For an open source platform for log management, the first results are hyperdxio/hyperdx (HyperDX is a self-hosted OpenTelemetry observability platform that provides centralized log management with ingestion, full-text search, dashboards, and alerting, making it a strong open-source alternative to Splunk for log analytics), uptrace/uptrace and signoz/signoz (SigNoz is an open-source observability platform that provides log ingestion, full-text search, alerting, dashboards, and scalable storage via OpenTelemetry, directly matching the need for a self-hosted log management and analytics alternative to Splunk). openobserve/openobserve and grafana/loki round out the shortlist. Compare the match explanations and check the project documentation against your requirements.
Self-hosted log management and data analysis platforms for indexing, searching, and visualizing machine-generated operational data.
HyperDX is an OpenTelemetry observability platform that provides centralized log management, distributed tracing, and a self-hosted monitoring stack. It functions as a unified system for collecting, indexing, and visualizing logs, metrics, and traces from cloud and container environments. The platform distinguishes itself with specialized tooling for large language model monitoring and session replay, allowing user interactions in the browser to be linked to backend telemetry. It employs schema-less JSON parsing to index structured logs dynamically and uses source maps to resolve minified sta
HyperDX is a self-hosted OpenTelemetry observability platform that provides centralized log management with ingestion, full-text search, dashboards, and alerting, making it a strong open-source alternative to Splunk for log analytics.
Uptrace is an OpenTelemetry-based observability platform designed to collect, store, and analyze distributed traces, metrics, and logs. It functions as a centralized logging backend, a distributed tracing system, and a metrics engine to monitor application performance and system health. The platform is distinguished by AI-powered operational capabilities, allowing users to query telemetry data and manage monitoring dashboards using natural language. It specifically includes specialized monitoring for generative AI pipelines, tracking token usage and response quality for LLM interactions and r
Uptrace is an OpenTelemetry-based observability platform that doubles as a centralized logging backend with full-text search, dashboards, alerting, and scalable ClickHouse storage, making it a solid self-hosted alternative to Splunk for ingesting and analyzing logs alongside metrics and traces.
SigNoz is a full-stack observability platform designed to collect, store, and visualize metrics, logs, and distributed traces in a unified environment. It leverages OpenTelemetry-based data collection to ingest telemetry from diverse sources using vendor-neutral protocols, ensuring interoperability across complex microservices architectures. The platform utilizes a high-performance columnar storage engine to enable rapid aggregation and filtering, providing a centralized backend for monitoring application health and performance. What distinguishes the platform is its focus on automated instru
SigNoz is an open-source observability platform that provides log ingestion, full-text search, alerting, dashboards, and scalable storage via OpenTelemetry, directly matching the need for a self-hosted log management and analytics alternative to Splunk.
OpenObserve is a unified observability data platform designed to ingest, store, and analyze logs, metrics, and traces. It functions as a cloud-native monitoring tool that centralizes telemetry from diverse sources, including standard collectors and cloud service providers, into a single, scalable system. By utilizing a columnar storage engine backed by object storage, the platform enables efficient long-term data retention and high-performance analytical querying. The platform distinguishes itself through deep integration with artificial intelligence, allowing users to query data using natura
OpenObserve is a cloud-native observability platform purpose-built for ingesting, searching, and analyzing logs (along with metrics and traces) using columnar storage on object stores, directly addressing the need for a self-hostable Splunk alternative with full-text search, alerting, dashboards, and multi-source support.
Loki is a horizontally scalable, highly available log aggregation engine designed to store and query massive volumes of unstructured log data. It functions as a distributed observability platform that correlates logs, metrics, and traces to provide comprehensive visibility into the health and performance of complex infrastructure. The system distinguishes itself through a distributed query execution model that processes large datasets in parallel across cluster nodes. It utilizes label-based stream indexing and a distributed index to map log data to specific chunks, enabling rapid retrieval w
Loki is a horizontally scalable log aggregation engine that stores and indexes logs with labels, enabling fast querying via its LogQL language, and integrates seamlessly with Grafana and Prometheus to provide the dashboards, alerting, and real-time monitoring needed for a Splunk-like experience — all in a self-hostable, multi-source observability platform.
OpenSearch is a distributed search and analytics engine designed for indexing, searching, and analyzing massive volumes of structured and unstructured data in real time. It functions as a comprehensive platform that integrates enterprise-grade search capabilities, a vector database for high-dimensional similarity lookups, and a unified observability suite for monitoring logs, metrics, and traces across complex distributed environments. The platform distinguishes itself through its support for agentic workflow automation, allowing users to orchestrate multi-agent tasks and integrate foundation
OpenSearch is a distributed search and analytics engine that serves as a full-featured log management and observability platform, offering full-text search, real-time monitoring, alerting, dashboards via OpenSearch Dashboards, and scalable storage—making it a direct and comprehensive alternative to Splunk for ingesting and analyzing logs.
Highlight is a full-stack observability platform and monitoring system that aggregates logs, errors, and distributed traces to provide a unified view of application health. It functions as a distributed tracing system, an error monitoring service, and a session replay tool. The platform is available as a dockerized monitoring stack for self-hosted deployments on Linux. It distinguishes itself by combining backend observability with a visual recording system that captures document object model changes and network requests to replay user interactions. The system covers several core capability
Highlight is a self-hostable observability platform that ingests, indexes, and searches logs alongside traces and errors, offering dashboards and alerting — a viable Splunk alternative despite its broader focus.
Fluentd is a unified logging layer and distributed event router that collects, parses, and routes log data from diverse sources to various storage backends. It functions as a log forwarding agent and pipeline orchestrator, transforming raw unstructured log strings into formatted objects using structured log parsing. The project utilizes a plugin-based pipeline architecture to route data through independent input, filter, and output stages. It differentiates itself through tag-based event routing, which uses regular expression patterns to direct specific data streams to their intended destinat
Fluentd is a log forwarding agent and pipeline orchestrator that handles ingestion and routing, but it lacks the search, storage, alerting, and visualization features expected in a full Splunk alternative, making it a building block rather than a complete platform.
Fluent Bit is a cloud-native log shipper and unified telemetry collector designed as a resource-efficient data pipeline. It ingests logs, metrics, and traces from multiple sources, processing them in real-time before routing the data to external storage backends. The project functions as a real-time stream processor and OpenTelemetry log processor, capable of transforming and filtering data using SQL and conditional logic. It also acts as a distributed tracing agent that can sample traces to reduce data volume while preserving full request paths. The system provides reliable data delivery th
Fluent Bit is a lightweight, high-performance log shipper and telemetry collector that ingests and routes logs to external backends, but it does not provide the built-in search, storage, dashboards, or alerting needed for a full log management and analytics platform like Splunk — it is a building block rather than the complete tool.
Sampler is a shell command monitoring tool and terminal-based metrics dashboard. It functions as a YAML-configured shell orchestrator that executes commands at set intervals to collect data and monitor system metrics. The tool distinguishes itself by rendering real-time shell output as terminal widgets, such as sparklines, gauges, bar charts, and run charts. It also includes a conditional alerting system that triggers audio notifications, visual alerts, or secondary shell commands when sampled output matches predefined data conditions. The project covers broad capability areas including shel
Sampler is a terminal-based metrics dashboard that runs shell commands and renders real-time widgets with alerting, but it is not a log management platform — it lacks log ingestion, full-text search, and centralised multi-source storage needed for a Splunk alternative.
Bleve is a search indexing engine library written in Go, designed to provide full-text search and document retrieval capabilities for embedded application data. It functions as a framework for indexing structured or unstructured information, allowing developers to build searchable collections that support complex query logic and data analysis. The engine distinguishes itself through a pluggable analysis pipeline that normalizes text before indexing, alongside support for vector similarity search to identify semantically related content. It utilizes finite-state transducer automata for efficie
Bleve is a full-text search engine library for embedding in applications, not a standalone log management and analytics platform — it provides the search indexing piece but lacks the log ingestion pipelines, alerting, dashboards, and multi-source collection tools needed to replace Splunk.
Zinc is a high-performance full-text search engine written in Go. It provides a schema-less document index that organizes arbitrary datasets into searchable structures without requiring a predefined data format. The engine features an API compatible with Elasticsearch for indexing and querying data, which facilitates the ingestion of single and bulk records. It is designed as an in-process search engine that embeds indexing and retrieval logic within a single binary to operate with minimal system resource overhead. The system includes a built-in web-based management interface for executing s
Zinc is a high-performance search engine with an Elasticsearch-compatible API suitable for indexing arbitrary data, but it is not a full log management platform—it lacks built-in log ingestion pipelines, alerting, and rich dashboards that a Splunk alternative requires.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| hyperdxio/hyperdx | 9.3K | TypeScript | mit | |
| uptrace/uptrace | 4.1K | Go | agpl-3.0 | |
| signoz/signoz |
| 27.4K |
| TypeScript |
| NOASSERTION |
| openobserve/openobserve | 17.9K | TypeScript | agpl-3.0 |
| grafana/loki | 27.6K | Go | agpl-3.0 |
| opensearch-project/opensearch | 13.2K | Java | Apache-2.0 |
| highlight/highlight | 9.3K | TypeScript | NOASSERTION |
| fluent/fluentd | 13.6K | Ruby | Apache-2.0 |
| fluent/fluent-bit | 7.9K | C | Apache-2.0 |
| sqshq/sampler | 14.6K | Go | GPL-3.0 |