SecOps Hub

Free tools for Google SecOps
SIEM & SOAR deployments

Size your SecOps ingestion, check parser coverage for your log sources, and generate YARA-L detection rules and SOAR playbooks — all in minutes, no signup required.

GB/day ingestion estimator
700+ parser coverage database
YARA-L rules
SOAR playbook templates

SecOps SIEM Sizing Calculator

Estimate your daily log ingestion volume, recommended SecOps tier, and monthly cost before you commit to a deployment. Figures are indicative — actual volumes depend on your logging verbosity configuration and SecOps contract terms.

Infrastructure

Application Categories

Enter the number of instances/nodes per category (0 if not applicable)

Web / API servers
Databases (SQL/NoSQL)
Identity / IAM (AD, LDAP)
Network devices (FW, VPN)
Kubernetes / containers
SaaS apps (Workspace, M365)
Payment / PCI systems
Legacy / mainframe

Estimate

Daily Ingestion

6.6 GB/day

Standard tier range (≤100 GB/day)

Recommended Tier

SIEM + SOAR

SecOps Standard

SIEM + SOAR platform. No curated detections included — customers bring their own detection rules. Supports custom threat intelligence feeds (STIX/TAXII, CSV). Best for organisations with a mature detection engineering team.

SecOps SIEM (petabyte-scale storage)
SecOps SOAR (playbook automation)
Custom YARA-L detection rules
Bring-your-own threat intel (STIX/TAXII, CSV)
UDM normalisation for 700+ log sources
No curated detection rules included
No built-in Google Threat Intelligence

Storage Cost Estimate

Log storage (365 day retention)~$54/mo
Chronicle platform licenceQuote-based

Chronicle ingestion pricing is contract-based and depends on volume commitment, tier, and region. Storage costs above are indicative (~$23/TB/month Coldline equivalent). Contact Google Cloud or a partner for a full licence quote.

2.35 TB stored over 365 days at 6.6 GB/day

Volume Breakdown

Endpoints2.00 GB/day (30%)
Servers0.60 GB/day (9%)
Cloud projects4.00 GB/day (61%)
Applications0.00 GB/day (0%)

Need a detailed sizing report?

We'll review your architecture, validate log sources, and produce a SecOps deployment plan with accurate cost modelling.

SecOps Tier Comparison

CapabilityStandard
SIEM + SOAR
Enterprise
+ Google Threat Intel
Enterprise+
+ Mandiant Intel
SecOps SIEM
SecOps SOAR
Custom YARA-L rules
Bring-your-own threat intel
Curated detection rules
Google Threat Intelligence
Applied Threat Intel matching
Mandiant Threat Intelligence
Mandiant Advantage profiles
Zero-day & vuln intelligence

Pricing is usage-based and contract-negotiated with Google Cloud. Contact us for a detailed quote.

Ready to deploy SecOps?

CloudXero delivers end-to-end SecOps SIEM and SOAR deployments — from log source onboarding and custom parser development to YARA-L rule tuning and SOAR playbook automation.

We use analytics cookies to understand how visitors use CloudXero and improve the experience. No personal data is sold or shared with third parties.