Convert events per day into average, peak and licensable EPS, with headroom and a twelve-month growth projection.
Dividing daily events by 86,400 gives the flat average, which is the number nobody should size on: log volume tracks human and business activity, so the busiest hour typically carries 2–3× the daily mean. Multiplying by the peak factor gives the rate the pipeline must actually sustain, and adding headroom gives the licensed figure. SIEM licences and indexer counts are sold against EPS or GB/day, and a platform sized on the daily average will drop events or queue them for hours exactly when an incident is unfolding.
SIEM EPS
Average EPS = events per day ÷ 86,400. Peak EPS = average EPS × peak factor. Licensed EPS = peak EPS × (1 + headroom).
Twelve-month projection
Projected peak EPS = peak EPS × (1 + annual growth) × (1 + headroom).
Average EPS = events per day ÷ 86,400. Peak EPS = average EPS × peak factor. Licensed EPS = peak EPS × (1 + headroom). Dividing daily events by 86,400 gives the flat average, which is the number nobody should size on: log volume tracks human and business activity, so the busiest hour typically carries 2–3× the daily mean. Multiplying by the peak factor gives the rate the pipeline must actually sustain, and adding headroom gives the licensed figure.
SIEM licences and indexer counts are sold against EPS or GB/day, and a platform sized on the daily average will drop events or queue them for hours exactly when an incident is unfolding.
This calculator takes 5 inputs: Events per day (all sources), Peak-to-average factor, Licensing headroom, Annual event-volume growth, Log sources in scope. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
License on peak plus headroom. Most vendors meter a rolling daily or monthly volume rather than instantaneous EPS, so average volume drives the bill — but the hardware, ingest pipeline and queue depth must survive peak, and an under-sized ingest tier turns a busy morning into a detection gap.
Yes. Cloud audit trails, EDR telemetry and Kubernetes logging routinely add 20–40% a year without any new business activity. Re-measure quarterly and treat any single estimate as valid for one budget cycle only.