Huntress Managed SIEM collects and correlates logs from endpoints, firewalls, cloud and SaaS applications and identity systems, and is billed by data source rather than by data volume. Huntress Managed Security Awareness Training (SAT) provides managed learning programmes and phishing simulation, and is priced per learner.[2] SIEM licensing is more elaborate than the other Huntress products because it combines a count of sources with a pooled volume allocation, a retention schedule and a mechanism that favours truncating stored data over charging for overage. This article sets those rules out from the Huntress support documentation and pricing page.
Managed SIEM: units and price
The pricing page lists Managed SIEM at an MSRP of USD 4.00 per source per month, with an example of USD 3.50 per source at 100 sources, and describes “simple per-data-source billing and pooled storage allocation across all sources” with extended retention as an option.[2] The support documentation defines a Data Source as “any system or service that is generating data captured by the SIEM”, from an endpoint to a hardware device to a third-party SaaS application such as Okta or Duo, and notes that a single machine may have several sources, for example a Windows endpoint collecting event logs, antivirus logs and web server logs.[1]
How data sources are counted and billed
When a partner subscribes, it chooses a tier that sets the minimum number of data sources it commits to monthly. As sources are added, either by adding endpoints that capture Windows event logs or by connecting SaaS systems, the count rises, and sources above the commitment are charged “in the same way that we calculate and charge for endpoints”.[1] The calculation is a snapshot at the end of the monthly subscription period:
- If the number of sources is at or below the commitment, the customer is billed for the minimum.
- If it is above the commitment, the customer is billed for the total number of sources at the price per source of its tier.[1]
Billable log sources are those that have sent data in the last 30 days; after 30 days of inactivity a source is listed as inactive and no longer counts.[1] The entitlements article adds that billable SIEM sources are all SIEM data sources except free sources, which are currently ITDR logs when ITDR is enabled and set up.[3] SIEM can be disabled per organisation, in which case collection from billable sources stops, existing data is retained as per the contract, and new billable sources cannot be added.[3]
The Data Pool
Each data source is “allocated and billed for 10 GB/mo of ingestion even if the device uploads less than the threshold”.[1] Ingestion is measured as the uncompressed data size uploaded to cold storage and excludes filtered data.[1] The volume is pooled: at the start of a subscription the Data Pool is set from the annual committed volume, “monthly committed data sources times 10 GB times 12 months”, and when a source above the commitment is charged its remaining volume is added to the pool.[1] The pool is consumed each month by ingestion, in order of the earliest expiry of the allocation, and “all data allocations will expire after 12 months”.[1]
The article works two examples. A partner committed to 100 data sources has a 1,000 GB pool; in a month with 120 sources and 900 GB ingested, 200 GB is added to the pool and 900 GB consumed, leaving 300 GB for later months. If ingestion were 1,100 GB in the same situation, 200 GB is added and 1,100 GB consumed, leaving 100 GB.[1] A month above the monthly allocation therefore does not necessarily incur additional fees; it depends on the remaining pool.
Smart Filtering
Huntress applies “Smart Filtering” to discard data that it judges to have no security value. Filtered data is not retained in any Huntress systems and does not count towards ingestion; where Huntress cannot determine the type of data, or the partner has asked to disable filtering, all ingested data counts towards the source threshold.[1] The ingested volume per source therefore depends on how well each log type is recognised, which a licence manager should check when comparing the pool balance with the volume reported by the source system.
Predictable Billing
Huntress calls the mechanism for smoothing overage Predictable Billing. When the pool limit is reached, Huntress “will continue to collect data” but begins to truncate the oldest stored data, so a customer that ingests faster than committed gets a shorter retention window rather than a higher bill.[1] The example given is a partner with 10 sources at 10 GB: a 100 GB monthly allocation and a 1,200 GB pool, which at 200 GB per month is exhausted six months into the year and leaves a continuous six-month retention period with no extra charge.[1] Adding sources above the minimum raises the monthly bill at the same per-source rate as the committed minimum.[1]
For customers that regularly ingest more than expected, the article offers two routes: raising the commitment at the current tier for the rest of the subscription period, or moving to the next higher tier by replacing the existing 12-month subscription with a new one at the new tier with a cheaper per-GB price.[1]
Retention and extended retention
Partner data is held in active storage for 1 month and in cold storage for 12 months, with the first month in both, and total storage not exceeding 12 months; the first month’s unfiltered data is searchable in the SIEM console, and cold data may be “rehydrated” for search and compliance.[1] Huntress reserves the right to charge USD 1 per GB of rehydrated data beyond an included 500 GB of rehydration per year, while stating that it has no intention of charging partners to rehydrate data.[1]
An extended retention add-on SKU stores logs for 90 days active and 7 years cold, at a flat rate per log source applied by organisation, in addition to standard billing. It does not change the 10 GB per source per month allocation; it extends searchable storage from 1 to 3 months and cold storage from 1 to 7 years.[1] At the end of a non-renewing term logs are retained for 30 days and made available for download so that the customer can migrate data away.[1] The article also states that logs are immutable and that Huntress may remove limited logs only on a written, validated request from customer leadership in extenuating circumstances.[1]
Managed Security Awareness Training
The pricing page lists Managed SAT at an MSRP of USD 2.08 per learner per month, with an example of USD 1.75 at 100 learners, and describes fully managed learning programmes and phishing simulation, automated reporting, customisable training content and rapid onboarding.[2] The documents read do not define how a learner is counted (for example whether an inactive user or a user in several client organisations counts), so the quantity on the Order and the learner list in the portal are the working records. SAT is purchased and managed at the account level, not per organisation, and inherits user grouping from the identity provider during integration.[3] The Terms of Service note that some services use third-party images and templates to simulate phishing attacks and that Huntress makes no claim to that third-party intellectual property.[4]
Through an MSP there are no Huntress-required minimum seat counts; through a reseller or direct, the pricing page states a Huntress-required minimum of 50 seats per product, which applies to SAT as to the other products.[2]
What a licence manager should check
- The SIEM tier and committed number of data sources on the Order, and the monthly snapshot count of billable sources.
- The Data Pool balance and expiry dates of allocations, since unused volume expires after 12 months.[1]
- Whether any source type has no Smart Filtering, which increases ingested volume.
- Whether extended retention is on the Order where more than 12 months of logs are required.
- The learner count against the SAT quantity and the organisations to which learners belong.
Out of scope
This article does not cover pricing for tiers beyond the MSRP example, the logging compliance commitments beyond immutability, or the technical content of the SIEM and SAT products. It relies on support articles that show relative update ages rather than dates.