# The Cost of Keeping Everything ## SIEMs charge by volume, so cost decides what gets kept instead of risk Security tools are priced on ingestion. Every extra source and every traffic spike lands straight on the licence bill. Teams respond the only way they can: they sample, drop and shorten retention. The deck's figures for what that looks like: | Measure | Stated position | | --- | --- | | Volume in carrier and enterprise networks | millions of events per second | | DNS logs dropped under volume pressure | 40 to 60% | | Typical searchable retention | ~30 days | > [!warning] The part that hurts later > Sampling usually happens at peak, which is exactly when unusual traffic appears. The data most worth having is the data most likely to be cut. The chain the deck walks through: cost caps force sampling → an incident lands in a sampled-out window → reconstruction takes days rather than hours because the query-level evidence was never kept → an auditor later asks for records past the retention window and they do not exist. A budget decision turns into a compliance finding. ## Why it matters This is the buying trigger and it is a budget that already exists. Nobody has to be convinced that telemetry is valuable. They have to be shown they can keep it without paying ingestion rates for the privilege. It also explains why the entry conversation is cost rather than security. Cost has a number attached, a line item and an owner. Security value is real but harder to price at the point of purchase. ## Related - [[Red Onion MOC]] - [[Separating Capture Economics from Analytics Economics]] - [[Position Next to SIEM and Data Lake]] - [[SIEM - Security Information and Event Management]] - [[Why businesses pay for cybersecurity]]