# Next-gen SIEM changes the engine, not the bill

> Next-gen SIEM swaps the storage engine and ships the detection content. The invoice still follows your log volume.

Source: https://fmcybersecurity.com/en/insights/endpoint/what-next-gen-siem-is/
Locale: English
Other locale: https://fmcybersecurity.com/insights/endpoint/hva-er-next-gen-siem/

## Metadata

- Date: 2026-08-07
- Author: kenny-le
- Topic: endpoint
- Format: article
- Partner: crowdstrike

The "next-gen" in next-gen SIEM is a claim about the storage engine and the detection content. It is not a claim about the invoice. You still pay by the gigabyte, and the gigabytes still come from whatever you decide to log.

I run the log-source inventory on the CrowdStrike Falcon onboardings FM CyberSecurity delivers. Four of the last five customers arrived with a SIEM question. In all four, the question underneath was a budget question nobody had priced yet.

**TL;DR:** Next-gen SIEM means index-free storage, detection rules written by the vendor, and the vendor's own telemetry included instead of metered. What it does not mean is a new cost driver. Ingest volume and retention length still set the price, so the SIEM decision is a log-source decision first.

## What the next-gen label is claiming

Next-gen SIEM means three things: index-free storage, detection content shipped by the vendor, and the vendor's own security telemetry included rather than charged per gigabyte.

The previous generation built an index at write time. You sized appliances for it, you paid for the indexing, and then you wrote your own correlation rules on top. CrowdStrike's [Falcon Next-Gen SIEM](/en/products/crowdstrike/next-gen-siem/) drops the write-time index and searches the raw store instead. CrowdStrike states this gives "up to 150x faster search compared to legacy SIEMs and petabyte scale ingestion" ([CrowdStrike log management](https://www.crowdstrike.com/en-us/platform/next-gen-siem/log-management/)).

Treat the multiple as a vendor benchmark, not a promise about your data. The architectural point holds regardless: search cost moved from write time to read time, which is why the ingest meter is now the thing you negotiate.

## Why ingest volume, not seat count, drives the bill

CrowdStrike licenses Falcon Next-Gen SIEM on data ingestion volume and retention length, not on users or endpoint count ([CrowdStrike Next-Gen SIEM FAQ](https://www.crowdstrike.com/en-us/blog/falcon-next-gen-siem-top-faqs/), October 2024).

Falcon Insight XDR customers get 10GB per day of third-party data ingestion at no extra cost, with over 100 pre-built integrations ([CrowdStrike free third-party data ingest](https://www.crowdstrike.com/en-us/platform/endpoint-security/free-third-party-data-ingest/)). Above that line you are on a subscription, and the subscription tracks what you send.

In one proof of value I sat in on, moving the firewall from summary logging to full session logging took daily third-party ingest from under 2 GB to over 9 GB in an afternoon. Not one new detection came out of the extra 7 GB. That is the whole economics of a modern SIEM in one console change.

So pick log sources per detection question, not per system. Write down the question first ("would we see a VPN login from a country we do not operate in"), then route only the fields that answer it. Filtering at the pipeline, before ingest, is cheaper than filtering in a search bar afterwards.

## Retention is where the quote doubles

Retention is the second half of the licence, and it is the half that decides whether the project is affordable.

CrowdStrike's stated default is 7 days, extendable with the appropriate licensing (Next-Gen SIEM FAQ, October 2024). The current product page describes access to historical and real-time telemetry "for up to 5 years, or store data externally and query on-demand with federated search". The ceiling has moved between releases, so confirm the terms on your quote rather than on a blog post, mine included.

Then read the clause that made you ask. In scoping calls last year, the retention number the customer quoted me came from a contract or a sector rule every single time. Not once did it come from an investigation they had run and lost for want of old logs. Those clauses usually say retain. They rarely say searchable in minutes. Hot search for a year and cold archive for a year are different products at different prices, and the cheaper one often satisfies the auditor.

## Detection content decides more than the query engine

The query engine is what gets demoed. The detection content is what decides whether the SIEM finds anything in month two.

CrowdStrike says Falcon Next-Gen SIEM ships "more than 1,000 correlation rule templates" covering cloud platforms, endpoints, networks, identity systems and third-party applications ([CrowdStrike, 29 September 2025](https://www.crowdstrike.com/en-us/blog/boost-soc-detection-content-correlation-rule-template-discovery-dashboard/)). The console also has a view that matches available templates against the sources you have already onboarded, which is the number that matters to you.

Ask the vendor how many rules cover the sources on your list, not how many rules exist. A thousand templates and no coverage for your payment platform buys you an empty console with fast search. This is the single question I would put in a SIEM evaluation ahead of anything about query syntax.

## When endpoint telemetry answers the question first

For most Norwegian mid-market stacks, endpoint and identity telemetry already answers the questions a SIEM gets bought to answer.

We wrote up the buy-or-do-not-buy decision separately in [what SIEM is, and when an SMB needs one](/en/insights/endpoint/what-siem-is-and-when-smbs-need-one/). The point here is narrower. Next-gen changes what a SIEM costs to run and what it detects out of the box. It does not change whether you needed one, and a tuned EDR still covers laptops and sign-ins in more depth than a log pipeline does. The [difference between EDR and antivirus](/en/insights/endpoint/edr-and-antivirus-what-the-difference-is/) is the same argument one layer down.

One 2026 change is worth knowing if you are weighing a swap. On 23 March 2026 CrowdStrike announced that Falcon Next-Gen SIEM ingests and correlates Microsoft Defender for Endpoint telemetry "with no Falcon sensor required" ([CrowdStrike press release](https://www.crowdstrike.com/en-us/press-releases/crowdstrike-unveils-falcon-next-gen-siem-support-for-microsoft-defender-for-endpoint/)). The SIEM decision and the sensor decision are no longer the same decision.

## What managed adds, and who is on the bridge

Managed means somebody reads the alert at 03:00. That is the difference the commercial searches are asking about, and it is the expensive half of any SIEM.

CrowdStrike Falcon Complete Next-Gen MDR is the managed layer here, sold to larger SMBs and enterprises. CrowdStrike's own analysts staff the 24/7 bridge. When the service is bought with coverage across third-party data sources, that team analyses third-party logs and correlates incidents across those sources alongside Falcon's own telemetry (Next-Gen SIEM FAQ, October 2024).

FM CyberSecurity's job on that service is onboarding, detection tuning and local escalation in Norwegian, inside working hours you can reach. We are a certified [CrowdStrike](/en/partners/crowdstrike/) partner and we run the platform end to end rather than passing the ticket on. What we push hardest on is the part that sets your bill: sizing the log sources before the subscription is signed, not after the first invoice.

Start with one week of measured third-party ingest at your real logging levels. Then you are negotiating with a number instead of a quote.

## If this resonates

- Read [what SIEM is, and when an SMB needs one](/en/insights/endpoint/what-siem-is-and-when-smbs-need-one/) for the buy decision, and [what the Falcon platform is](/en/insights/endpoint/what-crowdstrike-falcon-is-the-platform-behind-modern-mdr/) for the layers underneath.
- Forward this to whoever signs the log-retention clauses in your customer contracts. That is usually your contract owner, not your IT manager.
- Talk to Kenny for a 30-minute review of your log sources and what they would cost to ingest. See [FM CyberSecurity's managed detection and response](/en/services/mdr/).

## FAQ

### What makes a SIEM next-gen?

Three things. It stores logs without building a write-time index, so ingest is not throttled by indexing. It ships vendor-written detection content instead of leaving every correlation rule to you. And it includes the vendor's own security telemetry in the platform price rather than metering it. Pricing still follows ingest volume and retention length, which is the part the label does not change.

### Is CrowdStrike a SIEM?

CrowdStrike Falcon is an endpoint, identity and cloud security platform, and Falcon Next-Gen SIEM is the SIEM module inside it. It takes third-party logs from firewalls, identity providers, SaaS and network gear, and runs detections on them in the same back end as the endpoint telemetry. For teams already on Falcon, that removes the integration work of stitching a separate SIEM to a separate EDR.

### What does managed next-gen SIEM include?

With CrowdStrike Falcon Complete Next-Gen MDR bought with third-party data coverage, CrowdStrike's analysts monitor and triage around the clock and correlate incidents across your third-party log sources. FM CyberSecurity handles onboarding, detection tuning and local escalation. What managed does not do is decide your log sources for you. That scoping still sets the licence, and it is worth doing before you sign.

*Drafted with AI assistance, reviewed and edited by Kenny Le and the FM CyberSecurity editorial team.*

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
