Skip to main content

Signals

A signal is a message from a sensor that Pharos checked, and it is the whole billable unit. Connecting a manager is free. There is no per-manager fee and no licence, and the bill follows what the connected fleet actually sends. Billing runs on a volume ladder, so the per-signal rate falls as monthly volume grows, and the console's Billing page shows the price list, the workspace's position in it, and the bill so far.

What counts as a signal​

The sensor sendsOne signal is
An alert from a manager's streamone alert that carried at least one value Pharos had to look up
The fleet's vulnerability stateone vulnerable package on one agent, counted once per billing month
The fleet's file inventoryone known indicator that a reported file hash matched, counted once per billing month

In practice, on one manager over one month:

  • An agent whose kernel package is flagged for forty CVEs is one signal, and stays one signal when the count grows to fifty next month.
  • An alert carrying a source address, a destination address and a file hash is one signal, whatever the three verdicts were.
  • A hash that matched on twelve hosts is one signal, and a thousand hashes that matched nothing are none.
  • A watchlist reporting that a watched CVE gained a public exploit is none. That is an advisory, and advisories are not signals.

Three consequences worth naming:

  • The vulnerability unit is the remediation, not the CVE. One agent, one package to upgrade, one signal a month. A package gaining more CVEs next month is not a new charge, and re-reporting an open vulnerability every hour costs nothing.
  • The lookup unit is the alert, not the value. An alert typically carries several values, and it is metered once.
  • Scanning files is free. Matching one is the signal. Pharos checks every file hash the fleet reports against its indicator corpus and charges nothing for the ones that come back clean, which is almost all of them. A clean estate scanned every day costs nothing to scan.

The Billing page splits the month's signals by kind, per day and per manager, so a bill can be traced back to the sensor that produced it.

What is never a signal​

  • A watchlist firing. That is an advisory, and it has its own name for a reason: nobody sent it, Pharos generated it from a change in the catalog because a watchlist subscribed to that change, and it is not billed. Advisories have their own page in the console, next to the Signals inbox, and never touch the meter. What a watchlist is, and what counts as a change, is in The corpus.
  • Reading the corpus. Searches, facets and CVE pages are what the subscription buys, and none of it is metered.
  • A person pasting a value into Investigate. A person is not a sensor, and the lookup stays free even when the fleet is stopped at its limit.
  • Heartbeats and inventory reports from the sidecar.
  • An alert the sidecar answered from its own cache. It never reached Pharos, so it was never checked.

How the bill adds up​

Billing runs on a graduated ladder. The workspace does not pick a band. Every signal past the free allowance falls into a band by monthly volume, and the per-signal rate is lower in each higher band. The console's Billing page shows the ladder and where the month sits on it.

The total charged is the cheapest the ladder can produce for the month's volume, taken across the whole table rather than band by band. One effect of that rule is visible on the Billing page as a plateau near the top of each band: for a short stretch, sending more signals does not raise the bill, because the next band's lower rate applied to the larger volume produces the same total or less. The projected cost on the Billing page already accounts for this, so the figure it shows is the figure that is charged.

The monthly limit​

Every workspace carries a monthly limit, expressed in signals rather than in dollars, and the console shows the resulting price next to it. There are two numbers here, and which one stops the fleet depends on whether Pharos is switched on.

Before Pharos is switched on, the ceiling is the 500 free signals. The first 500 signals of every month are free, and while nothing is being charged that free allowance is the ceiling itself. It applies however the limit below is set: raising the limit to 200,000 on a workspace that has not been switched on still stops the fleet at 500, and the Billing page says so next to the control.

Once the workspace is metered, the limit applies. New workspaces start at 1,000 signals a month. The limit is self-service up to 200,000, and support raises it beyond that. An admin of the workspace sets it, and everybody else on the team sees where the month stands against it. The first 500 signals stay free and are deducted before any rate applies. Notices go out at 50, 80 and 100 percent, once each per billing month, and the counter is exact and live.

Stopping at the limit is the default. At 100 percent the fleet stops reporting, and that is a pause rather than an outage:

  • Heartbeats and inventory keep flowing, so the managers stay visible on the Managers page.
  • Investigate keeps answering.
  • The console, the search and the Signals inbox are unaffected.

Raising the limit lifts the stop at once, and the fleet resumes on its next check-in with the service, within about ten minutes. On resume the sidecar starts at the present rather than replaying the backlog, so a capped week does not become a burst bill. An admin of a metered workspace can turn stopping off, and the fleet then keeps reporting past the limit. On the free allowance that switch is refused, because there the stop is the only thing holding the workspace to what it agreed to spend.

The counter resets on the billing month boundary.

Switching Pharos on​

Closed beta

Pharos is in closed beta and pricing is being finalised. The meter runs exactly as described on this page, and the Billing page shows the month's signals and where they sit against the limit. No invoice is collected automatically: every invoice is held as a draft and reviewed by a person before anything is charged. The Billing page in the console is authoritative for what applies to a workspace.

Adding a card does not start the meter. The card belongs to the organization and is shared by every Wazuh Labs service, so turning Pharos on is a separate decision, and it is a button on the Billing page. Until an admin presses it the workspace is on the free allowance, which is why a fleet that has never been switched on stops at 500 signals however its limit is set.

The same button is what a non-billable organization presses. Some organizations are set to non-billable, so there is no card to add and nothing to pay: the meter still runs and every signal on it is waived. That does not lift the free ceiling on its own. Until Pharos is switched on the fleet stops at 500 signals a month exactly as it would for anyone else, and switching on is what hands the workspace its full limit at no cost. The Billing page says which of the two an organization is.