Sheet 37 / Lock-In and Data Portability
Digital Signet / SIEM Vendor Dossier 2026
Verified 2026-06-20
SIEM vendor lock-in and data portability
The lock-in cost is not the licence; it is the data lake, the detection language, and the analyst muscle memory. Three axes worth scoring.
Data lake portability
- Snowflake-backed (Panther, Hunters, Anvilogic, Securonix)[23]: buyer keeps the lake on exit.
- S3-backed (CrowdStrike, SentinelOne data lake): buyer keeps the bucket on exit, query layer departs.
- ELK-backed (Elastic, Graylog)[16]: open-source escape path on self-managed deployment.
- Walled garden (Splunk, QRadar, Sentinel)[1]: the data lives in vendor-managed indexes; export on exit is real but slow.
Detection-language portability
SPL (Splunk), KQL (Sentinel), AQL (QRadar), YARA-L (Chronicle), Python (Panther). Migration cost is dominated by content rewrite, not data move. Plan for a 4-6 month parallel-run for any SIEM switch above 200 GB/day.
5-year Splunk ELA premium
A 5-year Splunk ELA carries an estimated 15-25% lock-in premium vs a 1-year Snowflake-native contract because the exit cost is amortised against the term. Diligence the contract exit clauses, not just the unit price.