Cortex XSIAM · Sizing Research
Third-Party EDR Sizing
Research Deep Dive
The original 10,000-endpoint sizing research for SentinelOne, CrowdStrike, and Microsoft Defender, reproduced as captured, section by section against the comparisons on the EDR Telemetry Economics page.
Section 1 · Aligns to “SentinelOne Deep Visibility”
SentinelOne and XSIAM
Captured sizing research for a 10,000-endpoint SentinelOne estate ingested into XSIAM as a third-party EDR feed.
SentinelOne — 10,000 endpoints Captured research
For a customer with 10,000 endpoints using SentinelOne with Cortex XSIAM, the daily log volume varies significantly depending on the operating system and the level of activity on the hosts.
Estimated Log Volume for 10,000 Endpoints
Based on standard SentinelOne Deep Visibility metrics, the total daily uncompressed data for 10,000 endpoints typically ranges from 2.8 TB to 5 TB per day for a standard Windows environment, depending on agent version and activity levels.
| Endpoint Type | Events Per Agent / Day | Data Per Agent / Day | Total (10,000 EPs) |
|---|---|---|---|
| Windows Agents (v22.3+) | ~90,000 events | ~180 MB* | ~1.8 TB / day |
| Windows Agents (v22.2-) | ~140,000 events | ~280 MB (Uncompressed) | ~2.8 TB / day |
| macOS Agents | ~140,000 events | ~280 MB (Uncompressed) | ~2.8 TB / day |
| Linux Agents (Standard) | ~500,000 events | ~1,000 MB* | ~10 TB / day |
| Linux Servers | ~4,000,000 events | ~8,000 MB* | ~80 TB / day |
*Estimated based on the 280 MB / 140,000 event ratio provided for older versions and macOS.
Critical Sizing Considerations
- XSIAM Licensing: In an XSIAM NG SIEM deployment where a customer retains their third-party EDR (like SentinelOne), all raw EDR logs ingested count toward the XSIAM Base Subscription daily GB/day total.
- Variable Factors: Actual volume can fluctuate based on resource type (server vs. VDI), OS version, and specific SentinelOne data collection policies (e.g., granular Deep Visibility settings).
- Data Savings Opportunity: If the customer replaces SentinelOne with native Cortex XDR agents, these logs are exempt from the daily GB/day base ingestion total, which can significantly lower overall licensing costs.
- Accurate Forecasting: To get precise figures before a proposal, it is recommended to review the current ingestion volume in the customer's existing SIEM or conduct a POC testing period to establish a baseline.
- Tuning and reduction work: the SentinelOne Log Reduction & Alert Tuning Guide covers the documented collection paths, the XQL to baseline actual volume, issue exclusions, parsing rules, and whether a data pipeline like Cribl is worth it.
- Filter-based planning ranges: the EDR Telemetry Economics vendor section and estimator.
Section 2 · Aligns to “CrowdStrike Falcon Data Replicator”
CrowdStrike and XSIAM
Captured sizing research for CrowdStrike FDR at the same 10,000-endpoint scale, where the numbers are compressed rather than raw.
CrowdStrike FDR — 10,000 endpoints Captured research
For CrowdStrike, the data volumes look very different compared to SentinelOne. This is primarily because CrowdStrike provides significantly less raw event data than other vendors, and the figures they provide in their documentation are based on compressed data sent via Falcon Data Replicator (FDR).
Estimated Log Volume for 10,000 Endpoints (CrowdStrike FDR)
According to CrowdStrike's documentation on minimum expected compressed data per host per day:
| Endpoint Type | Minimum Compressed Data / Host / Day | Total Minimum (10,000 EPs) |
|---|---|---|
| Windows | 2.5 MB | ~25 GB / day |
| macOS | 2.5 MB | ~25 GB / day |
| Linux | 10 MB | ~100 GB / day |
Note: These are the absolute minimums. The actual expected amount will be higher and depends heavily on host activity, your specific CrowdStrike subscriptions, and the filtering policies applied.
Critical Sizing Considerations for CrowdStrike in XSIAM
- Data Quality & Context: Raw event data from CrowdStrike is known to be highly partial and lacks the relevant context that other vendors provide natively. Because of this, Cortex XSIAM has to allocate additional backend resources to stitch CrowdStrike FDR data with other event information to make it usable for analytics and investigations.
- Analytics Limitations: Because CrowdStrike provides far less data than Cortex XDR agents and lacks on-endpoint causality chains, only a subset of XSIAM's analytics-based detectors (primarily Network, File, Process, and Registry) will be functional on CrowdStrike telemetry.
- XSIAM Licensing: Just like SentinelOne, if the customer chooses to retain CrowdStrike and ingest the logs via FDR into XSIAM, that ingested volume will count toward their XSIAM Base Subscription daily GB/day total.
To get an accurate estimate for licensing, the best approach is to either look at their current SIEM's ingestion metrics for CrowdStrike or run a short POV (Proof of Value) to establish a baseline in their specific environment.
Section 3 · Aligns to “Microsoft Defender for Endpoint”
Microsoft Defender (MDE) and XSIAM
Captured sizing research for MDE, where the entitled volume and the volume real investigation needs differ by twentyfold.
Microsoft Defender for Endpoint — 10,000 endpoints Captured research
For Microsoft Defender for Endpoint (MDE), calculating the log volume is less straightforward because Microsoft does not publish a flat "expected MB per day" officially. Instead, they estimate individual log entries to be around 500 bytes, though certain events can spike up to 2.5 MB each.
However, based on field experience and customer data, here is what you can expect for 10,000 endpoints:
Estimated Log Volume for 10,000 Endpoints (Microsoft Defender)
- The Baseline ("Free" Tier) Volume: Microsoft Sentinel's E5 license only includes 5 MB of free log ingestion per endpoint per day.
- Total for 10,000 EPs: ~50 GB / day
- The Catch: This 5 MB limit is highly truncated and only covers a subset of basic alerts, missing critical raw telemetry.
- The Effective Volume (for Real Incident Response): To achieve full EDR visibility required for actual threat hunting and incident response in a SIEM, customers consistently report needing at least 100 MB per endpoint per day.
- Total for 10,000 EPs: ~1,000,000 MB / day (or ~1 TB / day)
Critical Sizing Considerations for Microsoft Defender in XSIAM
- Base Subscription Licensing: Similar to SentinelOne and CrowdStrike, if a customer keeps Microsoft Defender and streams the raw logs to Cortex XSIAM via the Microsoft Graph API/Event Hubs, that entire ~1 TB/day volume counts toward the XSIAM Base Subscription daily GB/day total.
- Missing Server Data: Microsoft's E5/MDE telemetry often isolates or excludes server data unless separate add-on licenses (Defender for Servers) are purchased. When quoting, verify if the 10,000 endpoints include servers, as their event volume is significantly higher than workstations.
- Analytics Limitations: As with other third-party EDRs, Cortex XSIAM covers key detections for Network, File, Process, and Registry events from MDE. However, MDE cannot provide the patented, on-endpoint causality chains that native Cortex XDR agents provide, meaning some of XSIAM's most advanced AI behavioral detectors won't be fully operational on this data.
- Cost Saving Strategy: This is a strong opportunity to pitch the XDR EA Add-On or native Cortex XDR agents. If the customer replaces Microsoft Defender with Cortex XDR, the equivalent 1 TB/day of endpoint data becomes entirely exempt from the XSIAM daily GB/day ingest billing, providing a much lower Total Cost of Ownership (TCO) than paying to ingest Defender logs into XSIAM or Sentinel.
Across All Three
What Every Section Above Agrees On
Three vendors, three shapes of data, one consistent commercial conclusion.
- Retained third-party EDR telemetry is metered. SentinelOne, CrowdStrike, and Defender raw logs all count against the XSIAM base subscription daily GB/day total when the customer keeps their existing agent.
- Native Cortex XDR agent telemetry is not. Replacing the third-party agent removes the line item entirely rather than negotiating it down, which is the strongest commercial lever on the table.
- Analytics coverage is a subset on every third-party feed. Without on-endpoint causality chains, network, file, process, and registry detections work, and the most advanced behavioral detectors do not fully operate.
- Nobody should quote from a table. All three sections end at the same place: read the customer's current SIEM ingestion metrics or run a short POC/POV to establish a real baseline before a proposal.
- Commercial treatment is as of today, not a contractual guarantee. Confirm current metering terms with the Palo Alto Networks account team in writing before any figure reaches a customer.
Provenance
Sources & Status
What is documented, what is field-reported, and what is preserved here only as a record of the original research.
- Ingest raw EDR events from SentinelOne DeepVisibility — Palo Alto Networks Cortex documentationCloud Funnel to S3 and SQS path, the
sentinelone_deep_visibility_rawdataset, mapping intoxdr_dataand XDM, the instruction to include all fields, and the documented third-party agent and analytics limitations. - Ingest raw EDR events from Microsoft Defender for Endpoint — Palo Alto Networks Cortex documentationAzure Event Hubs path, the dedicated collector requirement, and the analytics subset limitation.
- CrowdStrike FDR data volumes — Splunk Add-on for CrowdStrike FDR documentationAverage compressed data per host per day: 2.5 MB Windows, 2.5 MB macOS, 8–10 MB Linux, citing CrowdStrike.
- SentinelOne Cloud Funnel ingestion filtering and best practices — Google Cloud Security CommunityPractitioner report of roughly 600–700 MB per endpoint per day on a default open query, and a two-order-of-magnitude reduction from excluding file events.
- The SentinelOne per-OS event counts and per-agent megabyte figures in Section 1 now drive the Daily Ingest Estimator on the EDR Telemetry Economics page.They are captured research rather than a published vendor table, so treat them as directional planning numbers. They do reproduce the documented single-OS totals at 10,000 endpoints and the 2.8–5 TB per day range for a standard Windows estate, which is why they replaced the earlier flat per-endpoint assumption.
- The Microsoft 5 MB E5 entitlement versus roughly 100 MB effective volume is field-reported rather than vendor-published.Directional only. Baseline against the customer's own metrics or a proof of value.
Continue
- XSIAM & EDR Telemetry Economics — the live sizing page, estimator, fidelity matrix, and discovery questions.
- SentinelOne Log Reduction & Alert Tuning Guide — documented collection paths, XQL baselining, issue exclusions, parsing rules, and the Cribl question.
- Cortex XDR Deep Dive — what the native agent produces and why causality changes detection coverage.