Work out siem events per second instantly with clear inputs, formula shown and shareable results.
SIEM sizing starts from events per second by source class, because a workstation generates well under one event per second while a firewall or proxy generates tens. Peaks matter more than averages: incident response, mass authentication failures and scanning bursts routinely produce three times the baseline, and licensing to the average guarantees dropped events exactly when they are needed.
EPS sizing
average EPS = hosts x host EPS + network devices x network EPS; peak ~ 3 x average; licence to peak x 1.2
Authentication storms, malware outbreaks and vulnerability scans all multiply log rates simultaneously. Measured peak-to-average ratios of 2 to 5 are common in enterprise estates.
Firewall and proxy connection logs, followed by endpoint process telemetry and DNS. Filtering at the source is usually more effective than buying more capacity.