Splunk vs Google SecOps (Chronicle) cost: 2026 comparison
Independent head-to-head cost comparison. Per-GB Splunk plus its mandatory Enterprise Security layer versus Chronicle's GB data-cap pricing at five log-volume bands, and where the ES licence, Splunk Enterprise Agreement discounts, and Chronicle's quote-only US pricing decide the winner. Splunk rates reproduced from published reseller list cards; Chronicle from the UK G-Cloud listing. Updated August 2026.
Per-GB plus ES versus an all-in data cap
Splunk and Chronicle both ultimately track data volume, but they package it very differently, and the difference is what makes Splunk the more expensive option on a like-for-like SIEM basis. Splunk Cloud meters per gigabyte ingested, roughly $1,000 per GB per day per year at a typical 50 GB per day deployment, tapering toward $665 at very high volume and rising toward $1,620 at single-digit volumes. That per-GB line buys ingest and search, but not a SIEM. To run detections, risk-based alerting, and investigation workflow you add Splunk Enterprise Security, whose reseller per-GB rate sits close to the base ingest rate, so ES roughly doubles the Splunk licence. Chronicle (now Google SecOps) prices on a single GB data cap sold in annual packages, effectively about £2,000 per terabyte per year on the UK G-Cloud listing, with its analytics included in that number.
The practical effect is that the honest Splunk column has to include ES, and once it does, Chronicle undercuts Splunk at every volume band. At 50 GB per day Splunk plus ES runs roughly $100K to $130K against Chronicle at about $46K; at 200 GB per day it is roughly $300K to $400K against about $184K; at 1,000 GB per day roughly $1.3M to $1.6M against about $920K. The gap is structural: Splunk charges separately for the ingest and for the content that makes the platform a SIEM, while Chronicle folds both into one cap. The two real qualifiers pull in opposite directions and are covered below: Splunk grants 25 to 40 percent Enterprise Agreement discounts at scale, and Chronicle's US pricing is quote-only, so its published figure converts the UK G-Cloud rate rather than a US rate card.
None of that makes Splunk the wrong choice. The premium buys genuine capability: Splunk's search performance at scale, the maturity and breadth of the Enterprise Security content library, IT Service Intelligence, the premium app ecosystem, and self-managed on-premise deployment for environments that require it. The buying decision turns on whether those capabilities are worth roughly double the licence, on whether deep existing SPL content and skills make migration costly, and on platform ecosystem, not on a single headline number.
Same environment, both vendors
| Profile | Splunk + ES (SIEM config) | Chronicle data cap | Cheaper on licence | Note |
|---|---|---|---|---|
| 5 GB/day | ~$16K-$28K | ~$5K-$8K | Chronicle | Splunk base ($8K-$14K) doubled for ES; Chronicle package minimum sets its floor |
| 50 GB/day | ~$100K-$130K | ~$46K | Chronicle | SIEM use needs ES, which roughly doubles the Splunk licence |
| 200 GB/day | ~$300K-$400K | ~$184K | Chronicle | Splunk per-GB rate tapers but the ES layer compounds with volume |
| 500 GB/day | ~$730K-$900K | ~$460K | Chronicle | Splunk EA discount (25-40%) narrows but rarely closes the gap |
| 1,000 GB/day | ~$1.3M-$1.6M | ~$920K | Chronicle | At scale Splunk EA discounting and Chronicle cap sizing set the real number |
Annual licence figures, before negotiated multi-year discounts. The Splunk column is a transparent model: the base Splunk Cloud licence (reseller list, roughly $665 to $1,620 per GB per day per year, checked August 2026) doubled to add Enterprise Security, per Splunk's own reseller ES rate. The Chronicle column converts the UK G-Cloud published price of about £2,000 per terabyte per year at roughly $1.26 per pound; that G-Cloud listing is the only openly published Chronicle unit price, and US pricing is quote-only, so treat the dollar figures as indicative rather than a US rate card. Splunk grants 25 to 40 percent off list on Enterprise Agreements above $500K. Excludes staffing, storage, integration, and one-time migration; always obtain a vendor quote.
When Splunk genuinely wins
- +Mature SOCs that need Splunk's search performance and the depth of the Enterprise Security content library, IT Service Intelligence, and the premium app ecosystem, where the analytics capability justifies the premium
- +Organisations with deep SPL (Search Processing Language) skills and existing Splunk content who would pay the full migration cost to leave and lose years of tuned detections
- +Environments needing self-managed on-premise deployment for data residency or air-gap requirements, where Splunk Enterprise runs on your own hardware and Chronicle's Google-Cloud data plane does not fit
- +Buyers who value a published, benchmarkable reseller rate card and predictable per-GB math over Chronicle's quote-only US pricing, where only the UK G-Cloud listing is public
- +Teams already standardised on Cisco security tooling (Splunk has been a Cisco company since the $28 billion acquisition closed), where platform consolidation offsets the licence premium
When Google SecOps (Chronicle) genuinely wins
- +Cost-led buyers at any meaningful volume, where Chronicle's all-in data-cap price undercuts Splunk plus the mandatory Enterprise Security licence at every band from 50 GB per day upward
- +High-log-volume environments per unit of analyst headcount, where Google sizes the bundled data cap generously and the effective per-terabyte rate stays low
- +Organisations wanting bundled Mandiant threat intelligence (Chronicle Enterprise) or Mandiant Hunt (Enterprise Plus) without a separate threat-intel subscription on top of the SIEM licence
- +Google Cloud-native organisations where Chronicle's native integration and BigQuery-backed retention matter, and there is no on-premise requirement to satisfy
- +Buyers who want a SIEM whose analytics are included in the headline price rather than a platform (Splunk) that is a log store until you add the ES content layer that makes it a SIEM