awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

security information and event management (SIEM)

Ranking updated Jun 30, 2026

For an open source SIEM for log analysis, the strongest matches are wazuh/wazuh (Wazuh is a full-featured open-source SIEM platform that combines), fluent/fluent-bit (Fluent Bit is a lightweight log shipper and telemetry) and fluent/fluentd (Fluentd is a log collection and routing pipeline, not). misp/misp and deviantony/docker-elk round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

We curate open-source GitHub repositories matching “open source siem”. Results are ranked by relevance to your query — pick filters below to narrow, or refine with AI.

security information and event management (SIEM)

Find the best repos with AI.We'll search the best matching repositories with AI.
  • wazuh/wazuhwazuh avatar

    wazuh/wazuh

    14,779View on GitHub↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Wazuh is a full-featured open-source SIEM platform that combines endpoint detection and response with centralized log collection, event correlation, alerting, and real-time monitoring, making it a comprehensive match for your security information and event management needs.

    CTelemetry Correlation Engines
    View on GitHub↗14,779
  • fluent/fluent-bitfluent avatar

    fluent/fluent-bit

    7,946View on GitHub↗

    Fluent Bit is a cloud-native log shipper and unified telemetry collector designed as a resource-efficient data pipeline. It ingests logs, metrics, and traces from multiple sources, processing them in real-time before routing the data to external storage backends. The project functions as a real-time stream processor and OpenTelemetry log processor, capable of transforming and filtering data using SQL and conditional logic. It also acts as a distributed tracing agent that can sample traces to reduce data volume while preserving full request paths. The system provides reliable data delivery th

    Fluent Bit is a lightweight log shipper and telemetry collector, not a full SIEM platform—it handles ingestion and routing but lacks the event correlation, alerting, and built-in dashboards that an open-source SIEM requires.

    CLog IngestionLogging PipelinesLog Forwarders
    View on GitHub↗7,946
  • fluent/fluentdfluent avatar

    fluent/fluentd

    13,554View on GitHub↗

    Fluentd is a unified logging layer and distributed event router that collects, parses, and routes log data from diverse sources to various storage backends. It functions as a log forwarding agent and pipeline orchestrator, transforming raw unstructured log strings into formatted objects using structured log parsing. The project utilizes a plugin-based pipeline architecture to route data through independent input, filter, and output stages. It differentiates itself through tag-based event routing, which uses regular expression patterns to direct specific data streams to their intended destinat

    Fluentd is a log collection and routing pipeline, not a full SIEM platform—it handles log ingestion but lacks event correlation, alerting, dashboards, and threat intelligence features you need.

    RubyLog ForwardersSyslog Ingestion
    View on GitHub↗13,554
  • misp/mispMISP avatar

    MISP/MISP

    6,360View on GitHub↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    MISP is a threat intelligence sharing platform for exchanging and correlating structured indicators, not a SIEM that ingests and analyzes logs from infrastructure—so it lacks the log collection and real-time monitoring central to a SIEM.

    PHPSecurity Event CorrelationThreat Intelligence
    View on GitHub↗6,360
  • deviantony/docker-elkdeviantony avatar

    deviantony/docker-elk

    18,375View on GitHub↗

    This project is a containerized orchestration layer for the Elastic Stack, providing a pre-configured set of Docker Compose files to deploy Elasticsearch, Logstash, and Kibana as a unified data analysis stack. It functions as a centralized log management system for ingesting, indexing, and searching log data using a cluster of interconnected services. The deployment pattern includes an Elasticsearch cluster manager that enables scaling data nodes through replica scaling and internal discovery. It provides a web-based administration interface for monitoring cluster health and status. The syst

    This repository provides Docker Compose files to deploy the Elastic Stack (Elasticsearch, Logstash, Kibana) for centralized log management, but it is not itself a SIEM platform—it is an orchestration layer that can be configured for SIEM purposes if additional security and detection components (like Elastic Security) are added.

    ShellLog Ingestion
    View on GitHub↗18,375
  • hyperdxio/hyperdxhyperdxio avatar

    hyperdxio/hyperdx

    9,324View on GitHub↗

    HyperDX is an OpenTelemetry observability platform that provides centralized log management, distributed tracing, and a self-hosted monitoring stack. It functions as a unified system for collecting, indexing, and visualizing logs, metrics, and traces from cloud and container environments. The platform distinguishes itself with specialized tooling for large language model monitoring and session replay, allowing user interactions in the browser to be linked to backend telemetry. It employs schema-less JSON parsing to index structured logs dynamically and uses source maps to resolve minified sta

    HyperDX is an OpenTelemetry-based observability platform focused on application performance and log management, but it lacks the security event correlation, threat detection, and SIEM-specific workflows that this search requires.

    TypeScriptLog IngestionLog ForwardersAlert Routing
    View on GitHub↗9,324
  • smicallef/spiderfootsmicallef avatar

    smicallef/spiderfoot

    18,189View on GitHub↗

    SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati

    SpiderFoot is an OSINT reconnaissance and threat intelligence automation framework that collects external data from public sources, not a SIEM for ingesting and analyzing internal security logs — it lacks the core log management, real-time alerting, and event correlation this search demands.

    PythonThreat Actor Tracking ToolsThreat Intelligence Platforms
    View on GitHub↗18,189
  • sigmahq/sigmaSigmaHQ avatar

    SigmaHQ/sigma

    10,136View on GitHub↗

    Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that

    Sigma is a detection-rule format and translation tool used to write and convert signatures across SIEM backends, but it is not a SIEM platform itself—it does not collect logs, correlate events, or provide dashboards, so it meets only a narrow part of what you need.

    PythonSecurity Event Correlation
    View on GitHub↗10,136
  • signoz/signozSigNoz avatar

    SigNoz/signoz

    27,355View on GitHub↗

    SigNoz is a full-stack observability platform designed to collect, store, and visualize metrics, logs, and distributed traces in a unified environment. It leverages OpenTelemetry-based data collection to ingest telemetry from diverse sources using vendor-neutral protocols, ensuring interoperability across complex microservices architectures. The platform utilizes a high-performance columnar storage engine to enable rapid aggregation and filtering, providing a centralized backend for monitoring application health and performance. What distinguishes the platform is its focus on automated instru

    SigNoz is a full-stack observability platform for collecting and analyzing metrics, logs, and traces using OpenTelemetry, but it is designed for application performance monitoring rather than security event management and threat detection.

    TypeScriptLog IngestionAlert RoutingTelemetry Correlation Engines
    View on GitHub↗27,355
  • apache/nifiapache avatar

    apache/nifi

    5,976View on GitHub↗

    Apache NiFi is a flow-based programming platform that enables the visual design, monitoring, and management of data pipelines. At its core, it provides a web-based visual dataflow designer where users build directed graphs of processors to route, transform, and mediate data movement between any source and destination without writing custom code. The system records fine-grained data provenance for every data item from ingestion to delivery, supporting audit, debugging, and replay of data lineage. The platform distinguishes itself through a zero-master cluster architecture that distributes proc

    Apache NiFi is a general-purpose data pipeline and integration platform, not a SIEM — it can handle log collection and routing but lacks the built-in event correlation, alerting, and threat intelligence features that define a security information and event management system.

    JavaReal-Time Monitoring DashboardsHorizontal Scaling
    View on GitHub↗5,976
  • elastic/detection-ruleselastic avatar

    elastic/detection-rules

    2,508View on GitHub↗

    This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base

    This repository is a rule library for Elasticsearch-based detection, not a SIEM platform itself—it provides threat detection content but lacks the log collection, correlation engine, dashboards, and alerting infrastructure needed for a self-contained SIEM.

    PythonSecurity Event Correlation
    View on GitHub↗2,508
  • victoriametrics/victoriametricsVictoriaMetrics avatar

    VictoriaMetrics/VictoriaMetrics

    16,343View on GitHub↗

    VictoriaMetrics is a high-performance, scalable time series database and observability platform designed for long-term storage and analysis of metric, log, and trace data. It functions as a unified backend for monitoring ecosystems, offering full compatibility with industry-standard protocols and query languages. The system is built to handle massive data volumes through a distributed architecture that supports horizontal scaling and efficient data lifecycle management. The platform distinguishes itself through a storage engine that utilizes consistent hashing for data sharding and log-struct

    VictoriaMetrics is a high-performance time series database and observability platform that can store and query logs alongside metrics, but it is not a dedicated SIEM with security-specific event correlation, threat detection, or alerting — it functions more as a scalable backend for monitoring rather than a complete security information and event management system.

    GoLog IngestionLog ForwardersMetric Visualization Tools
    View on GitHub↗16,343
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
wazuh/wazuh14.8KCotherFeb 20, 2026
fluent/fluent-bit7.9KCApache-2.0Jun 26, 2026
fluent/fluentd13.6KRubyApache-2.0Jun 15, 2026
misp/misp6.4KPHPAGPL-3.0Jun 17, 2026
deviantony/docker-elk18.4KShellMITJun 22, 2026
hyperdxio/hyperdx9.3KTypeScriptmitFeb 21, 2026
smicallef/spiderfoot18.2KPythonMITApr 13, 2026
sigmahq/sigma10.1KPythonotherFeb 19, 2026
signoz/signoz27.4KTypeScriptNOASSERTIONJun 16, 2026
apache/nifi6KJavaapache-2.0Feb 20, 2026

Related searches

  • a self-hosted SIEM
  • an open source platform for log management
  • an intrusion detection system
  • an open source alternative to SolarWinds
  • an open source network monitoring tool
  • Blue Team, SIEM and Threat Detection
  • an open source platform for error tracking
  • an open source network monitoring tool