Editorially independent. Sponsors are disclosed and never influence our analysis.
Independent research, supported bycriblSponsor
Compare / Splunk vs Google SecOps

Splunk vs Google SecOps (Chronicle) cost: 2026 comparison

Independent head-to-head cost comparison. Per-GB Splunk plus its mandatory Enterprise Security layer versus Chronicle's GB data-cap pricing at five log-volume bands, and where the ES licence, Splunk Enterprise Agreement discounts, and Chronicle's quote-only US pricing decide the winner. Splunk rates reproduced from published reseller list cards; Chronicle from the UK G-Cloud listing. Updated August 2026.

Splunk
Per-GB + ES
ES roughly doubles the licence
Chronicle
GB data cap
~£2,000/TB/yr, analytics included
At 50 GB/day
~$46K vs ~$115K
Chronicle vs Splunk+ES
Decider
ES vs bundle
Separate SIEM licence vs all-in cap

Per-GB plus ES versus an all-in data cap

Splunk and Chronicle both ultimately track data volume, but they package it very differently, and the difference is what makes Splunk the more expensive option on a like-for-like SIEM basis. Splunk Cloud meters per gigabyte ingested, roughly $1,000 per GB per day per year at a typical 50 GB per day deployment, tapering toward $665 at very high volume and rising toward $1,620 at single-digit volumes. That per-GB line buys ingest and search, but not a SIEM. To run detections, risk-based alerting, and investigation workflow you add Splunk Enterprise Security, whose reseller per-GB rate sits close to the base ingest rate, so ES roughly doubles the Splunk licence. Chronicle (now Google SecOps) prices on a single GB data cap sold in annual packages, effectively about £2,000 per terabyte per year on the UK G-Cloud listing, with its analytics included in that number.

The practical effect is that the honest Splunk column has to include ES, and once it does, Chronicle undercuts Splunk at every volume band. At 50 GB per day Splunk plus ES runs roughly $100K to $130K against Chronicle at about $46K; at 200 GB per day it is roughly $300K to $400K against about $184K; at 1,000 GB per day roughly $1.3M to $1.6M against about $920K. The gap is structural: Splunk charges separately for the ingest and for the content that makes the platform a SIEM, while Chronicle folds both into one cap. The two real qualifiers pull in opposite directions and are covered below: Splunk grants 25 to 40 percent Enterprise Agreement discounts at scale, and Chronicle's US pricing is quote-only, so its published figure converts the UK G-Cloud rate rather than a US rate card.

None of that makes Splunk the wrong choice. The premium buys genuine capability: Splunk's search performance at scale, the maturity and breadth of the Enterprise Security content library, IT Service Intelligence, the premium app ecosystem, and self-managed on-premise deployment for environments that require it. The buying decision turns on whether those capabilities are worth roughly double the licence, on whether deep existing SPL content and skills make migration costly, and on platform ecosystem, not on a single headline number.

Same environment, both vendors

ProfileSplunk + ES (SIEM config)Chronicle data capCheaper on licenceNote
5 GB/day~$16K-$28K~$5K-$8KChronicleSplunk base ($8K-$14K) doubled for ES; Chronicle package minimum sets its floor
50 GB/day~$100K-$130K~$46KChronicleSIEM use needs ES, which roughly doubles the Splunk licence
200 GB/day~$300K-$400K~$184KChronicleSplunk per-GB rate tapers but the ES layer compounds with volume
500 GB/day~$730K-$900K~$460KChronicleSplunk EA discount (25-40%) narrows but rarely closes the gap
1,000 GB/day~$1.3M-$1.6M~$920KChronicleAt scale Splunk EA discounting and Chronicle cap sizing set the real number

Annual licence figures, before negotiated multi-year discounts. The Splunk column is a transparent model: the base Splunk Cloud licence (reseller list, roughly $665 to $1,620 per GB per day per year, checked August 2026) doubled to add Enterprise Security, per Splunk's own reseller ES rate. The Chronicle column converts the UK G-Cloud published price of about £2,000 per terabyte per year at roughly $1.26 per pound; that G-Cloud listing is the only openly published Chronicle unit price, and US pricing is quote-only, so treat the dollar figures as indicative rather than a US rate card. Splunk grants 25 to 40 percent off list on Enterprise Agreements above $500K. Excludes staffing, storage, integration, and one-time migration; always obtain a vendor quote.

When Splunk genuinely wins

When Google SecOps (Chronicle) genuinely wins

FAQ

Common questions

Which is cheaper for a mid-market organisation, Splunk or Google SecOps (Chronicle)?

Chronicle is materially cheaper on licence at mid-market scale, and the gap is structural rather than marginal. The reason is Enterprise Security: Splunk Cloud ingest at 50 GB per day is roughly $50K to $65K on the base licence, broadly comparable to other per-GB vendors, but a genuine SIEM deployment needs Splunk Enterprise Security, which on published reseller rate cards roughly doubles the licence to about $100K to $130K. Chronicle at the same 50 GB per day runs about $46K on its GB data cap, with analytics included. Without ES you are comparing a log-analytics platform against a full SIEM, which is not a like-for-like comparison. With ES, Chronicle undercuts Splunk by roughly half at this scale. The caveats are that Splunk figures are reseller list before a 25 to 40 percent Enterprise Agreement discount at high volume, and Chronicle's US pricing is quote-only, so the dollar figures convert the UK G-Cloud listing rather than a US rate card.

Does Splunk really need Enterprise Security to work as a SIEM?

For genuine SIEM use, effectively yes. Splunk Enterprise Security is the premium content layer that provides prebuilt detections, risk-based alerting, investigation workflow, and the threat intelligence framework. Without it, Splunk is a powerful log-analytics and search platform but not a SIEM in the detection-and-response sense. On published reseller rate cards the ES per-GB rate sits close to the base ingest rate itself, so adding ES roughly doubles the Splunk licence. That is why an honest Splunk-versus-Chronicle cost comparison has to include ES in the Splunk column: Chronicle bundles its analytics into the data-cap price, so leaving ES out would compare a SIEM against a log store.

Why is Chronicle so much cheaper than Splunk on paper?

Two structural reasons. First, Chronicle bundles its analytics into a single GB data-cap price (about £2,000 per terabyte per year on the UK G-Cloud listing), whereas Splunk charges separately for ingest and for the Enterprise Security content that makes it a SIEM, so the Splunk buyer pays twice on effectively the same data. Second, Google runs Chronicle on its own internal infrastructure (Borg, BigQuery, Spanner) where storage and indexing are cheap at Google scale, which lets Google package generous data caps at competitive per-terabyte rates. The honest qualifier is that cheaper on licence is not the whole decision: Splunk's search performance, the maturity and breadth of the ES content library, and self-managed on-premise deployment are real capabilities that a pure price comparison does not capture, and Chronicle's US pricing is quote-only so the published gap is indicative rather than a guaranteed US rate.

What does it cost to migrate from Splunk to Chronicle?

Splunk-to-Chronicle migration is moderately complex because the detection content models differ: Splunk uses SPL (Search Processing Language) and Chronicle uses YARA-L 2.0, so detections do not port cleanly. Migration of 100 to 200 detections typically runs $100K to $200K in professional services plus 4 to 6 months of calendar time. Where the annual licence saving is $150K or more, which is common once Enterprise Security is included in the Splunk figure, payback under 18 months makes the migration a clear positive return. Where the saving is smaller, or where years of tuned Splunk content and deep SPL skills would be lost, the migration is rarely worth it without a separate consolidation or strategic driver.

Do Splunk Enterprise Agreement discounts close the gap?

They narrow it but rarely close it. Splunk grants 25 to 40 percent off list on multi-year Enterprise Agreements above roughly $500K list value, and quarter-end is the right pressure point. But the Chronicle figure is also a list-style anchor that a US buyer would negotiate from a quote, so both sides move in a real negotiation. Because the Splunk premium is driven by the mandatory ES licence rather than by the ingest rate alone, a discount on the whole Splunk bill and a discount on the Chronicle cap tend to preserve the structural gap rather than erase it. The exception is very high volume with an aggressive Splunk EA, where a 40 percent discount on a $1.5M list can bring Splunk close to Chronicle's roughly $920K at 1,000 GB per day.

Updated 13 July 2026