In this article:
Want us to find IT vendors for you?
Share your vendor requirements with one of our account managers, then we build a vetted shortlist and arrange introductory calls with each vendor.
Book a call

Does XDR Replace SIEM? A guide for IT leaders facing renewal

XDR replaces SIEM detection, not log retention or arbitrary ingestion. PCI needs 12 months, CIS 90 days, and no framework names a SIEM. Three architectures, priced.

Author:
Date

What do you do if your endpoint vendor's account team explains that the SIEM is now redundant because their platform does correlation, retention and detection in one place. Meanwhile the renewal quote also came with an increase.

Both conversations are commercially motivated and it leads to 2 questions.

That question has two parts. Can you cancel the SIEM renewal without failing your next audit, and what does each path cost once you price it properly.

Of the nine compliance frameworks I checked against their source documents, exactly two prescribe a numeric log retention period. PCI DSS requires twelve months. CIS Controls v8 requires ninety days. The remaining seven set an outcome and leave the duration to you. None of the nine mandates a SIEM.

That means the audit question and the SIEM question are separate questions, and treating them as one is what pushes teams into paying SIEM prices for data they query twice a year.

IT Leaders Report 2026

What are your IT peers investing in 2026?

We spoke to about 1,300 IT leaders from various organisations to understand what they're evaluating. Most of it is the kind of thing you'd only hear from a peer you know well enough to ask, so we've put it in one place.

Read the report
IT Leaders Report 2026 cover artwork

The three architectures a SIEM renewal puts on the table

There are three viable configurations, and the middle one is the one almost nobody writes about.

Architecture 1, XDR only. Detection and retention both sit inside the XDR platform, on its native retention window.

Architecture 2, XDR plus a retention tier. The XDR handles detection on hot security telemetry. A cheap, high-volume store holds everything else for the compliance period, queried rarely and priced per gigabyte stored rather than per gigabyte ingested into an analytics engine.

Architecture 3, XDR plus SIEM. The XDR handles endpoint and identity detection. The SIEM remains the system of record and the correlation engine across everything else.

Architecture Holds detection Holds retention What it cannot do Metering unit
1. XDR only XDR analytics engine XDR native window (7–31 days default) Hold arbitrary log sources; meet a 12-month floor without an add-on Per endpoint / per user
2. XDR + retention tier XDR analytics engine Object store or log lake, 1–12 years Fast interactive search across all data; cross-source correlation Per endpoint, plus per GB stored and per GB scanned
3. XDR + SIEM Both, with overlap SIEM analytics tier Avoid paying analytics rates on low-value log volume Per endpoint, plus per GB/day ingested or per EPS

The vendors have already answered this question by shipping across the boundary

Before the framework detail, one fact worth holding onto, because it undercuts both sides of the sales conversation.

Palo Alto Networks brought Cortex XSIAM to general availability on 12 October 2022, an XDR vendor shipping a product positioned against the SIEM category.

CrowdStrike acquired Humio in 2021 and now sells Falcon LogScale and Falcon Next-Gen SIEM as separate licences alongside the endpoint agent.

SentinelOne sells Singularity Data Lake, which accepts query syntax from other platforms so that migrating customers can carry detection content across.

Microsoft moved in the opposite direction, bringing Sentinel into the Defender portal and making the Sentinel data lake generally available on 30 September 2025. Cisco closed its acquisition of Splunk on 18 March 2024.

Every major XDR vendor now sells a log platform. Every major SIEM vendor now sells endpoint detection. The category boundary the sales conversation depends on has already dissolved from the inside.

One more point that follows from this. No standards body defines XDR. There is no specification, no conformance test and no certification. XDR is a commercial category, which means no auditor can require it and no auditor can accept it as evidence of anything on its own.

What they assess is retention duration, log review cadence and integrity. Our guide to the SIEM vendor market covers how the SIEM side of that line has consolidated; the MDR and XDR provider comparison covers the other side.

What compliance frameworks actually require for log retention

I checked each framework against its own source document rather than a vendor compliance page, because vendor summaries of these clauses reliably drift toward whatever the vendor sells.

Framework Retention requirement Review requirement Names a technology? Citation
PCI DSS 4.0.1 At least 12 months, with the most recent 3 months immediately available for analysis Daily review of CDE component logs SIEM offered as one option Req. 10.5.1 (review: 10.4.1)
CIS Controls v8 Minimum 90 days. No availability requirement stated Collect, alert, review (IG2/IG3) No Safeguard 8.10
NIST SP 800-53 Rev 5 Organisation-defined. Archived records permitted with a retrieval capability Audit review and analysis No AU-11, AU-11(1), AU-6
NIST SP 800-171 / CMMC L2 Organisation-defined. No availability requirement stated Monitoring, analysis, reporting No 3.3.1 (Rev 2)
HIPAA Security Rule Risk-based for logs. 6 years for documentation Information system activity review No §164.312(b), §164.316(b)(2)(i)
ISO/IEC 27001:2022 Organisation-defined, including availability Monitor for anomalous behaviour No A.8.15, A.8.16
SOC 2 (AICPA TSC) None stated Controls tested across the observation period No CC-series criteria
NIS2 Not specified in the directive Detection of anomalous activity No Art. 21; CIR 2024/2690 §3.2.5
DORA Entity sets the period by risk assessment Detection mechanisms; logging procedures No CDR 2024/1774 Article 12

Three things in that table are worth pulling out, because they are routinely misreported.

The HIPAA six-year figure does not apply to audit logs. The Security Rule ties six years to documentation retention under §164.316(b)(2)(i). The audit log duration itself falls under §164.312(b) and is determined by your risk analysis. Any vendor page telling you HIPAA requires six years of log retention is paraphrasing the wrong clause, and it is the single most common error in content on this topic.

NIST already describes the retention tier pattern as a control. AU-11(1) explicitly contemplates long-term audit records held in archive, provided a retrieval capability exists. Cold storage with query on read is not a compromise position. It is the control as written.

PCI DSS specifies a hot and cold split, not a single tier. Requirement 10.5.1 asks for twelve months retained with the most recent three months immediately available for analysis. That is a three-month hot window and a nine-month archive. It is Architecture 2 described in a standard.

On the insurance side, the questions are different again. Publicly available cyber insurance application questionnaires ask about endpoint detection coverage, multi-factor authentication enforcement, tested and immutable backups, and whether logging and monitoring run with round-the-clock triage.

They ask about coverage and response, rarely about a retention figure. If you want the full picture of how underwriting questions now drive security architecture, we covered that in the cyber-insurance renewal piece.

So the audit answer is yes, you can cancel a SIEM renewal without failing an audit. The constraint is duration and review evidence, and both are purchasable without a SIEM.

The constraint that actually decides it is a different one.

Default XDR retention windows fall short of every compliance floor

Platform Default telemetry retention Maximum available How it is purchased Searchable in place?
Microsoft Defender XDR 30 days (advanced hunting) 2 years analytics tier; 12 years in the Sentinel data lake Sentinel data lake or extended analytics retention Yes, KQL query on read
CrowdStrike Falcon 7 days on standard SKUs 365 days via LogScale tiers; up to 5 years via Search Retention Separate per-endpoint retention licence Yes, index-free search
SentinelOne Singularity Not cleanly documented for the base agent Extended via Singularity Data Lake Data Lake licence, metered on monthly average ingestion Yes
Palo Alto Cortex XSIAM 31 days ingested data Cold storage add-on, 6-month minimum Hot and cold storage add-ons purchased separately Hot yes; cold search limited

Every platform in that table fails PCI's twelve-month floor at default. Three of the four fail the CIS ninety-day floor at default. Extended retention is a separate purchase in every case, and that purchase is the line item the "your SIEM is redundant" conversation leaves out.

A second detail matters more than it looks. Retention is not uniform within a platform. On XSIAM, ingested data sits at 31 days, while cases run to 186 days, forensic data to 365 days and audit logs to 365 days. A single retention figure on a datasheet does not describe what you will actually have when an assessor asks for a specific event from eight months ago.

Verification note (remove before publication). SentinelOne does not publish a clear default telemetry retention window for the base agent independent of a Singularity Data Lake licence. The 24-month figure that circulates comes from product marketing rather than documentation. Confirm this directly with the vendor before it goes into a business case.

What XDR platforms cannot ingest without a paid log tier

This is the part that decides whether Architecture 1 is available to you at all, and it is the part that vendor comparisons skip, because vendors document what they support and stay silent on what they do not.

I worked through the published connector catalogues for each platform in full. The finding is consistent across all four.

Arbitrary log ingestion is possible only through the vendor's own SIEM or log-management tier, which is metered per gigabyte. The base per-endpoint XDR licence accepts a fixed catalogue of security telemetry sources and nothing else.

Data source Defender XDR (base) CrowdStrike Falcon (base) SentinelOne (base) Cortex XSIAM
LOB and custom apps, arbitrary format No Requires Sentinel custom tables No Requires Next-Gen SIEM / LogScale No Requires Singularity Data Lake Yes Broker VM with custom parsers
Syslog from arbitrary network devices No Sentinel CommonSecurityLog via AMA No LogScale syslog ingest No Data Lake syslog ingest Yes Broker VM syslog collector
Mainframe and midrange Not publicly documented Not publicly documented Syslog only if the system emits it Not publicly documented Not publicly documented Syslog via broker if emitted
OT, ICS and SCADA Separate product Defender for IoT passive sensors Not publicly documented in base Discovery via Ranger Log ingest via Data Lake Via connectors and broker
Physical access and building systems Not publicly documented Not publicly documented Not publicly documented Syslog via broker only
Print, MFP and IoT devices Discovery only Enterprise IoT via Defender for Endpoint Not publicly documented Discovery via Ranger Syslog via broker only
Third-party SaaS audit logs, no native connector No Sentinel Logs Ingestion API No Next-Gen SIEM HEC No Data Lake REST API Yes API collector and parsers
Databases and their audit logs No Requires Sentinel No Requires Next-Gen SIEM No Requires Data Lake Yes Via broker
Legacy systems outside the agent support matrix No Syslog to Sentinel No LogScale ingest No Data Lake syslog Yes Broker syslog

XSIAM is the outlier, and the reason is structural. It was built with a SIEM-style ingestion layer from the start and it meters on gigabytes per day accordingly. The other three separate the endpoint licence from the log licence, and the log licence is where arbitrary sources live.

Two cases deserve naming because they are separate products rather than connectors. Operational technology on the Microsoft side runs through Defender for IoT with passive out-of-band sensors, which is a distinct purchase with its own deployment work.

If you have a plant floor in scope, our ICS and SCADA security guide covers what that segmentation actually involves. Print, MFP and IoT estates are handled as asset discovery across most of these platforms rather than as log sources, which is a recurring gap and one we have written about in why device logging remains a headache.

Here is the test to run before you go further. Pull the log source list your assessor asked for in the last two audits. Mark which sources the base XDR catalogue covers.

Price the remainder through the vendor's log tier at their per-gigabyte rate. If the remainder is anything other than trivial, Architecture 1 is off the table regardless of what the SIEM renewal costs, and the real comparison is between Architectures 2 and 3.

The retention tier options and what each one costs

Architecture 2 needs a place to put compliance data that is cheap to store and acceptable to query slowly.

Microsoft Sentinel data lake. Generally available since 30 September 2025 and operated inside the Defender portal. Published rates are 0.05 USD per GB ingested, 0.026 USD per GB per month stored billed against a 6:1 compression ratio, and 0.005 USD per GB scanned at query time. Retention extends to twelve years. Searchable in place with KQL. Some Defender XDR tables are not yet supported in the lake, and table plan changes are limited in frequency.

Amazon Security Lake. AWS-operated, storing OCSF-normalized Parquet in your own S3 bucket. Pricing runs at 0.75 USD per GB for CloudTrail management and data events, 0.25 USD per GB for other AWS log sources, plus 0.035 USD per GB for normalization, with S3, Glue and query charges on top. Custom sources must conform to OCSF and Parquet themselves, which is real engineering work.

CrowdStrike Falcon LogScale and Search Retention. Retention licences are sold in 30, 60, 90, 180 and 365-day tiers, extending to five years through Search Retention. Index-free search keeps query cost predictable. A single node handles roughly one terabyte per day of ingest, above which deployments need architectural support.

Object storage with query on read. Write normalized telemetry to S3 or equivalent and query it federated, without indexing it into an analytics platform. There is a documented production pattern here: one organization held six months of CrowdStrike EDR telemetry in S3 and searched it from Splunk through a federation layer, keeping the data out of the Splunk licence entirely. You own the schema, the normalization and the retrieval latency.

Tier Pricing unit Searchable in place Main limitation
Sentinel data lake $/GB ingested + $/GB/month stored + $/GB scanned Yes, KQL Table support gaps; limited plan change frequency
Amazon Security Lake $/GB ingested + $/GB converted + S3 and query charges Via Athena or OpenSearch Custom sources must self-conform to OCSF
Falcon LogScale / Search Retention Retention-day licence tier + ingest volume Yes, index-free Separate licence from the endpoint agent
Object storage + query on read $/GB stored + $/GB scanned Federated query only No detection engine; you own normalisation

How to calculate the crossover between the three architectures

You need two numbers you already have. N, your endpoint or user count. V, your daily volume of arbitrary logs in gigabytes, meaning everything outside native XDR telemetry.

The per-endpoint XDR cost is common to all three architectures, so it cancels out of the comparison. What differs is the log line.

  • Architecture 2: (V × 30 × storage rate) + (monthly GB scanned × query rate)
  • Architecture 3: V × 30 × SIEM analytics ingest rate

Storage rates sit roughly two orders of magnitude below SIEM analytics ingest rates. At Sentinel data lake rates, thirty days of a 50 GB per day flow costs 75 USD to ingest and around 6.50 USD per month to store. The same 1,500 GB through an analytics tier is a four-figure monthly line before commitment discounts.

So the variable that decides between Architectures 2 and 3 is not storage volume, it is query volume. Rarely searched compliance data belongs in a retention tier, where you pay almost nothing to hold it and a small amount on the rare occasions you read it. Frequently searched data belongs in a SIEM, where per-gigabyte-scanned charges would otherwise accumulate past what the analytics tier costs.

The practical threshold: if your team runs ad hoc searches across the full log estate weekly or more often, Architecture 3 pays for itself. If the answer is quarterly, Architecture 2 is cheaper by an order of magnitude and meets the same framework requirements.

On the SIEM side you will mostly be working with units rather than rates, because list pricing is quote-only for QRadar, Exabeam, Securonix, Devo, Panther and, in practice, Splunk. The units themselves are public.

Sentinel meters gigabytes ingested per day with commitment tiers starting at 100 GB per day.

Splunk meters on ingest volume, workload compute units or entity count depending on the contract.

QRadar meters events per second and flows per minute.

Elastic meters resource consumption.

On the XDR side, Defender meters per user or device through M365 licensing, CrowdStrike meters per endpoint with cloud workloads billed per sensor hour, SentinelOne meters per agent with the Data Lake billed on monthly average ingestion, and XSIAM meters gigabytes per day alongside endpoint count.

What happens to your detections when you leave the platform

The cost that appears on neither quote is detection rewriting.

Platform Detection language Managed as code Sigma backend Portability on exit
Microsoft Defender XDR KQL Yes, API and ARM/Bicep Yes Requires translation
CrowdStrike Falcon CrowdStrike Query Language Yes, API Yes Requires translation
SentinelOne Singularity PowerQuery, with KQL and SPL accepted Yes, API Yes Best case if Sigma-authored
Palo Alto Cortex XSIAM XQL Yes, API Not publicly documented Proprietary, requires rewrite

If your team has spent three years building SIEM correlation content, moving to XDR-only means rewriting it in a proprietary query language, and moving away again later means rewriting it a second time. Content authored in Sigma travels.

Content authored natively does not. That is a real cost with a real headcount attached, and it belongs in the comparison alongside the licence numbers.

The practical mechanics of this kind of move are covered in what happens when you migrate between Microsoft Defender and CrowdStrike, and the failure modes of SIEM replacement specifically in 5 problems that surface after you replace your on-prem SIEM.

All four platforms report detection coverage against MITRE ATT&CK, so a coverage report is available in any of the three architectures. Every platform also sells a managed tier, and the managed tier changes ownership of detection logic from your team to the provider. That is a governance decision as much as a staffing one, and we compared the options in the MDR provider guide.

Which architecture fits your estate

Run four checks in order.

  1. Which frameworks apply, and does any of them state a duration? If PCI is in scope, your floor is twelve months retained with three months immediately available. If only CIS v8 applies, it is ninety days. Everything else is yours to set and document.
  2. Which log sources has your assessor actually asked to see? Mark them against the ingestion table above. Anything outside the base XDR catalogue removes Architecture 1 from consideration.
  3. How often does your team search the full log estate? Weekly or more, Architecture 3. Quarterly, Architecture 2.
  4. How much detection content exists, and in what language? Sigma-authored content moves freely. Proprietary content is a rewrite priced in engineer-months.

Architecture 1 fits a small, cloud-native estate with no compliance duration requirement, where every log source an assessor cares about is already a native XDR connector. That is a narrow set of organizations, and if you are reading this because a renewal arrived, you are probably not in it.

Architecture 2 fits the majority of mid-market estates. You have a twelve-month or ninety-day floor, you have log sources outside the XDR catalogue, and you search them rarely. You buy an XDR licence, route arbitrary logs to a retention tier at storage prices, and document the hot and cold split against the framework clause. This is the configuration the market talks about least and needs most.

Architecture 3 fits estates with genuine cross-source correlation requirements, a detection engineering team that queries daily, heavy OT or mainframe presence, or a regulator that expects continuous monitoring across systems the XDR will never see. If that is you, the renewal increase is a negotiation problem rather than an architecture problem.

The answer to "does XDR replace SIEM" is that it replaces the detection function for endpoint and identity, and it does not replace the retention and arbitrary-ingestion functions unless you buy those separately from the same vendor at similar per-gigabyte prices. Once you are paying per gigabyte either way, the question stops being which category to buy and becomes which tier each class of data belongs in.

See what's out there before you sign the renewal

Your XDR and SIEM vendors can't give you a neutral read on this, because one of them loses the account either way. We can help you explore options before you decide. Talk to us and we'll get back to you with a shortlist of options who fit.

Book a call

FAQ

Does XDR replace SIEM?

It replaces the detection function for endpoint and identity telemetry. It does not replace log retention beyond the native window or ingestion of arbitrary log sources, both of which require a separately licensed log tier from the same vendor. Whether that combination is cheaper than your SIEM depends on your daily log volume and how often you query it.

Is a SIEM required for PCI DSS compliance?

No. PCI DSS 4.0.1 Requirement 10.5.1 sets a twelve-month retention period with three months immediately available, and Requirement 10.4.1 requires daily log review. A SIEM is offered as one acceptable means of automating that review, never as a mandate.

How long do you have to retain security logs?

It depends on the framework. PCI DSS requires at least twelve months. CIS Controls v8 Safeguard 8.10 requires a minimum of ninety days. NIST SP 800-53, ISO/IEC 27001, SOC 2, HIPAA, NIS2 and DORA all leave the duration organisation-defined and expect you to justify it from a risk assessment.

Can XDR meet twelve-month log retention requirements?

Not at default. Defender XDR retains 30 days, Cortex XSIAM 31 days and CrowdStrike Falcon 7 days on standard SKUs. Each platform sells extended retention as a separate purchase, and that purchase is what makes the twelve-month floor achievable.

What can a SIEM ingest that XDR cannot?

Line-of-business applications with arbitrary log formats, syslog from any network device, mainframe and midrange systems, physical access control, databases and their audit logs, and third-party SaaS where no native connector exists. Base XDR licences from Microsoft, CrowdStrike and SentinelOne accept none of these without their respective log tier.

Is XDR cheaper than SIEM?

Per endpoint, yes and predictably so. Once you route arbitrary logs through the XDR vendor's log tier, you are paying per gigabyte in the same way a SIEM charges, and the saving narrows or disappears. The cheapest configuration for rarely queried compliance data is usually an XDR licence plus a low-cost retention tier, rather than either product alone.