Editorially independent. Sponsors are disclosed and never influence our analysis.
Vendor / Graylog

Graylog pricing in 2026: Open, Enterprise, Security, and the consumption model

The independent Graylog pricing reference. Graylog Open (free and source-available), Graylog Enterprise from $15,000/yr and Graylog Security from $18,000/yr, the consumption-based model tied to daily volume, cloud versus self-managed, and where Graylog wins for log-management-first teams. Rates verified against Graylog's published pricing, August 2026.

Pricing model
Consumption
Daily volume / annual consumption
Graylog Open
Free
Source-available, self-hosted
Enterprise
From $15K/yr
Log management + support
Security (SIEM)
From $18K/yr
Adds detection + analytics

Figures verbatim from graylog.org/pricing: Enterprise "starting at $15,000/yr based on daily volume or annual consumption", Security "starting at $18,000/yr", Open free/source-available, Cloud priced through sales. Consumption-based; confirm your volume against a quote.

How Graylog pricing actually works

Graylog has a clean four-way structure. Graylog Open is free and source-available: the full log management core, self-hosted on your own infrastructure. Graylog Enterprise, from $15,000 per year, adds enterprise support, advanced reporting, archiving, correlation, and the Illuminate content on top. Graylog Security, from $18,000 per year, builds on Enterprise and adds the SIEM layer of detections, anomaly detection, threat intelligence, and SOC workflows. Graylog Cloud is the fully managed option, priced through sales.

Both paid editions are consumption-priced, tied to daily log volume or annual consumption rather than a published per-gigabyte rate. The $15,000 and $18,000 figures are the stated starting points; the real number for your deployment is set during the sales engagement based on the volume you license. That is the key nuance: Graylog gives you a transparent floor, but the slope above it is negotiated on volume, not published as a step table.

The free Open edition is genuinely useful, which shapes the buying pattern. Many teams run production centralised logging on Graylog Open and only move to a paid edition when they need a specific capability: enterprise support and archiving push them to Enterprise, and the need for active security detection pushes them to Security. Because the upgrade path is feature-driven rather than forced, the sensible approach is to prove the deployment on Open, then buy the edition whose features you can actually name.

The self-managed versus cloud choice is the other lever. Self-managed Graylog means running the OpenSearch and MongoDB backend and owning the operations, which avoids the managed premium but costs engineering time. Graylog Cloud removes the ops burden at a price set through sales. For teams with platform engineering capacity, self-managed Enterprise is usually cheaper all-in; for lean teams, Cloud can win once operational time is counted honestly.

Graylog editions and pricing

EditionPriceWhat you get
Graylog OpenFree (source-available)Full log management core, self-hosted. No Illuminate content packs or enterprise-only features.
Graylog EnterpriseFrom $15,000/yrConsumption-priced on daily volume or annual consumption. Adds enterprise support, reporting, archiving, correlation.
Graylog SecurityFrom $18,000/yrEnterprise plus SIEM and security analytics: detections, anomaly detection, threat intel, SOC workflows.
Graylog CloudContact salesFully managed platform. No public rate on the pricing page; priced by volume through sales.

Graylog cost scenarios

ProfileDeploymentCostNote
Small team / labGraylog Open, self-hostedFree + your infrastructureYou run OpenSearch/MongoDB and the ops; software is free
Mid-market log mgmtGraylog Enterprise, entryFrom $15,000/yrConsumption-based; actual figure set by licensed daily volume
Mid-market SOCGraylog Security, entryFrom $18,000/yrAdds the security analytics and detection layer
Higher volumeEnterprise or Security, scaledNegotiated on volumePrice rises with committed daily volume; no published per-GB step

Four Graylog cost optimisations that genuinely work

Start on Graylog Open and upgrade deliberately

Defers licence spend

Graylog Open is a genuinely capable, source-available log management platform, not a crippled trial. Many teams run production centralised logging on Open and only move to Enterprise or Security when they specifically need enterprise support, archiving, reporting, or the security analytics layer. Prove the deployment on Open first, then buy the paid edition for the features you can name.

Buy Enterprise, not Security, if you only need log management

~$3K/yr at entry

The step from Enterprise (from $15,000/yr) to Security (from $18,000/yr) buys the SIEM and security-analytics layer: detections, anomaly detection, threat intelligence, and SOC workflows. If your requirement is operational log management and compliance rather than active threat detection, Enterprise covers it and the Security premium is spend you do not need yet.

Right-size committed daily volume

Directly on licence

Both paid editions are consumption-priced on daily log volume or annual consumption, so the licence tracks how much you commit to ingest. Filtering low-value logs (debug noise, health checks, duplicate sources) at the input stage before they count against your committed volume is the direct lever, exactly as with per-GB SIEMs.

Weigh self-managed infrastructure against Cloud

Deal-dependent

Self-managed Graylog means you run the OpenSearch and MongoDB backend and carry the ops burden, but you avoid the managed-cloud premium. Graylog Cloud removes that operational cost at a price set through sales. For teams with platform engineering capacity, self-managed Enterprise is usually cheaper all-in; for lean teams, Cloud can be the better total cost once ops time is counted.

When Graylog is the right SIEM

Graylog wins for teams that want strong centralised log management with a clean, affordable path into security analytics. The free Open edition lets you prove the platform in production, the paid editions start at published five-figure entry points rather than opaque six-figure quotes, and Graylog Security adds a real SIEM layer without changing platforms. It fits mid-market SOCs, log-management-first engineering teams, and organisations that value a source-available foundation and predictable upgrade economics.

Graylog is less compelling at the very top of the volume range, where hyperscale cloud-native telemetry and the deepest threat-hunting workloads favour security data lakes and the largest enterprise SIEMs, and where the consumption pricing above the entry point is negotiated rather than transparent. If your requirement is enormous ingest with advanced analytics and a mature app ecosystem, weigh Graylog against Splunk, Sentinel, and Chronicle; if it is capable, cost-controlled logging and SIEM for a mid-market estate, Graylog is often the most economical serious option.

FAQ

Common questions

Is Graylog free?

Yes, in part. Graylog Open is a free, source-available edition with the full log management core: collection, parsing, search, dashboards, and alerting, self-hosted on your own infrastructure. It is a real production option, not a time-limited trial. What it lacks are the enterprise-only capabilities (Illuminate content packs, enterprise support, advanced reporting and archiving) and the security analytics layer. Those live in the paid editions: Graylog Enterprise from $15,000 per year and Graylog Security from $18,000 per year.

How much does Graylog cost in 2026?

Graylog publishes entry points rather than a full rate card. Graylog Enterprise starts at $15,000 per year and Graylog Security starts at $18,000 per year, both priced on a consumption model tied to daily log volume or annual consumption. Graylog Open is free. Graylog Cloud, the fully managed platform, is priced through sales with no public figure on the pricing page. Because the paid editions are consumption-based, the real number for your deployment depends on the daily volume you license, so treat $15,000 and $18,000 as starting points and confirm against a quote for your volume.

What is the difference between Graylog Enterprise and Graylog Security?

Graylog Enterprise is the commercial log management platform: it adds enterprise support, advanced reporting, archiving, correlation, and the Illuminate content on top of Graylog Open. Graylog Security builds on Enterprise and adds the SIEM layer: security detections, anomaly detection, threat intelligence integration, and SOC investigation workflows. The $3,000 per year gap at the entry point (from $15,000 to $18,000) is the cost of turning a log management platform into a security analytics platform. Choose Enterprise for operational logging and compliance, Security for active threat detection.

How does Graylog pricing compare to Splunk?

Graylog is generally the more economical option for log management and mid-market SIEM, particularly because Graylog Open is free and the paid editions start at published five-figure entry points, whereas Splunk's all-in cost at comparable volume typically runs well into six figures once Enterprise Security is added. Splunk's advantages are ecosystem breadth, maturity, and the depth of its app marketplace. The practical decision is usually scale and use case: Graylog fits teams that want strong centralised logging with an affordable security upgrade path, while Splunk suits large enterprises that need its breadth and can fund it.

Does Graylog publish a per-GB price?

No. The paid editions are consumption-priced on daily log volume or annual consumption rather than a published per-gigabyte step rate, and the actual price is set during the sales engagement based on the volume you license. That means two buyers at different volumes will see different effective per-GB economics, and the only figures Graylog states publicly are the Enterprise and Security starting points of $15,000 and $18,000 per year. For a precise per-GB comparison against other SIEMs, you need a quote at your specific daily volume.

Updated 13 July 2026