Most of the Falcon platform is sold per device, but four module families use other units. Falcon Next-Gen SIEM is licensed on the volume of data ingested and the length of retention.[1] Charlotte Agentic SOAR uses credit-based pricing.[4] Falcon Next-Gen Identity Security is licensed per active identity.[5] Falcon Cloud Security is sold as packages priced by custom quote.[6] Under the CrowdStrike Terms and Conditions, each Order states the Offering quantity in CrowdStrike’s applicable license metrics.[8] The ingestion and credit metrics belong to the consumption family described in subscription and consumption licensing. The active-identity metric is a user-based count comparable to those in named user licensing.
Editions
| Module | Editions or packages named by CrowdStrike | Licensing basis |
|---|---|---|
| Falcon Next-Gen SIEM | Next-Gen SIEM; 10GB/day tier for Falcon Insight XDR customers[1] | Ingestion volume and retention[1] |
| Charlotte Agentic SOAR | Charlotte Agentic SOAR Essentials; Charlotte Agentic SOAR[4] | Credits[4] |
| Falcon Next-Gen Identity Security | Falcon Identity Threat Detection; Falcon Identity Threat Protection[5] | Active identity[5] |
| Falcon Cloud Security | Proactive Security; Cloud Detection and Response; CDR with Containers; CDR with Managed Containers; CNAPP; CNAPP with Containers[6] | Custom quote[6] |
Metrics
| CrowdStrike term | Catalog row | Definition |
|---|---|---|
| Data ingestion volume and retention | Data ingestion volume | Licensing is “based on data ingestion volume and the length of retention”.[1] The free tier is expressed in GB per day.[1] |
| Credit | Charlotte Agentic SOAR credit | “Flexible, credit-based pricing to power agentic actions across your environment.”[4] |
| Active identity | Active identity | “Active identities are accounts that have authenticated in the last 90 days”.[5] |
| Endpoint | Endpoint | Any physical or virtual device, including containers and virtual machine images.[8] Used for the sensor-based modules that feed these products. |
Counting / floors
Next-Gen SIEM
Ingestion and retention (FAQ dated 2024-10-21). Next-Gen SIEM licensing is based on data ingestion volume and the length of retention. Customers can scale the license and buy additional data capacity when needed.[1] Default retention is 7 days and can be extended up to 36 months with the appropriate licensing.[1] Catalog proof: Next-Gen SIEM licensed on ingestion volume and retention.
Falcon data is not counted (as retrieved 2026-09-26). Data from licensed Falcon modules, including endpoint, identity, cloud and other Falcon telemetry, is available in Next-Gen SIEM without additional ingestion charges.[2] Only third-party data consumes the purchased capacity. Catalog proof: Falcon module data carries no additional ingestion charge.
10GB/day tier. All Falcon Insight XDR customers with a dedicated CID can ingest up to 10GB of third-party data per day at no additional cost.[1] Falcon Enterprise is one bundle that includes Falcon Insight XDR.[9] Data above the daily limit is not ingested unless the customer has an extended subscription, so the tier does not create overage charges.[1] The tier’s limits are the 10GB daily cap, 7-day retention, and no access to premium features such as correlation rule templates and third-party Falcon Fusion SOAR actions.[1] Catalog proof: 10GB per day of third-party data for Falcon Insight XDR customers.
Retention after termination. Under the Terms, Customer Data is deleted in line with the data retention period the customer bought. Before termination the customer may download Customer Data available under its purchased Products and retention period.[8]
Charlotte Agentic SOAR
Credits (as retrieved 2026-09-26). Charlotte Agentic SOAR can be bought standalone or is included in Falcon Next-Gen SIEM. For Next-Gen SIEM customers, the credit allotment is based on data ingestion.[4] Falcon Fusion SOAR is subject to a fair usage policy.[4] Charlotte Agentic SOAR Essentials excludes Charlotte AI’s Detection Triage agent and Response Agent. Existing customers can activate it from the Falcon console, and only a user with the Falcon administrator role can opt in.[4] Essentials has a “limited” workflow engine, meaning named connectors; the full edition adds premium third-party connectors.[4] Credit prices and per-action consumption rates are not published. Catalog proof: Charlotte Agentic SOAR is credit-based; SIEM allotment follows ingestion.
Identity protection
Active identities (as retrieved 2026-09-26). Falcon Identity Threat Detection and Falcon Identity Threat Protection are each licensed per active identity. An active identity is an account that has authenticated in the last 90 days. Human and service accounts both count. Hybrid identities synced across on-premises and cloud directories are counted only once.[5] Catalog proof: Identity Security counts accounts authenticated in the last 90 days.
The count is taken from authentication activity, not from the size of the directory. Disabled or dormant accounts that have not authenticated for 90 days drop out of the count, while service accounts in active use add to it. The pricing page does not say which authentication events count, or how the 90-day window is measured at order and renewal time. Identity Threat Protection also sets the higher coverage tier of the Falcon Complete Limited Warranty, $2,000,000 instead of $1,000,000 for EDR only.[10]
Cloud security
Quoted packages. The Falcon Cloud Security pricing page offers six packages and asks for a custom quote. It publishes no metric or price.[6] CNAPP includes the features of Proactive Security and Cloud Detection and Response. The “with Containers” packages add container and Kubernetes protection, and the Managed Containers package covers containers managed by the cloud service provider.[6] Catalog proof: Falcon Cloud Security sold as quoted packages.
Virtualization & partitioning
The Terms and Conditions define an Endpoint as any physical or virtual device, and name containers and virtual machine images.[8] Falcon Cloud Security combines agent-based and agentless protection, including agentless snapshot scanning for workloads where an agent cannot be installed.[7] The retrieved pages do not say whether agentless coverage is licensed differently from sensor-protected workloads. The quote defines that. Catalog proof: Endpoint includes virtual machines, containers and VM images.
Cloud / BYOL
Not applicable in the bring-your-own-license sense. All four module families are CrowdStrike-hosted services, and the customer does not deploy them on its own cloud infrastructure. Falcon Cloud Security protects workloads across all major clouds.[7] For bring-your-own-license rules on hyperscalers in general, see cloud BYOL.
Programs
- Falcon Flex. CrowdStrike positions Flex as the procurement route for Next-Gen SIEM, with an upfront commitment and flexible licensing for additional offerings and services.[3] See CrowdStrike Falcon Flex.
- Managed service. Falcon Complete Next-Gen MDR provides 24/7 expert support and full remediation, with coverage across third-party data sources.[3] See CrowdStrike Falcon Complete and service provider licensing.
Out of scope
- Falcon LogScale and the legacy Humio self-hosted product. The Humio self-hosted terms list data ingested or searched and number of users among their example metrics, but they are separate from the Falcon Terms and Conditions.[11]
- Prices for ingestion capacity, retention packages, credits, active identities and cloud security packages, none of which CrowdStrike publishes.
- Data residency, GovCloud and FedRAMP offerings.
- Exposure management, data protection and other modules without a public licensing statement.