Graylog pricing in 2026: Open, Enterprise, Security, and the consumption model
The independent Graylog pricing reference. Graylog Open (free and source-available), Graylog Enterprise from $15,000/yr and Graylog Security from $18,000/yr, the consumption-based model tied to daily volume, cloud versus self-managed, and where Graylog wins for log-management-first teams. Rates verified against Graylog's published pricing, August 2026.
Figures verbatim from graylog.org/pricing: Enterprise "starting at $15,000/yr based on daily volume or annual consumption", Security "starting at $18,000/yr", Open free/source-available, Cloud priced through sales. Consumption-based; confirm your volume against a quote.
How Graylog pricing actually works
Graylog has a clean four-way structure. Graylog Open is free and source-available: the full log management core, self-hosted on your own infrastructure. Graylog Enterprise, from $15,000 per year, adds enterprise support, advanced reporting, archiving, correlation, and the Illuminate content on top. Graylog Security, from $18,000 per year, builds on Enterprise and adds the SIEM layer of detections, anomaly detection, threat intelligence, and SOC workflows. Graylog Cloud is the fully managed option, priced through sales.
Both paid editions are consumption-priced, tied to daily log volume or annual consumption rather than a published per-gigabyte rate. The $15,000 and $18,000 figures are the stated starting points; the real number for your deployment is set during the sales engagement based on the volume you license. That is the key nuance: Graylog gives you a transparent floor, but the slope above it is negotiated on volume, not published as a step table.
The free Open edition is genuinely useful, which shapes the buying pattern. Many teams run production centralised logging on Graylog Open and only move to a paid edition when they need a specific capability: enterprise support and archiving push them to Enterprise, and the need for active security detection pushes them to Security. Because the upgrade path is feature-driven rather than forced, the sensible approach is to prove the deployment on Open, then buy the edition whose features you can actually name.
The self-managed versus cloud choice is the other lever. Self-managed Graylog means running the OpenSearch and MongoDB backend and owning the operations, which avoids the managed premium but costs engineering time. Graylog Cloud removes the ops burden at a price set through sales. For teams with platform engineering capacity, self-managed Enterprise is usually cheaper all-in; for lean teams, Cloud can win once operational time is counted honestly.
Graylog editions and pricing
| Edition | Price | What you get |
|---|---|---|
| Graylog Open | Free (source-available) | Full log management core, self-hosted. No Illuminate content packs or enterprise-only features. |
| Graylog Enterprise | From $15,000/yr | Consumption-priced on daily volume or annual consumption. Adds enterprise support, reporting, archiving, correlation. |
| Graylog Security | From $18,000/yr | Enterprise plus SIEM and security analytics: detections, anomaly detection, threat intel, SOC workflows. |
| Graylog Cloud | Contact sales | Fully managed platform. No public rate on the pricing page; priced by volume through sales. |
Graylog cost scenarios
| Profile | Deployment | Cost | Note |
|---|---|---|---|
| Small team / lab | Graylog Open, self-hosted | Free + your infrastructure | You run OpenSearch/MongoDB and the ops; software is free |
| Mid-market log mgmt | Graylog Enterprise, entry | From $15,000/yr | Consumption-based; actual figure set by licensed daily volume |
| Mid-market SOC | Graylog Security, entry | From $18,000/yr | Adds the security analytics and detection layer |
| Higher volume | Enterprise or Security, scaled | Negotiated on volume | Price rises with committed daily volume; no published per-GB step |
Four Graylog cost optimisations that genuinely work
Start on Graylog Open and upgrade deliberately
Defers licence spendGraylog Open is a genuinely capable, source-available log management platform, not a crippled trial. Many teams run production centralised logging on Open and only move to Enterprise or Security when they specifically need enterprise support, archiving, reporting, or the security analytics layer. Prove the deployment on Open first, then buy the paid edition for the features you can name.
Buy Enterprise, not Security, if you only need log management
~$3K/yr at entryThe step from Enterprise (from $15,000/yr) to Security (from $18,000/yr) buys the SIEM and security-analytics layer: detections, anomaly detection, threat intelligence, and SOC workflows. If your requirement is operational log management and compliance rather than active threat detection, Enterprise covers it and the Security premium is spend you do not need yet.
Right-size committed daily volume
Directly on licenceBoth paid editions are consumption-priced on daily log volume or annual consumption, so the licence tracks how much you commit to ingest. Filtering low-value logs (debug noise, health checks, duplicate sources) at the input stage before they count against your committed volume is the direct lever, exactly as with per-GB SIEMs.
Weigh self-managed infrastructure against Cloud
Deal-dependentSelf-managed Graylog means you run the OpenSearch and MongoDB backend and carry the ops burden, but you avoid the managed-cloud premium. Graylog Cloud removes that operational cost at a price set through sales. For teams with platform engineering capacity, self-managed Enterprise is usually cheaper all-in; for lean teams, Cloud can be the better total cost once ops time is counted.
When Graylog is the right SIEM
Graylog wins for teams that want strong centralised log management with a clean, affordable path into security analytics. The free Open edition lets you prove the platform in production, the paid editions start at published five-figure entry points rather than opaque six-figure quotes, and Graylog Security adds a real SIEM layer without changing platforms. It fits mid-market SOCs, log-management-first engineering teams, and organisations that value a source-available foundation and predictable upgrade economics.
Graylog is less compelling at the very top of the volume range, where hyperscale cloud-native telemetry and the deepest threat-hunting workloads favour security data lakes and the largest enterprise SIEMs, and where the consumption pricing above the entry point is negotiated rather than transparent. If your requirement is enormous ingest with advanced analytics and a mature app ecosystem, weigh Graylog against Splunk, Sentinel, and Chronicle; if it is capable, cost-controlled logging and SIEM for a mid-market estate, Graylog is often the most economical serious option.