Having worked on a machine learning time series document search solution for the last 2 years, I know exactly why the cost of this is so high. Running logs through a model must be VERY expensive.
I had a good friend at Splunk who passed a few years ago. He was working on something similar, well before we had decent models. His anomaly detection used differences in regular expression patterns to detect "strange things". I guess that's why he carried the title "Chief Mind".
I'm excited where ML and time series data is going. It's going to be interesting!