG rate: $4.30/GB
Before: 100 GB/day x 365 = 36,500 GB/yr
36,500 GB x $4.30 = ~$157,000/yr
After: 200 GB/day x 365 = 73,000 GB/yr
73,000 GB x $4.30 = ~$314,000/yr
Bill change: roughly doubles
On Gravwell's node meter
Ingest doubles: no ingest meter runs
Each indexer: unlimited ingest capacity
Bill moves only if: you add indexers for performance
Reason to add a node: search speed or retention headroom, not volume
Exact new figure: quote-based, no published rate card

The ingest-side arithmetic uses Microsoft Sentinel's published $4.30 per GB PAYG rate from our Sentinel pricing page; commitment tiers soften the doubling (to $2.96 effective at 100 GB/day) but the bill still scales with ingested volume. The Gravwell column is deliberately qualitative: because each indexer carries unlimited ingest, doubling raw volume adds no per-GB charge, and the bill only moves if the extra data forces more indexers for search or retention performance. Gravwell publishes no rate card, so the honest statement is directional, not a dollar figure.

Node meter vs ingest meter, across this site's references

PlatformWhat is meteredPublished anchorRaw volume doubles
GravwellIndexer / node count (unlimited ingest per node)No published dollar figure; Community free at 2 GB/day, paid tiers sales-quoted by indexer countIngest is unmetered; the bill moves only if you add indexers for search or retention headroom
Splunk Cloudfigures: /splunk-pricingIngested GB/day (or SVC workload units)Roughly $665 to $1,620 per GB/day per year depending on commit volumeMetered volume doubles; the ingest bill roughly doubles
Microsoft Sentinelfigures: /sentinel-pricingIngested GB (per-GB meter)$4.30 per GB PAYG, $2.96 effective at the 100 GB/day commitment tierMetered volume doubles; commitment tiers soften but do not remove it
Pantherfigures: /panther-pricingIngested TB/month$50,000/yr per 1 TB/month on the AWS Marketplace listingMetered volume doubles; the volume meter roughly doubles

Comparison rates are the ones already documented on this site's vendor pages, linked per row, each verified against the vendor's published pricing on the date shown on that page. The structural point is meter placement: an ingest meter prices every gigabyte that arrives, and Gravwell's node meter prices the indexers you run regardless of volume. Which lands cheaper for you depends on how much you ingest, how unpredictable it is, and how much infrastructure a node deployment needs for your search and retention targets.

Who the node model fits, and who it does not

Good fit when
  • + High or spiky ingest: unlimited per-node ingest means volume spikes carry no per-GB penalty
  • + Long retention matters: unlimited retention is part of the model, not a priced add-on
  • + You want to collect everything: the whole pitch is not being forced to under-collect to control cost
  • + On-prem, hybrid or OT/industrial data: self-hosted Professional and Enterprise tiers exist for exactly this
  • + Individual analysts and evaluators: the free Community Edition (2 GB/day, full platform) is usable, not a timed trial
Weaker fit when
  • - Small, steady, low ingest: a metered per-GB tier may cost less than standing up indexers
  • - You need a rate card before talking to sales: paid tiers publish no dollar figures
  • - You do not want to run infrastructure: self-hosted tiers push node and storage ops onto you
  • - Procurement wants itemised meters: cost lives in node count and storage, not line-item GB/query/seat
  • - Mature workflows built on an incumbent: migration effort, not pricing model, is the binding constraint

The compute and infrastructure question

Every SIEM bill has a compute component somewhere; the models differ mainly in where it sits and whether you run it. Ingest-priced platforms fold search and detection compute into the per-GB rate. Workload-priced models meter compute directly. Gravwell's node model puts compute in the indexers themselves: you provision nodes, and their capacity is what serves ingest, search and retention.

That has a clear upside and a clear cost. In its favour, there is no volume meter to fear, unlimited ingest and retention are stated features, and a heavy investigation month does not produce a surprise per-query bill. Against it, the self-hosted tiers mean you run the infrastructure, indexer nodes and their storage, so operational effort and hardware or cloud-compute cost move onto your side of the line, and because paid pricing is sales-quoted there is no public rate card to forecast against before you talk to Gravwell. On this site's usual transparency framing, Gravwell is highly transparent about the model (nodes, unlimited data) and opaque about the commercial number, which it gates behind sales. The practical question for a buyer is whether they would rather forecast gigabytes on a published meter or indexer count on a quoted one.

Verify before you buy

As with every vendor page on this site: the figures above were verified against Gravwell's published pages on 17 August 2026, and SIEM pricing changes frequently. Before signing anything, confirm the current model at gravwell.io/pricing, get the indexer count behind your quote and what it supports for your workload in writing, and ask directly how many indexers your ingest and retention targets imply, how the self-hosted infrastructure cost (nodes and storage) sits alongside the Gravwell licence, and what Community Edition's retention and seat limits are if you plan to evaluate on it. Our methodology page explains how figures on this site are sourced and what verification means.

FAQ

Common questions

How is Gravwell priced in 2026?

Gravwell prices on the number of indexers (nodes) in the cluster, not on how much data you send. Its pricing page states the model plainly: pricing is based on the number of indexers in the cluster, and each indexer has unlimited ingest capacity. Every deployment advertises unlimited data ingestion, unlimited retention, unlimited search count, unlimited users and unlimited automations. There are four ways to run it: a free Community Edition capped at 2 GB/day of ingest, and three commercial options, Professional and Enterprise (both self-hosted) and Cloud (managed). Gravwell does not publish dollar figures for the commercial tiers; the pricing page routes to a contact-sales form, so paid pricing is quote-based.

What does 'unlimited ingest' actually mean on a node model?

It means the meter is not your data volume. Gravwell's own wording is that it does not price based on data rates and that every deployment includes unlimited data. Practically, you can send 10 GB/day or 10 TB/day into a given cluster without a per-GB charge appearing. What you scale instead is indexers: you add nodes when you need more parallel search performance or retention headroom, not because a volume meter is running. That inverts the usual SIEM question. On an ingest meter the binding constraint is how much you collect; on Gravwell's node model the binding constraint is how much compute and storage you provision to search and keep it.

How much do the paid Gravwell tiers cost?

Gravwell does not publish a rate card. The pricing page lists the model (indexer-based, unlimited data) and the tier names (Professional, Enterprise, Cloud) but no dollar amounts, and it routes to a request-pricing form, so the number arrives through a sales conversation sized on your indexer count and deployment. The only figure on a Gravwell pricing page is a competitor illustration in their cost-series blog (a $600 per GB/day/year scenario attributed to ingest-priced tools), which is not Gravwell's own price. This page does not invent the tier figures Gravwell has not published.

What is in the free Community Edition?

Community Edition is free and capped at 2 GB/day of real ingest (their phrasing distinguishes real ingest from indexed data). It includes the entirety of Gravwell's search modules, ingesters and orchestration, so it is the full platform at a volume ceiling rather than a stripped-down trial, aimed at home use and individual analyst needs. Gravwell does not state a retention-period limit or an explicit user-seat cap for Community Edition beyond the 2 GB/day ingest limit, so confirm those directly if they matter to you.

Is Gravwell cheaper than Splunk or Sentinel?

It depends on whether your problem is volume or provisioning. Ingest-priced platforms meter every gigabyte that arrives: Splunk Cloud runs roughly $665 to $1,620 per GB/day per year depending on commit (see our Splunk pricing page), and Microsoft Sentinel meters $4.30 per GB PAYG, falling to $2.96 effective at the 100 GB/day commitment tier (see our Sentinel pricing page). Gravwell removes the volume meter entirely and charges for indexers instead, which is why its own positioning against Splunk stresses predictability and not being punished for ingest spikes. A team that ingests heavily and unpredictably tends to land better on a node model; a small, steady-volume team may find a metered tier cheaper than standing up indexers. Gravwell frames the win as predictability, not a guaranteed lower absolute number, and since paid figures are sales-quoted, the honest comparison is model-shape, not a like-for-like quote.

What about retention, search and seats?

Gravwell advertises all three as unlimited across its commercial tiers: unlimited retention, unlimited search count and unlimited users. That is a genuine difference from platforms that meter retention length, search/analytics compute or per-seat access separately. The trade is that the cost lives in the infrastructure you provision, indexer nodes and their storage, rather than in itemised meters, so a buyer forecasts node count and storage rather than GB, queries and seats. As always, get the specifics of what a given indexer count supports for your workload in writing before signing.

Who is behind Gravwell and what is it built on?

Gravwell is a security data / data-fusion platform: it ingests data from any source in raw, unstructured form (structure-on-read, no schema required at intake) and unifies logs, metrics and security data in one system, on-premises, cloud or hybrid, for both cyber-security and operational-technology use cases. It was co-founded by Corey Thuen (CEO) and Kris Watts, is based in Idaho, and announced a $15.4 million Series A led by Two Bear Capital with participation from Gula Tech Adventures, Next Frontier Capital, Innosphere Ventures Fund, Kickstart and Rise of the Rest.

Updated 13 July 2026