The problem is assuming every log needs to be processed, retained and queried in exactly the same place.
Many security platforms price some combination of ingestion, storage, processing, search or workload consumption. Ingestion-based pricing remains common, although structures vary considerably between vendors. At enterprise scale those economics matter: a security organisation ingesting tens or hundreds of terabytes each day experiences the impact of a small unit-price change very differently from a smaller SOC.
This creates the SIEM cost paradox we explored in Issue 12:
Better visibility requires more security evidence, but indiscriminately sending more evidence into the highest-cost tier can make visibility financially unsustainable.
There is a structural reason ingestion pricing bites so hard, and it is worth naming precisely. Ingestion pricing couples two unrelated things: the value of a log at the moment it arrives, and the cost of keeping it available months later. Most security telemetry has a steep, short value curve for detection and a flat, long value curve for investigation. Pricing both through the same tier forces a decision that is necessarily wrong for one of them.
The answer is not simply “collect less.” That creates investigation gaps, and, as Berlin and Thomson Reuters both illustrate, the gap does not become visible until the moment it is most expensive.