Cortex XSIAM · Sizing Research

Third-Party EDR Sizing
Research Deep Dive

The original 10,000-endpoint sizing research for SentinelOne, CrowdStrike, and Microsoft Defender, reproduced as captured, section by section against the comparisons on the EDR Telemetry Economics page.

Read this before quoting anything on this page. Every block marked Captured research, reproduced verbatim is the original assistant output preserved word for word, including its numbers. It is kept here as the provenance record behind the sizing conversation. Several of the SentinelOne per-OS figures could not be corroborated against vendor or practitioner sources and were deliberately removed from the EDR Telemetry Economics page for that reason. Each section closes with a short editorial note explaining how the captured figure reconciles with the tuned-filter ranges used on the live page. Quote the live page in front of a customer; quote this page only to show where a number came from.

Section 1 · Aligns to “SentinelOne Deep Visibility”

SentinelOne and XSIAM

Captured sizing research for a 10,000-endpoint SentinelOne estate ingested into XSIAM as a third-party EDR feed.

SentinelOne — 10,000 endpoints Captured research

Captured research, reproduced verbatim
what would it be the total amount of logs from a sentinel one customer using XSIAM SIEM ony daily they have around 10K endpoints

For a customer with 10,000 endpoints using SentinelOne with Cortex XSIAM, the daily log volume varies significantly depending on the operating system and the level of activity on the hosts.

Estimated Log Volume for 10,000 Endpoints

Based on standard SentinelOne Deep Visibility metrics, the total daily uncompressed data for 10,000 endpoints typically ranges from 2.8 TB to 5 TB per day for a standard Windows environment, depending on agent version and activity levels.

Endpoint TypeEvents Per Agent / DayData Per Agent / DayTotal (10,000 EPs)
Windows Agents (v22.3+)~90,000 events~180 MB*~1.8 TB / day
Windows Agents (v22.2-)~140,000 events~280 MB (Uncompressed)~2.8 TB / day
macOS Agents~140,000 events~280 MB (Uncompressed)~2.8 TB / day
Linux Agents (Standard)~500,000 events~1,000 MB*~10 TB / day
Linux Servers~4,000,000 events~8,000 MB*~80 TB / day

*Estimated based on the 280 MB / 140,000 event ratio provided for older versions and macOS.

Critical Sizing Considerations

  • XSIAM Licensing: In an XSIAM NG SIEM deployment where a customer retains their third-party EDR (like SentinelOne), all raw EDR logs ingested count toward the XSIAM Base Subscription daily GB/day total.
  • Variable Factors: Actual volume can fluctuate based on resource type (server vs. VDI), OS version, and specific SentinelOne data collection policies (e.g., granular Deep Visibility settings).
  • Data Savings Opportunity: If the customer replaces SentinelOne with native Cortex XDR agents, these logs are exempt from the daily GB/day base ingestion total, which can significantly lower overall licensing costs.
  • Accurate Forecasting: To get precise figures before a proposal, it is recommended to review the current ingestion volume in the customer's existing SIEM or conduct a POC testing period to establish a baseline.
Editorial note — how this reconciles with the live page. The table above is now the vendor-baseline layer of the Daily Ingest Estimator: the estimator takes each of these endpoint types as its own input, so a 10,000-endpoint single-OS estate reproduces these totals exactly — about 1.8 TB per day on current Windows agents, 2.8 TB on older Windows or macOS, 10 TB on Linux workstations and 80 TB on Linux servers. Two adjustments keep it honest in a customer conversation. First, baseline is not the number to lead with: the live page defaults to a field-typical band where a partially tuned Windows-dominant estate of 10,000 endpoints lands nearer 1 TB per day, which is what tuned deployments actually report, and practitioners report roughly a hundredfold cut from excluding file events alone. Second, an earlier draft of the live page assumed a flat 600 to 700 MB per endpoint from a single practitioner report, which produced 6 to 7 TB for 10,000 endpoints; that figure is retained only as a labelled upper-bound outlier, because it overstates almost every real deployment. The licensing, variable-factor, savings, and baseline points all hold and are reflected on the live page.
Where to go next

Section 2 · Aligns to “CrowdStrike Falcon Data Replicator”

CrowdStrike and XSIAM

Captured sizing research for CrowdStrike FDR at the same 10,000-endpoint scale, where the numbers are compressed rather than raw.

CrowdStrike FDR — 10,000 endpoints Captured research

Captured research, reproduced verbatim
What about Crowdstrike data?

For CrowdStrike, the data volumes look very different compared to SentinelOne. This is primarily because CrowdStrike provides significantly less raw event data than other vendors, and the figures they provide in their documentation are based on compressed data sent via Falcon Data Replicator (FDR).

Estimated Log Volume for 10,000 Endpoints (CrowdStrike FDR)

According to CrowdStrike's documentation on minimum expected compressed data per host per day:

Endpoint TypeMinimum Compressed Data / Host / DayTotal Minimum (10,000 EPs)
Windows2.5 MB~25 GB / day
macOS2.5 MB~25 GB / day
Linux10 MB~100 GB / day

Note: These are the absolute minimums. The actual expected amount will be higher and depends heavily on host activity, your specific CrowdStrike subscriptions, and the filtering policies applied.

Critical Sizing Considerations for CrowdStrike in XSIAM

  • Data Quality & Context: Raw event data from CrowdStrike is known to be highly partial and lacks the relevant context that other vendors provide natively. Because of this, Cortex XSIAM has to allocate additional backend resources to stitch CrowdStrike FDR data with other event information to make it usable for analytics and investigations.
  • Analytics Limitations: Because CrowdStrike provides far less data than Cortex XDR agents and lacks on-endpoint causality chains, only a subset of XSIAM's analytics-based detectors (primarily Network, File, Process, and Registry) will be functional on CrowdStrike telemetry.
  • XSIAM Licensing: Just like SentinelOne, if the customer chooses to retain CrowdStrike and ingest the logs via FDR into XSIAM, that ingested volume will count toward their XSIAM Base Subscription daily GB/day total.

To get an accurate estimate for licensing, the best approach is to either look at their current SIEM's ingestion metrics for CrowdStrike or run a short POV (Proof of Value) to establish a baseline in their specific environment.

Editorial note — how this reconciles with the live page. These figures carried forward almost unchanged, because they are traceable to published documentation. The live page states the Linux minimum as a range of 8 to 10 MB per host per day to match the source it cites, and adds that field reports of 10 to 40 MB per endpoint per day are common once real host activity and module subscriptions are included. The compressed-versus-parsed distinction is the one thing to confirm in any customer-quoted number.

Section 3 · Aligns to “Microsoft Defender for Endpoint”

Microsoft Defender (MDE) and XSIAM

Captured sizing research for MDE, where the entitled volume and the volume real investigation needs differ by twentyfold.

Microsoft Defender for Endpoint — 10,000 endpoints Captured research

Captured research, reproduced verbatim
What about Microsoft Defender (MDE) data?

For Microsoft Defender for Endpoint (MDE), calculating the log volume is less straightforward because Microsoft does not publish a flat "expected MB per day" officially. Instead, they estimate individual log entries to be around 500 bytes, though certain events can spike up to 2.5 MB each.

However, based on field experience and customer data, here is what you can expect for 10,000 endpoints:

Estimated Log Volume for 10,000 Endpoints (Microsoft Defender)

  • The Baseline ("Free" Tier) Volume: Microsoft Sentinel's E5 license only includes 5 MB of free log ingestion per endpoint per day.
    • Total for 10,000 EPs: ~50 GB / day
    • The Catch: This 5 MB limit is highly truncated and only covers a subset of basic alerts, missing critical raw telemetry.
  • The Effective Volume (for Real Incident Response): To achieve full EDR visibility required for actual threat hunting and incident response in a SIEM, customers consistently report needing at least 100 MB per endpoint per day.
    • Total for 10,000 EPs: ~1,000,000 MB / day (or ~1 TB / day)

Critical Sizing Considerations for Microsoft Defender in XSIAM

  • Base Subscription Licensing: Similar to SentinelOne and CrowdStrike, if a customer keeps Microsoft Defender and streams the raw logs to Cortex XSIAM via the Microsoft Graph API/Event Hubs, that entire ~1 TB/day volume counts toward the XSIAM Base Subscription daily GB/day total.
  • Missing Server Data: Microsoft's E5/MDE telemetry often isolates or excludes server data unless separate add-on licenses (Defender for Servers) are purchased. When quoting, verify if the 10,000 endpoints include servers, as their event volume is significantly higher than workstations.
  • Analytics Limitations: As with other third-party EDRs, Cortex XSIAM covers key detections for Network, File, Process, and Registry events from MDE. However, MDE cannot provide the patented, on-endpoint causality chains that native Cortex XDR agents provide, meaning some of XSIAM's most advanced AI behavioral detectors won't be fully operational on this data.
  • Cost Saving Strategy: This is a strong opportunity to pitch the XDR EA Add-On or native Cortex XDR agents. If the customer replaces Microsoft Defender with Cortex XDR, the equivalent 1 TB/day of endpoint data becomes entirely exempt from the XSIAM daily GB/day ingest billing, providing a much lower Total Cost of Ownership (TCO) than paying to ingest Defender logs into XSIAM or Sentinel.
Editorial note — how this reconciles with the live page. This section carried forward intact, including the two-number framing that makes MDE sizing hard. The live page adds one technical caveat worth raising in a technical meeting: raw MDE events must reach XSIAM through the dedicated Defender for Endpoint collector, because the generic Event Hub collector does not support stitching. The 5 MB entitlement and the roughly 100 MB effective figure remain field-reported planning numbers rather than vendor-published ones.

Across All Three

What Every Section Above Agrees On

Three vendors, three shapes of data, one consistent commercial conclusion.

  • Retained third-party EDR telemetry is metered. SentinelOne, CrowdStrike, and Defender raw logs all count against the XSIAM base subscription daily GB/day total when the customer keeps their existing agent.
  • Native Cortex XDR agent telemetry is not. Replacing the third-party agent removes the line item entirely rather than negotiating it down, which is the strongest commercial lever on the table.
  • Analytics coverage is a subset on every third-party feed. Without on-endpoint causality chains, network, file, process, and registry detections work, and the most advanced behavioral detectors do not fully operate.
  • Nobody should quote from a table. All three sections end at the same place: read the customer's current SIEM ingestion metrics or run a short POC/POV to establish a real baseline before a proposal.
  • Commercial treatment is as of today, not a contractual guarantee. Confirm current metering terms with the Palo Alto Networks account team in writing before any figure reaches a customer.

Provenance

Sources & Status

What is documented, what is field-reported, and what is preserved here only as a record of the original research.

Continue