For an open source SIEM for log analysis, the strongest matches are wazuh/wazuh (Wazuh is a full-featured open-source SIEM platform that combines), fluent/fluent-bit (Fluent Bit is a lightweight log shipper and telemetry) and fluent/fluentd (Fluentd is a log collection and routing pipeline, not). misp/misp and deviantony/docker-elk round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
We curate open-source GitHub repositories matching “open source siem”. Results are ranked by relevance to your query — pick filters below to narrow, or refine with AI.
Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito
Wazuh is a full-featured open-source SIEM platform that combines endpoint detection and response with centralized log collection, event correlation, alerting, and real-time monitoring, making it a comprehensive match for your security information and event management needs.
Fluent Bit is a cloud-native log shipper and unified telemetry collector designed as a resource-efficient data pipeline. It ingests logs, metrics, and traces from multiple sources, processing them in real-time before routing the data to external storage backends. The project functions as a real-time stream processor and OpenTelemetry log processor, capable of transforming and filtering data using SQL and conditional logic. It also acts as a distributed tracing agent that can sample traces to reduce data volume while preserving full request paths. The system provides reliable data delivery th
Fluent Bit is a lightweight log shipper and telemetry collector, not a full SIEM platform—it handles ingestion and routing but lacks the event correlation, alerting, and built-in dashboards that an open-source SIEM requires.
Fluentd is a unified logging layer and distributed event router that collects, parses, and routes log data from diverse sources to various storage backends. It functions as a log forwarding agent and pipeline orchestrator, transforming raw unstructured log strings into formatted objects using structured log parsing. The project utilizes a plugin-based pipeline architecture to route data through independent input, filter, and output stages. It differentiates itself through tag-based event routing, which uses regular expression patterns to direct specific data streams to their intended destinat
Fluentd is a log collection and routing pipeline, not a full SIEM platform—it handles log ingestion but lacks event correlation, alerting, dashboards, and threat intelligence features you need.
MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish
MISP is a threat intelligence sharing platform for exchanging and correlating structured indicators, not a SIEM that ingests and analyzes logs from infrastructure—so it lacks the log collection and real-time monitoring central to a SIEM.
This project is a containerized orchestration layer for the Elastic Stack, providing a pre-configured set of Docker Compose files to deploy Elasticsearch, Logstash, and Kibana as a unified data analysis stack. It functions as a centralized log management system for ingesting, indexing, and searching log data using a cluster of interconnected services. The deployment pattern includes an Elasticsearch cluster manager that enables scaling data nodes through replica scaling and internal discovery. It provides a web-based administration interface for monitoring cluster health and status. The syst
This repository provides Docker Compose files to deploy the Elastic Stack (Elasticsearch, Logstash, Kibana) for centralized log management, but it is not itself a SIEM platform—it is an orchestration layer that can be configured for SIEM purposes if additional security and detection components (like Elastic Security) are added.
HyperDX is an OpenTelemetry observability platform that provides centralized log management, distributed tracing, and a self-hosted monitoring stack. It functions as a unified system for collecting, indexing, and visualizing logs, metrics, and traces from cloud and container environments. The platform distinguishes itself with specialized tooling for large language model monitoring and session replay, allowing user interactions in the browser to be linked to backend telemetry. It employs schema-less JSON parsing to index structured logs dynamically and uses source maps to resolve minified sta
HyperDX is an OpenTelemetry-based observability platform focused on application performance and log management, but it lacks the security event correlation, threat detection, and SIEM-specific workflows that this search requires.
SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati
SpiderFoot is an OSINT reconnaissance and threat intelligence automation framework that collects external data from public sources, not a SIEM for ingesting and analyzing internal security logs — it lacks the core log management, real-time alerting, and event correlation this search demands.
Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that
Sigma is a detection-rule format and translation tool used to write and convert signatures across SIEM backends, but it is not a SIEM platform itself—it does not collect logs, correlate events, or provide dashboards, so it meets only a narrow part of what you need.
SigNoz is a full-stack observability platform designed to collect, store, and visualize metrics, logs, and distributed traces in a unified environment. It leverages OpenTelemetry-based data collection to ingest telemetry from diverse sources using vendor-neutral protocols, ensuring interoperability across complex microservices architectures. The platform utilizes a high-performance columnar storage engine to enable rapid aggregation and filtering, providing a centralized backend for monitoring application health and performance. What distinguishes the platform is its focus on automated instru
SigNoz is a full-stack observability platform for collecting and analyzing metrics, logs, and traces using OpenTelemetry, but it is designed for application performance monitoring rather than security event management and threat detection.
Apache NiFi is a flow-based programming platform that enables the visual design, monitoring, and management of data pipelines. At its core, it provides a web-based visual dataflow designer where users build directed graphs of processors to route, transform, and mediate data movement between any source and destination without writing custom code. The system records fine-grained data provenance for every data item from ingestion to delivery, supporting audit, debugging, and replay of data lineage. The platform distinguishes itself through a zero-master cluster architecture that distributes proc
Apache NiFi is a general-purpose data pipeline and integration platform, not a SIEM — it can handle log collection and routing but lacks the built-in event correlation, alerting, and threat intelligence features that define a security information and event management system.
This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base
This repository is a rule library for Elasticsearch-based detection, not a SIEM platform itself—it provides threat detection content but lacks the log collection, correlation engine, dashboards, and alerting infrastructure needed for a self-contained SIEM.
VictoriaMetrics is a high-performance, scalable time series database and observability platform designed for long-term storage and analysis of metric, log, and trace data. It functions as a unified backend for monitoring ecosystems, offering full compatibility with industry-standard protocols and query languages. The system is built to handle massive data volumes through a distributed architecture that supports horizontal scaling and efficient data lifecycle management. The platform distinguishes itself through a storage engine that utilizes consistent hashing for data sharding and log-struct
VictoriaMetrics is a high-performance time series database and observability platform that can store and query logs alongside metrics, but it is not a dedicated SIEM with security-specific event correlation, threat detection, or alerting — it functions more as a scalable backend for monitoring rather than a complete security information and event management system.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| wazuh/wazuh | 14.8K | C | other | |
| fluent/fluent-bit | 7.9K | C | Apache-2.0 | |
| fluent/fluentd | 13.6K | Ruby | Apache-2.0 | |
| misp/misp | 6.4K | PHP | AGPL-3.0 | |
| deviantony/docker-elk | 18.4K | Shell | MIT | |
| hyperdxio/hyperdx | 9.3K | TypeScript | mit | |
| smicallef/spiderfoot | 18.2K | Python | MIT | |
| sigmahq/sigma | 10.1K | Python | other | |
| signoz/signoz | 27.4K | TypeScript | NOASSERTION | |
| apache/nifi | 6K | Java | apache-2.0 |