awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Open Source Splunk Alternatives

Ranking updated Jun 30, 2026

For an open source platform for log management, the first results are hyperdxio/hyperdx (HyperDX is a self-hosted OpenTelemetry observability platform that provides centralized log management with ingestion, full-text search, dashboards, and alerting, making it a strong open-source alternative to Splunk for log analytics), uptrace/uptrace and signoz/signoz (SigNoz is an open-source observability platform that provides log ingestion, full-text search, alerting, dashboards, and scalable storage via OpenTelemetry, directly matching the need for a self-hosted log management and analytics alternative to Splunk). openobserve/openobserve and grafana/loki round out the shortlist. Compare the match explanations and check the project documentation against your requirements.

Self-hosted log management and data analysis platforms for indexing, searching, and visualizing machine-generated operational data.

Open Source Splunk Alternatives

Find the best repos with AI.We'll search the best matching repositories with AI.
  • hyperdxio/hyperdxhyperdxio avatar

    hyperdxio/hyperdx

    9,324View on GitHub↗

    HyperDX is an OpenTelemetry observability platform that provides centralized log management, distributed tracing, and a self-hosted monitoring stack. It functions as a unified system for collecting, indexing, and visualizing logs, metrics, and traces from cloud and container environments. The platform distinguishes itself with specialized tooling for large language model monitoring and session replay, allowing user interactions in the browser to be linked to backend telemetry. It employs schema-less JSON parsing to index structured logs dynamically and uses source maps to resolve minified sta

    HyperDX is a self-hosted OpenTelemetry observability platform that provides centralized log management with ingestion, full-text search, dashboards, and alerting, making it a strong open-source alternative to Splunk for log analytics.

    TypeScriptAlerting SystemsFull Text SearchLog Ingestion
    View on GitHub↗9,324
  • uptrace/uptraceuptrace avatar

    uptrace/uptrace

    4,098View on GitHub↗

    Uptrace is an OpenTelemetry-based observability platform designed to collect, store, and analyze distributed traces, metrics, and logs. It functions as a centralized logging backend, a distributed tracing system, and a metrics engine to monitor application performance and system health. The platform is distinguished by AI-powered operational capabilities, allowing users to query telemetry data and manage monitoring dashboards using natural language. It specifically includes specialized monitoring for generative AI pipelines, tracking token usage and response quality for LLM interactions and r

    Uptrace is an OpenTelemetry-based observability platform that doubles as a centralized logging backend with full-text search, dashboards, alerting, and scalable ClickHouse storage, making it a solid self-hosted alternative to Splunk for ingesting and analyzing logs alongside metrics and traces.

    GoLog IngestionHTTP Log IngestionLog Forwarders
    View on GitHub↗4,098
  • signoz/signozSigNoz avatar

    SigNoz/signoz

    27,355View on GitHub↗

    SigNoz is a full-stack observability platform designed to collect, store, and visualize metrics, logs, and distributed traces in a unified environment. It leverages OpenTelemetry-based data collection to ingest telemetry from diverse sources using vendor-neutral protocols, ensuring interoperability across complex microservices architectures. The platform utilizes a high-performance columnar storage engine to enable rapid aggregation and filtering, providing a centralized backend for monitoring application health and performance. What distinguishes the platform is its focus on automated instru

    SigNoz is an open-source observability platform that provides log ingestion, full-text search, alerting, dashboards, and scalable storage via OpenTelemetry, directly matching the need for a self-hosted log management and analytics alternative to Splunk.

    TypeScriptLog IngestionAlert RoutingLog Processing Pipelines
    View on GitHub↗27,355
  • openobserve/openobserveopenobserve avatar

    openobserve/openobserve

    17,937View on GitHub↗

    OpenObserve is a unified observability data platform designed to ingest, store, and analyze logs, metrics, and traces. It functions as a cloud-native monitoring tool that centralizes telemetry from diverse sources, including standard collectors and cloud service providers, into a single, scalable system. By utilizing a columnar storage engine backed by object storage, the platform enables efficient long-term data retention and high-performance analytical querying. The platform distinguishes itself through deep integration with artificial intelligence, allowing users to query data using natura

    OpenObserve is a cloud-native observability platform purpose-built for ingesting, searching, and analyzing logs (along with metrics and traces) using columnar storage on object stores, directly addressing the need for a self-hostable Splunk alternative with full-text search, alerting, dashboards, and multi-source support.

    TypeScriptAlert Routing
    View on GitHub↗17,937
  • grafana/lokigrafana avatar

    grafana/loki

    27,640View on GitHub↗

    Loki is a horizontally scalable, highly available log aggregation engine designed to store and query massive volumes of unstructured log data. It functions as a distributed observability platform that correlates logs, metrics, and traces to provide comprehensive visibility into the health and performance of complex infrastructure. The system distinguishes itself through a distributed query execution model that processes large datasets in parallel across cluster nodes. It utilizes label-based stream indexing and a distributed index to map log data to specific chunks, enabling rapid retrieval w

    Loki is a horizontally scalable log aggregation engine that stores and indexes logs with labels, enabling fast querying via its LogQL language, and integrates seamlessly with Grafana and Prometheus to provide the dashboards, alerting, and real-time monitoring needed for a Splunk-like experience — all in a self-hostable, multi-source observability platform.

    GoDistributed Observability SystemsLog Storage EnginesObservability Platforms
    View on GitHub↗27,640
  • opensearch-project/opensearchopensearch-project avatar

    opensearch-project/OpenSearch

    13,196View on GitHub↗

    OpenSearch is a distributed search and analytics engine designed for indexing, searching, and analyzing massive volumes of structured and unstructured data in real time. It functions as a comprehensive platform that integrates enterprise-grade search capabilities, a vector database for high-dimensional similarity lookups, and a unified observability suite for monitoring logs, metrics, and traces across complex distributed environments. The platform distinguishes itself through its support for agentic workflow automation, allowing users to orchestrate multi-agent tasks and integrate foundation

    OpenSearch is a distributed search and analytics engine that serves as a full-featured log management and observability platform, offering full-text search, real-time monitoring, alerting, dashboards via OpenSearch Dashboards, and scalable storage—making it a direct and comprehensive alternative to Splunk for ingesting and analyzing logs.

    JavaSearch and Analytics EnginesAgentic Workflow AutomationLucene-Based Search Engines
    View on GitHub↗13,196
  • highlight/highlighthighlight avatar

    highlight/highlight

    9,303View on GitHub↗

    Highlight is a full-stack observability platform and monitoring system that aggregates logs, errors, and distributed traces to provide a unified view of application health. It functions as a distributed tracing system, an error monitoring service, and a session replay tool. The platform is available as a dockerized monitoring stack for self-hosted deployments on Linux. It distinguishes itself by combining backend observability with a visual recording system that captures document object model changes and network requests to replay user interactions. The system covers several core capability

    Highlight is a self-hostable observability platform that ingests, indexes, and searches logs alongside traces and errors, offering dashboards and alerting — a viable Splunk alternative despite its broader focus.

    TypeScriptDistributed Tracing SystemsCentralized Logging SystemsDistributed Request Tracing
    View on GitHub↗9,303
  • fluent/fluentdfluent avatar

    fluent/fluentd

    13,554View on GitHub↗

    Fluentd is a unified logging layer and distributed event router that collects, parses, and routes log data from diverse sources to various storage backends. It functions as a log forwarding agent and pipeline orchestrator, transforming raw unstructured log strings into formatted objects using structured log parsing. The project utilizes a plugin-based pipeline architecture to route data through independent input, filter, and output stages. It differentiates itself through tag-based event routing, which uses regular expression patterns to direct specific data streams to their intended destinat

    Fluentd is a log forwarding agent and pipeline orchestrator that handles ingestion and routing, but it lacks the search, storage, alerting, and visualization features expected in a full Splunk alternative, making it a building block rather than a complete platform.

    RubyHTTP Log IngestionLog ForwardersSyslog Ingestion
    View on GitHub↗13,554
  • fluent/fluent-bitfluent avatar

    fluent/fluent-bit

    7,946View on GitHub↗

    Fluent Bit is a cloud-native log shipper and unified telemetry collector designed as a resource-efficient data pipeline. It ingests logs, metrics, and traces from multiple sources, processing them in real-time before routing the data to external storage backends. The project functions as a real-time stream processor and OpenTelemetry log processor, capable of transforming and filtering data using SQL and conditional logic. It also acts as a distributed tracing agent that can sample traces to reduce data volume while preserving full request paths. The system provides reliable data delivery th

    Fluent Bit is a lightweight, high-performance log shipper and telemetry collector that ingests and routes logs to external backends, but it does not provide the built-in search, storage, dashboards, or alerting needed for a full log management and analytics platform like Splunk — it is a building block rather than the complete tool.

    CLog IngestionLog ForwardersLogging Pipelines
    View on GitHub↗7,946
  • sqshq/samplersqshq avatar

    sqshq/sampler

    14,577View on GitHub↗

    Sampler is a shell command monitoring tool and terminal-based metrics dashboard. It functions as a YAML-configured shell orchestrator that executes commands at set intervals to collect data and monitor system metrics. The tool distinguishes itself by rendering real-time shell output as terminal widgets, such as sparklines, gauges, bar charts, and run charts. It also includes a conditional alerting system that triggers audio notifications, visual alerts, or secondary shell commands when sampled output matches predefined data conditions. The project covers broad capability areas including shel

    Sampler is a terminal-based metrics dashboard that runs shell commands and renders real-time widgets with alerting, but it is not a log management platform — it lacks log ingestion, full-text search, and centralised multi-source storage needed for a Splunk alternative.

    GoAlerting SystemsAlerting Systems
    View on GitHub↗14,577
  • blevesearch/bleveblevesearch avatar

    blevesearch/bleve

    10,986View on GitHub↗

    Bleve is a search indexing engine library written in Go, designed to provide full-text search and document retrieval capabilities for embedded application data. It functions as a framework for indexing structured or unstructured information, allowing developers to build searchable collections that support complex query logic and data analysis. The engine distinguishes itself through a pluggable analysis pipeline that normalizes text before indexing, alongside support for vector similarity search to identify semantically related content. It utilizes finite-state transducer automata for efficie

    Bleve is a full-text search engine library for embedding in applications, not a standalone log management and analytics platform — it provides the search indexing piece but lacks the log ingestion pipelines, alerting, dashboards, and multi-source collection tools needed to replace Splunk.

    GoFull Text SearchFull-Text Search Engines
    View on GitHub↗10,986
  • prabhatsharma/zincprabhatsharma avatar

    prabhatsharma/zinc

    17,856View on GitHub↗

    Zinc is a high-performance full-text search engine written in Go. It provides a schema-less document index that organizes arbitrary datasets into searchable structures without requiring a predefined data format. The engine features an API compatible with Elasticsearch for indexing and querying data, which facilitates the ingestion of single and bulk records. It is designed as an in-process search engine that embeds indexing and retrieval logic within a single binary to operate with minimal system resource overhead. The system includes a built-in web-based management interface for executing s

    Zinc is a high-performance search engine with an Elasticsearch-compatible API suitable for indexing arbitrary data, but it is not a full log management platform—it lacks built-in log ingestion pipelines, alerting, and rich dashboards that a Splunk alternative requires.

    GoFull Text SearchFull-Text Search Engines
    View on GitHub↗17,856
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
hyperdxio/hyperdx9.3KTypeScriptmitFeb 21, 2026
uptrace/uptrace4.1KGoagpl-3.0Jan 21, 2026
signoz/signoz
27.4K
TypeScript
NOASSERTION
Jun 16, 2026
openobserve/openobserve17.9KTypeScriptagpl-3.0Feb 20, 2026
grafana/loki27.6KGoagpl-3.0Feb 20, 2026
opensearch-project/opensearch13.2KJavaApache-2.0Jun 16, 2026
highlight/highlight9.3KTypeScriptNOASSERTIONApr 16, 2026
fluent/fluentd13.6KRubyApache-2.0Jun 15, 2026
fluent/fluent-bit7.9KCApache-2.0Jun 26, 2026
sqshq/sampler14.6KGoGPL-3.0Feb 22, 2024

Related searches

  • a self-hosted SIEM
  • an open source platform for error tracking
  • an open source SIEM for log analysis
  • an open source alternative to Grafana
  • an open source application performance monitoring tool
  • an open source network monitoring tool
  • a centralized log aggregation system
  • a log search and analytics engine