License & Deployment Mix: 33 tools – 13 OSS, 14 SaaS. (OSS and SaaS counts can overlap when an open-source tool also offers a vendor-hosted edition.)
What Is SIEM?
Security Information and Event Management (SIEM) is a security technology that collects, normalizes, correlates, and analyzes log data from across an organization’s entire IT environment – servers, network devices, applications, endpoints, cloud services, and identity providers – to detect security threats, support incident investigation, and meet compliance requirements.
SIEM platforms combine two historically separate functions:
- SIM (Security Information Management) – long-term log collection, storage, and compliance reporting
- SEM (Security Event Management) – real-time event correlation, alerting, and dashboarding
Modern SIEM has evolved far beyond simple log aggregation. Today’s platforms incorporate User and Entity Behavior Analytics (UEBA), machine learning for anomaly detection, threat intelligence feeds, Security Orchestration Automation and Response (SOAR) capabilities, and detection-as-code workflows. The boundary between SIEM, XDR, and security data lakes is increasingly blurred.
Enterprise SIEM platforms provide:
- Log collection and normalization – ingest logs from hundreds of source types (syslog, agents, API collectors, cloud connectors) and normalize them into a common schema for cross-source correlation
- Correlation rules – define detection logic that matches patterns across multiple log sources and time windows; MITRE ATT&CK mapping; chained rules for multi-stage attack detection
- UEBA (User and Entity Behavior Analytics) – ML-driven baselines of normal user and device behavior; detect anomalies such as impossible travel, unusual access patterns, privilege escalation, and lateral movement
- Threat intelligence – ingest IOC feeds (STIX/ TAXII, MISP, commercial feeds) and automatically correlate against incoming logs for known-bad IPs, domains, file hashes, and TTPs
- Incident response – case management, alert triage, investigation timelines, evidence collection, and analyst collaboration; SOAR playbooks for automated response actions
- Compliance reporting – pre-built report templates for PCI-DSS, HIPAA, SOX, GDPR, SOC 2, NIST, and CIS; scheduled report generation; audit trail and evidence export
- Threat hunting – ad-hoc search across historical log data; query languages (SPL, KQL, Lucene, SQL) for proactive investigation; saved searches and hunt notebooks
- Dashboards and visualization – real-time security dashboards; drill-down from summary metrics to individual events; geographic and timeline visualizations
- Multi-tenancy – centralized management of multiple customer environments with data isolation; per-tenant rules, dashboards, and retention policies; essential for MSPs and MSSPs
SIEM is the backbone of Security Operations Centers (SOCs). Without SIEM, security teams lack the centralized visibility needed to detect attacks that span multiple systems, correlate seemingly unrelated events into coherent incident timelines, and demonstrate compliance to auditors.
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
This evaluation covers the full SIEM and security log-analytics landscape: self-hosted open source, commercial, and cloud-native platforms.
Overview Comparison
| Tool | Type | License | Deployment | Language / Platform | Pricing Model |
|---|---|---|---|---|---|
| Wazuh | XDR/SIEM | GPL-2.0 | Self-hosted | C, Python / Linux | Free; paid cloud option |
| Security Onion | NSM/SIEM distribution | GPL-2.0 | Self-hosted | Python, Lua / Linux | Free; paid support |
| OSSIM | Traditional SIEM | AGPL-3.0 | Self-hosted | Python, C / Linux | Free (USM Anywhere is paid) |
| OpenSearch Security Analytics | Log analytics / SIEM | Apache-2.0 | Self-hosted, cloud | Java / Cross-platform | Free; AWS managed option |
| Graylog (OSS) | Log management | Apache-2.0 | Self-hosted | Java / Cross-platform | Free; Operations/Security editions paid |
| Elastic Security (Basic) | SIEM (free tier) | ELv2 | Self-hosted, cloud | Java, Go / Cross-platform | Free; Platinum/Enterprise paid |
| Apache Metron | Big-data analytics | Apache-2.0 | Self-hosted | Java / Hadoop ecosystem | Free |
| MozDef | Incident response / SIEM | MPL-2.0 | Self-hosted | Python / Linux | Free |
| Matano | Serverless SIEM (AWS) | Apache-2.0 | AWS (serverless) | Rust, Python / AWS | Free (AWS infra costs) |
| Sigma | Detection rule format | LGPL-2.1 | N/A (rule format) | YAML / Cross-platform | Free |
| TheHive | Incident response | Proprietary | Self-hosted, SaaS | Scala / Cross-platform | Freemium (TheHive 5, ex-AGPL); SSO is paid |
| Velociraptor | Forensics / hunting | Apache-2.0 | Self-hosted | Go / Cross-platform | Free; Rapid7 cloud option |
| Grafana Loki | Log aggregation | AGPL-3.0 | Self-hosted, cloud | Go / Cross-platform | Free; Grafana Cloud paid |
| Hayabusa | Event log analyzer | Apache-2.0 | Local (CLI) | Rust / Cross-platform | Free |
| OSSEC | HIDS / log analysis | GPL-2.0 | Self-hosted | C / Cross-platform | Free; Atomic OSSEC paid |
| Splunk Enterprise Security | Traditional SIEM | Proprietary | Self-hosted, cloud | C++, Python / Cross-platform | Per GB/day ingest or workload pricing |
| IBM QRadar | Traditional SIEM | Proprietary | Self-hosted, SaaS | Java / Linux appliance | Per EPS or per device |
| LogRhythm | Traditional SIEM + SOAR | Proprietary | Self-hosted, cloud | .NET, C++ / Windows/Linux | Per log source or per node |
| Exabeam | UEBA / Next-Gen SIEM | Proprietary | Cloud, self-hosted | Java / Linux | Per user or per GB |
| Securonix | UEBA / Cloud SIEM | Proprietary | Cloud (Snowflake) | Java / Cloud-native | Per user |
| Sumo Logic | Cloud SIEM + analytics | Proprietary | Cloud (SaaS) | Go, Java / Cloud-native | Per GB/day ingest (credits) |
| Rapid7 InsightIDR | Cloud SIEM + UEBA | Proprietary | Cloud (SaaS) | Ruby, Go / Cloud-native | Per asset |
| Datadog Security | Cloud SIEM + observability | Proprietary | Cloud (SaaS) | Go, Python / Cloud-native | Per GB analyzed |
| Elastic Security (Platinum) | Next-Gen SIEM | ELv2 + Subscription | Self-hosted, cloud | Java, Go / Cross-platform | Per node (subscription) |
| Graylog Security | Next-Gen SIEM | BSL-1.1 | Self-hosted, cloud | Java / Cross-platform | Per GB/day ingest |
| Devo | High-perf log analytics | Proprietary | Cloud (SaaS) | Java / Cloud-native | Per GB/day ingest |
| Hunters | SOC platform (SIEM+XDR) | Proprietary | Cloud (SaaS) | Cloud-native | Per data source |
| Stellar Cyber | Open XDR + SIEM | Proprietary | Self-hosted, cloud | Python / Linux, cloud | Per user or per asset |
| Microsoft Sentinel | Azure-native SIEM | Cloud service | Cloud (Azure) | KQL / Azure Log Analytics | Per GB ingested (pay-as-you-go or commitment) |
| Google Chronicle | Google Cloud SIEM | Cloud service | Cloud (GCP) | UDM / Google infrastructure | Fixed-price (storage-based) |
| AWS Security Lake | Security data lake | Cloud service | Cloud (AWS) | OCSF / S3 + Athena | Per GB stored + query costs |
| Amazon Security Lake | Security data lake | Cloud service | Cloud (AWS) | OCSF / S3 + Athena | Per GB stored + query costs |
| Panther | Detection-as-code SIEM | Proprietary | Cloud (SaaS) | Python, Go / Snowflake | Per TB ingested |
Log Collection & Processing
| Tool | Agents | Syslog | API Collection | Cloud Connectors | Normalization Schema |
|---|---|---|---|---|---|
| Wazuh | Yes (Wazuh agent) | Yes | Yes (API integration module) | AWS, Azure, GCP | Wazuh rule taxonomy |
| Security Onion | Yes (Elastic/Wazuh agent) | Yes | Yes (Logstash input) | Limited (manual) | ECS + custom |
| OSSIM | Yes (OSSEC agent) | Yes | Yes (plugin-based) | AWS, Azure | USM taxonomy |
| OpenSearch Sec. Analytics | Via Fluent Bit/Logstash | Yes | Yes (ingest pipelines) | AWS native | OCSF (emerging) |
| Graylog (OSS) | Yes (Sidecar/Beats) | Yes | Yes (input plugins) | Via integrations | GELF + custom |
| Elastic Security (Basic) | Yes (Elastic Agent) | Yes | Yes (Logstash, Beats) | AWS, Azure, GCP, O365 | ECS (Elastic Common Schema) |
| Apache Metron | No (Kafka consumers) | Yes | Yes (parsers) | Manual | Metron telemetry schema |
| MozDef | No (log forwarding) | Yes | Yes (plugins) | Limited | MozDef event format |
| Matano | No (S3 sources) | Via S3 | Yes (Lambda sources) | AWS native, O365, Okta | Apache Iceberg + custom |
| Sigma | N/A | N/A | N/A | N/A | N/A (rule format only) |
| TheHive | No (alert ingestion) | No | Yes (API + feeds) | Via SIEM integration | TheHive case format |
| Velociraptor | Yes (VR agent) | No | Yes (VQL) | No | VQL result format |
| Grafana Loki | Yes (Promtail/Alloy) | Yes | Yes (Loki API) | AWS, GCP, Azure | Labels + LogQL |
| Hayabusa | No (offline analysis) | No | No | No | Sigma-compatible |
| OSSEC | Yes (OSSEC agent) | Yes | No | No | OSSEC log format |
| Splunk ES | Yes (Universal Forwarder) | Yes | Yes (Splunk Connect, HEC) | 1000+ apps (Splunkbase) | CIM (Common Information Model) |
| IBM QRadar | Yes (WinCollect, agents) | Yes | Yes (DSM, protocol sources) | AWS, Azure, GCP, O365 | QRadar event taxonomy |
| LogRhythm | Yes (System Monitor) | Yes | Yes (Open Collector) | AWS, Azure, O365 | LogRhythm schema |
| Exabeam | Yes (agent) | Yes | Yes (cloud connectors) | 500+ integrations | Exabeam data model |
| Securonix | Yes (SNYPR agent) | Yes | Yes (connectors) | 350+ connectors | Securonix event schema |
| Sumo Logic | Yes (installed collector) | Yes | Yes (hosted collector) | AWS, Azure, GCP, O365 | CIM-compatible |
| Rapid7 InsightIDR | Yes (Insight Agent) | Yes | Yes (event sources) | AWS, Azure, O365 | Rapid7 data model |
| Datadog Security | Yes (Datadog Agent) | Yes | Yes (integrations) | 700+ integrations | Datadog event schema |
| Elastic Sec. (Platinum) | Yes (Elastic Agent) | Yes | Yes (Logstash, Beats, Fleet) | AWS, Azure, GCP, O365 | ECS (Elastic Common Schema) |
| Graylog Security | Yes (Sidecar/Beats) | Yes | Yes (input plugins) | Via Illuminate packs | GELF + Illuminate |
| Devo | Yes (Devo Agent) | Yes | Yes (relay, API) | 400+ integrations | Devo data model |
| Hunters | No (API ingestion) | Yes | Yes (native connectors) | AWS, Azure, GCP, O365 | Hunters data schema |
| Stellar Cyber | Yes (sensor) | Yes | Yes (connectors) | AWS, Azure, GCP | Open XDR schema |
| Microsoft Sentinel | Yes (AMA, MMA) | Yes | Yes (data connectors) | Azure native, AWS, GCP | ASIM (Advanced SIEM Information Model) |
| Google Chronicle | Yes (forwarders) | Yes | Yes (feeds, API) | Google Cloud native, AWS, Azure | UDM (Unified Data Model) |
| AWS Security Lake | No (source integration) | Via sources | Yes (OCSF sources) | AWS native | OCSF |
| Amazon Security Lake | No (source integration) | Via sources | Yes (OCSF sources) | AWS native | OCSF |
| Panther | No (log transport) | Yes | Yes (S3, SQS, HTTP) | AWS, GCP, O365, Okta | Panther schemas + custom |
Detection & Analytics
| Tool | Correlation Rules | UEBA | ML / AI | Threat Intelligence | Detection-as-Code |
|---|---|---|---|---|---|
| Wazuh | Yes (XML rules) | No | No | Yes (CDB lists, VirusTotal) | Partial (XML rules in files) |
| Security Onion | Yes (Suricata + Sigma) | No | No | Yes (STIX/TAXII, MISP) | Yes (Sigma rules) |
| OSSIM | Yes (directives) | No | No | Yes (OTX built-in) | No (GUI-based) |
| OpenSearch Sec. Analytics | Yes (Sigma rules) | No | Yes (anomaly detection) | No (manual integration) | Yes (Sigma-native) |
| Graylog (OSS) | Yes (pipeline rules) | No | No | No (via lookup tables) | Partial (pipeline code) |
| Elastic Security (Basic) | Yes (EQL, KQL rules) | No | No (paid feature) | Yes (Elastic TI module) | Yes (detection rules as code) |
| Apache Metron | Yes (Stellar rules) | No | Yes (Spark ML) | Yes (enrichment) | Yes (Stellar expressions) |
| MozDef | Yes (alerts) | No | No | Yes (IntelMQ) | Partial (Python alerts) |
| Matano | Yes (Python detections) | No | No | Yes (enrichment tables) | Yes (Python, native) |
| Sigma | Yes (rule format) | No | No | No | Yes (purpose-built) |
| TheHive | No (alert consumer) | No | No | Yes (MISP, Cortex analyzers) | No (response platform) |
| Velociraptor | Yes (VQL artifacts) | No | No | Yes (Sigma + Yara) | Yes (VQL artifacts) |
| Grafana Loki | Yes (LogQL alerting) | No | No | No | Partial (LogQL rules) |
| Hayabusa | Yes (Sigma rules) | No | No | No | Yes (Sigma-native) |
| OSSEC | Yes (XML rules) | No | No | Yes (CDB lists) | Partial (XML rules in files) |
| Splunk ES | Yes (correlation searches, SPL) | Yes (UBA add-on) | Yes (MLTK) | Yes (TI framework) | Yes (SPL + conf files) |
| IBM QRadar | Yes (custom rules, building blocks) | Yes (UBA app) | Yes (QRadar AI) | Yes (X-Force, STIX/TAXII) | Partial (API-managed rules) |
| LogRhythm | Yes (AI Engine rules) | Yes (UEBA module) | Yes (AI Engine) | Yes (TI framework) | Partial (rule export/import) |
| Exabeam | Yes (correlation rules) | Yes (core feature) | Yes (behavioral ML) | Yes (TI enrichment) | Partial (rule API) |
| Securonix | Yes (policies) | Yes (core feature) | Yes (ML models) | Yes (TI feeds) | Partial (policy API) |
| Sumo Logic | Yes (CSE rules) | Yes (entity risk) | Yes (anomaly detection) | Yes (CrowdStrike TI) | Yes (rules as code) |
| Rapid7 InsightIDR | Yes (detection rules) | Yes (UBA built-in) | Yes (behavioral analytics) | Yes (Threat Command) | Partial (API-managed) |
| Datadog Security | Yes (detection rules) | No | Yes (anomaly detection) | Yes (TI enrichment) | Yes (Terraform + API) |
| Elastic Sec. (Platinum) | Yes (EQL, KQL, ES | QL) | Yes (ML jobs) | Yes (anomaly detection, ML) | Yes (TI module, STIX) |
| Graylog Security | Yes (correlation engine) | Yes (anomaly detection) | Yes (ML module) | Yes (TI framework) | Partial (API-managed rules) |
| Devo | Yes (correlation rules) | Yes (behavioral) | Yes (ML models) | Yes (TI feeds, MISP) | Yes (LINQ rules as code) |
| Hunters | Yes (detection stories) | Yes (entity analytics) | Yes (graph-based ML) | Yes (multi-feed) | Yes (detection stories) |
| Stellar Cyber | Yes (correlation rules) | Yes (ML-based) | Yes (AI-driven) | Yes (multi-feed TI) | Partial (rule API) |
| Microsoft Sentinel | Yes (analytics rules, KQL) | Yes (UEBA built-in) | Yes (Fusion ML, BYO ML) | Yes (TI connectors, MDTI) | Yes (ARM templates, KQL as code) |
| Google Chronicle | Yes (YARA-L rules) | Yes (entity analytics) | Yes (VirusTotal ML) | Yes (VirusTotal, Mandiant TI) | Yes (YARA-L rules as code) |
| AWS Security Lake | No (data lake only) | No | No | No (via consumers) | No (data layer) |
| Amazon Security Lake | No (data lake only) | No | No | No (via consumers) | No (data layer) |
| Panther | Yes (Python detections) | No | No | Yes (enrichment) | Yes (Python, native DAC) |
Incident Response
| Tool | Case Management | Playbooks / SOAR | Automated Response | Ticketing Integration |
|---|---|---|---|---|
| Wazuh | No | No (active response scripts) | Yes (active response) | Via API / webhook |
| Security Onion | Yes (SOC cases) | No | No | TheHive integration |
| OSSIM | Yes (tickets) | No | Yes (policy actions) | Built-in ticketing |
| OpenSearch Sec. Analytics | No | No | No | Via OpenSearch alerting |
| Graylog (OSS) | No | No | No | Via alert notifications |
| Elastic Security (Basic) | Yes (cases) | No | No | Via Kibana alerting |
| Apache Metron | No | No | No | Manual |
| MozDef | Yes (investigations) | Yes (playbooks) | Yes (automated actions) | Via API |
| Matano | No | No | No | Via SNS / Lambda |
| Sigma | N/A | N/A | N/A | N/A |
| TheHive | Yes (core feature) | Yes (via Cortex) | Yes (Cortex responders) | Jira, GLPI, RT integration |
| Velociraptor | No | No | Yes (VQL remediation) | Via API |
| Grafana Loki | No | No | No | Via Grafana alerting |
| Hayabusa | No | No | No | No (offline tool) |
| OSSEC | No | No | Yes (active response) | No |
| Splunk ES | Yes (notable events) | Yes (SOAR / Phantom) | Yes (adaptive response) | Jira, ServiceNow, PagerDuty |
| IBM QRadar | Yes (offenses) | Yes (SOAR module) | Yes (custom actions) | Jira, ServiceNow, Resilient |
| LogRhythm | Yes (cases) | Yes (SmartResponse) | Yes (automated response) | Jira, ServiceNow |
| Exabeam | Yes (case management) | Yes (playbooks) | Yes (automated response) | Jira, ServiceNow |
| Securonix | Yes (incidents) | Yes (SOAR module) | Yes (response actions) | Jira, ServiceNow |
| Sumo Logic | Yes (insights) | Yes (Cloud SOAR) | Yes (automated actions) | Jira, ServiceNow, PagerDuty |
| Rapid7 InsightIDR | Yes (investigations) | Yes (InsightConnect) | Yes (containment actions) | Jira, ServiceNow |
| Datadog Security | Yes (signals + cases) | Yes (Workflow Automation) | Yes (automated workflows) | Jira, PagerDuty, Slack |
| Elastic Sec. (Platinum) | Yes (cases) | Yes (via Elastic rules) | Yes (response actions) | Jira, ServiceNow, Swimlane |
| Graylog Security | No | No | Yes (event definitions) | Via alert notifications |
| Devo | Yes (cases) | Yes (SOAR module) | Yes (automated response) | Jira, ServiceNow |
| Hunters | Yes (stories + cases) | Yes (automated investigation) | Yes (response actions) | Jira, ServiceNow, Slack |
| Stellar Cyber | Yes (incidents) | Yes (playbooks) | Yes (automated response) | Jira, ServiceNow |
| Microsoft Sentinel | Yes (incidents) | Yes (Logic Apps / SOAR) | Yes (automated response) | Jira, ServiceNow, Dynamics 365 |
| Google Chronicle | Yes (cases) | Yes (Chronicle SOAR) | Yes (automated playbooks) | Jira, ServiceNow |
| AWS Security Lake | No (data lake only) | No | No | Via consumer tools |
| Amazon Security Lake | No (data lake only) | No | No | Via consumer tools |
| Panther | No | No | Yes (automated remediation) | Jira, Slack, PagerDuty |
Storage & Scale
| Tool | Data Architecture | Retention | Hot / Warm / Cold | EPS Capacity | Multi-Tenancy |
|---|---|---|---|---|---|
| Wazuh | OpenSearch (Wazuh Indexer) | Configurable (ISM policies) | Yes (OpenSearch ISM) | 10K+ EPS (scales horizontally) | Yes (multi-cluster) |
| Security Onion | Elasticsearch + Redis | Configurable | Yes (ILM) | 10K+ EPS | No (single instance) |
| OSSIM | MySQL + flat files | 90 days default | No | 2K-5K EPS | No |
| OpenSearch Sec. Analytics | OpenSearch | Configurable (ISM) | Yes (ISM policies) | 50K+ EPS (scales horizontally) | Yes (index-level isolation) |
| Graylog (OSS) | Elasticsearch/OpenSearch + MongoDB | Configurable (index sets) | Yes (index rotation) | 20K+ EPS | No (single tenant) |
| Elastic Security (Basic) | Elasticsearch | Configurable (ILM) | Yes (ILM + frozen tier) | 50K+ EPS | No (basic license) |
| Apache Metron | HDFS + HBase | Configurable | Yes (HDFS tiering) | 100K+ EPS (Kafka/Storm) | No |
| MozDef | Elasticsearch | Configurable | No | 5K-10K EPS | No |
| Matano | S3 (Apache Iceberg tables) | Unlimited (S3 lifecycle) | Yes (S3 tiers) | Scales with Lambda | Yes (AWS account isolation) |
| Sigma | N/A | N/A | N/A | N/A | N/A |
| TheHive | Elasticsearch/OpenSearch + Cassandra | Configurable | No | N/A (alert ingestion) | Yes (organizations) |
| Velociraptor | File-based + LevelDB | Configurable | No | N/A (forensics focus) | Yes (multi-org) |
| Grafana Loki | Object storage (S3, GCS) | Configurable (retention) | Yes (compactor) | 100K+ EPS (scales horizontally) | Yes (tenant ID header) |
| Hayabusa | N/A (offline) | N/A | N/A | N/A | N/A |
| OSSEC | Flat files | Configurable | No | 5K EPS | No |
| Splunk ES | Splunk indexes (proprietary) | Configurable (buckets) | Yes (SmartStore + S3) | 100K+ EPS (indexer clustering) | Yes (multi-tenant search heads) |
| IBM QRadar | Ariel DB (proprietary) | Configurable | Yes (data offloading) | 50K+ EPS (distributed) | Yes (domain separation) |
| LogRhythm | Elasticsearch + SQL | Configurable | Yes (archive tiers) | 40K+ EPS | Yes (entity separation) |
| Exabeam | Exabeam Data Lake | 365 days typical | Yes (hot/cold) | 50K+ EPS | Yes (multi-tenant) |
| Securonix | Snowflake / Hadoop | 365+ days | Yes (Snowflake tiers) | 100K+ EPS | Yes (cloud-native) |
| Sumo Logic | Proprietary cloud storage | Configurable (30-5000 days) | Yes (infrequent tier) | 100K+ EPS (cloud scale) | Yes (partitions) |
| Rapid7 InsightIDR | Rapid7 Insight cloud | 13 months default | No (cloud-managed) | Cloud-scale | Yes (multi-org) |
| Datadog Security | Datadog cloud storage | 15 months default (logs) | Yes (Online Archives) | Cloud-scale | Yes (multi-org) |
| Elastic Sec. (Platinum) | Elasticsearch | Configurable (ILM) | Yes (ILM + searchable snapshots) | 100K+ EPS (cluster scaling) | Yes (spaces + RBAC) |
| Graylog Security | Elasticsearch/OpenSearch + MongoDB | Configurable (index sets) | Yes (index rotation) | 50K+ EPS | Yes (Graylog Enterprise) |
| Devo | Devo data lake (proprietary) | 400+ days | Yes (online/nearline) | 1M+ EPS (claimed) | Yes (multi-domain) |
| Hunters | Snowflake (backend) | Configurable | Yes (Snowflake tiers) | Cloud-scale | Yes (multi-tenant) |
| Stellar Cyber | ClickHouse + Elasticsearch | Configurable | Yes (tiered storage) | 100K+ EPS | Yes (multi-tenant) |
| Microsoft Sentinel | Azure Log Analytics + ADX | 90 days hot, 12 years archive | Yes (Analytics/Basic/Archive) | Cloud-scale (no hard limit) | Yes (workspace-per-tenant or Lighthouse) |
| Google Chronicle | Google infrastructure | 12 months default (extendable) | Managed (opaque) | Petabyte-scale | Yes (multi-tenant) |
| AWS Security Lake | S3 (Apache Iceberg + Parquet) | Configurable (S3 lifecycle) | Yes (S3 tiers) | Cloud-scale | Yes (AWS Organizations) |
| Amazon Security Lake | S3 (Apache Iceberg + Parquet) | Configurable (S3 lifecycle) | Yes (S3 tiers) | Cloud-scale | Yes (AWS Organizations) |
| Panther | Snowflake (backend) | Configurable | Yes (Snowflake tiers) | Cloud-scale | Yes (multi-account) |
SSO / OIDC Comparison
These tools assume an Authentik-class OIDC provider as the IdP. OIDC is the preferred SSO protocol.
| Tool | OIDC | SAML | SCIM | Authentik Notes |
|---|---|---|---|---|
| Wazuh | Yes* | Yes* | No | Via OpenSearch Dashboards OIDC/SAML backend; Authentik as IdP; requires manual security config |
| Security Onion | No | No | No | Local auth; reverse proxy SSO possible |
| OSSIM | No | No | No | Local auth; LDAP integration |
| OpenSearch Sec. Analytics | Yes | Yes | No | Native OIDC and SAML via OpenSearch Security plugin; Authentik as IdP |
| Graylog (OSS) | No | No | No | Local auth + LDAP; no SSO in OSS edition |
| Elastic Security (Basic) | No | No | No | Basic license lacks SSO; Platinum required for OIDC/SAML |
| Apache Metron | No | No | No | Knox Gateway for auth; no native OIDC/SAML |
| MozDef | Yes* | No | No | OIDC via Mozilla configuration; limited documentation |
| Matano | N/A | N/A | N/A | Serverless; AWS IAM auth; no web UI |
| Sigma | N/A | N/A | N/A | Rule format; no web UI |
| TheHive | Yes | No | No | Native OIDC (TheHive 5+); Authentik as OIDC IdP |
| Velociraptor | Yes | No | No | Native OIDC support; Authentik as IdP |
| Grafana Loki | Yes* | Yes* | No | Via Grafana (OIDC/SAML); Authentik as IdP |
| Hayabusa | N/A | N/A | N/A | CLI tool; no web UI |
| OSSEC | No | No | No | No web UI in base OSSEC; relies on external dashboards |
| Splunk ES | Yes | Yes | Yes | Native OIDC and SAML; SCIM via Splunk Cloud; Authentik as IdP |
| IBM QRadar | No | Yes | No | SAML SSO; no native OIDC; LDAP/AD integration |
| LogRhythm | No | Yes | No | SAML SSO; no OIDC; LDAP/AD integration |
| Exabeam | Yes | Yes | Yes | Native OIDC and SAML; SCIM provisioning; Authentik as IdP |
| Securonix | Yes | Yes | Yes | Native OIDC and SAML; SCIM directory sync |
| Sumo Logic | Yes | Yes | Yes | Native OIDC and SAML; SCIM provisioning; Authentik as IdP |
| Rapid7 InsightIDR | No | Yes | Yes | SAML SSO; SCIM provisioning; no native OIDC |
| Datadog Security | Yes | Yes | Yes | Native OIDC and SAML; SCIM directory sync; Authentik as IdP |
| Elastic Sec. (Platinum) | Yes | Yes | No | Native OIDC and SAML via Elasticsearch security; Authentik as IdP |
| Graylog Security | Yes | Yes | No | Native OIDC and SAML in Security/Enterprise edition; Authentik as IdP |
| Devo | No | Yes | Yes | SAML SSO; SCIM provisioning; no native OIDC |
| Hunters | Yes | Yes | No | Native OIDC and SAML; Authentik as IdP |
| Stellar Cyber | No | Yes | No | SAML SSO; no native OIDC; LDAP integration |
| Microsoft Sentinel | Yes* | Yes | Yes | Entra ID (Azure AD); OIDC federation; SAML; SCIM; Authentik as external IdP |
| Google Chronicle | Yes* | Yes | Yes | Google Workspace / Cloud Identity; OIDC federation; Authentik as external IdP |
| AWS Security Lake | Yes* | Yes | No | AWS IAM Identity Center; OIDC federation; Authentik as external IdP |
| Amazon Security Lake | Yes* | Yes | No | AWS IAM Identity Center; OIDC federation; Authentik as external IdP |
| Panther | Yes | Yes | Yes | Native OIDC and SAML; SCIM provisioning; Authentik as IdP |
* = requires extension, plugin, specific configuration, or cloud identity federation
Best SSO support: Splunk ES, Exabeam, Securonix, Sumo Logic, Datadog, Panther (OIDC + SAML + SCIM)
No SSO: Security Onion, OSSIM, Graylog (OSS), Elastic (Basic), Apache Metron, OSSEC
OIDC among OSS: OpenSearch Security Analytics, TheHive, Velociraptor, Wazuh (via OpenSearch)
Monitoring Integration
monitoring stack integration for monitoring the SIEM platform itself and for sharing data between monitoring and SIEM.
| Tool | Telegraf Metrics | Fluent Bit Logs | Grafana Dashboards |
|---|---|---|---|
| Wazuh | Yes – Wazuh API stats via HTTP input; OpenSearch metrics via elasticsearch input | Yes – Wazuh logs via tail input; forward to OpenSearch | Yes – Wazuh indices via OpenSearch data source; pre-built community dashboards |
| Security Onion | Yes – Elasticsearch metrics; system metrics of SO nodes | Yes – SO logs via syslog/tail | Yes – Elasticsearch data source; custom dashboards |
| OSSIM | Yes – system metrics; MySQL metrics | Yes – OSSIM logs via syslog | Limited – no native Grafana integration |
| OpenSearch Sec. Analytics | Yes – OpenSearch stats via elasticsearch input | Yes – OpenSearch logs via tail | Yes – native Grafana OpenSearch data source |
| Graylog (OSS) | Yes – Graylog API metrics via HTTP input; Elasticsearch metrics | Yes – Graylog server logs via tail | Yes – Elasticsearch data source; Graylog metrics |
| Elastic Security (Basic) | Yes – Elasticsearch cluster stats via elasticsearch input | Yes – Elasticsearch logs via tail | Yes – native Elasticsearch data source |
| Apache Metron | Yes – Kafka, Storm, HBase metrics via JMX/Jolokia | Yes – Metron logs via tail | Limited – custom dashboards |
| MozDef | Yes – Elasticsearch metrics; system metrics | Yes – MozDef logs via tail | Limited – custom dashboards |
| Matano | Yes – AWS CloudWatch metrics via cloudwatch input | Yes – Lambda logs via CloudWatch | Yes – CloudWatch data source |
| Sigma | N/A | N/A | N/A |
| TheHive | Yes – TheHive API stats via HTTP input | Yes – TheHive logs via tail | Yes – TheHive metrics via API; custom dashboards |
| Velociraptor | Yes – VR server metrics via HTTP input | Yes – VR server logs via tail | Yes – custom dashboards |
| Grafana Loki | Yes – Loki metrics (Prometheus endpoint) | Yes – Loki logs via tail | Yes – native Loki data source (same Grafana instance) |
| Hayabusa | N/A (offline tool) | N/A | N/A |
| OSSEC | Yes – system metrics of OSSEC server | Yes – OSSEC logs via tail | Limited – custom dashboards |
| Splunk ES | Yes – Splunk REST API metrics via HTTP input | Yes – Splunk internal logs via syslog forwarding | Yes – Splunk data source plugin (unofficial) |
| IBM QRadar | Yes – QRadar API health metrics via HTTP input | Yes – QRadar syslog forwarding | Limited – QRadar API for custom dashboards |
| LogRhythm | Yes – system metrics of LR nodes | Yes – LogRhythm logs via syslog | Limited – custom dashboards |
| Exabeam | Yes – Exabeam API health metrics | Yes – Exabeam logs via syslog | Limited – API-based custom dashboards |
| Securonix | Limited – cloud service; API health only | Yes – syslog forwarding | Limited – API-based |
| Sumo Logic | Limited – cloud service; Health Events API | Yes – via Sumo Logic API | Limited – cloud service |
| Rapid7 InsightIDR | Limited – cloud service; API health | No (cloud-managed) | Limited – cloud service |
| Datadog Security | Limited – cloud service; API metrics | No (cloud-managed) | Limited – Datadog has its own dashboards |
| Elastic Sec. (Platinum) | Yes – Elasticsearch cluster stats via elasticsearch input | Yes – Elasticsearch logs via tail | Yes – native Elasticsearch data source |
| Graylog Security | Yes – Graylog API metrics; Elasticsearch metrics | Yes – Graylog logs via tail | Yes – Elasticsearch data source |
| Devo | Limited – cloud service; API health | Yes – syslog forwarding | Limited – API-based |
| Hunters | Limited – cloud service | No (cloud-managed) | Limited – cloud service |
| Stellar Cyber | Yes – ClickHouse/ES metrics; platform metrics | Yes – platform logs via syslog | Yes – built-in Grafana or custom |
| Microsoft Sentinel | Limited – Azure Monitor metrics via Azure input | Yes – Azure diagnostic logs | Yes – Azure Monitor data source |
| Google Chronicle | Limited – cloud service | No (cloud-managed) | Limited – cloud service |
| AWS Security Lake | Yes – CloudWatch metrics | Yes – CloudTrail/CloudWatch logs | Yes – CloudWatch data source |
| Amazon Security Lake | Yes – CloudWatch metrics | Yes – CloudTrail/CloudWatch logs | Yes – CloudWatch data source |
| Panther | Limited – cloud service; API health | No (cloud-managed) | Limited – cloud service |
Compliance & Reporting
| Tool | Built-in Reports | Custom Dashboards | Compliance Frameworks |
|---|---|---|---|
| Wazuh | Yes (regulatory reports) | Yes (OpenSearch Dashboards) | PCI-DSS, HIPAA, GDPR, NIST 800-53, TSC, CIS |
| Security Onion | Limited | Yes (Kibana) | No pre-built compliance |
| OSSIM | Yes (compliance reports) | Yes (USM dashboards) | PCI-DSS, HIPAA, ISO 27001 |
| OpenSearch Sec. Analytics | Limited (findings) | Yes (OpenSearch Dashboards) | No pre-built compliance |
| Graylog (OSS) | No | Yes (custom dashboards) | No pre-built compliance |
| Elastic Security (Basic) | Limited | Yes (Kibana dashboards) | No pre-built compliance (basic) |
| Apache Metron | No | Limited | No pre-built compliance |
| MozDef | Limited | Yes (custom dashboards) | No pre-built compliance |
| Matano | No | Via Athena/QuickSight | No pre-built compliance |
| Sigma | N/A | N/A | N/A |
| TheHive | Yes (case reports) | Limited | No pre-built compliance |
| Velociraptor | Yes (hunt reports) | Limited | CIS benchmarks (via hunts) |
| Grafana Loki | No | Yes (Grafana dashboards) | No pre-built compliance |
| Hayabusa | Yes (timeline reports) | No | MITRE ATT&CK mapping |
| OSSEC | Yes (regulatory reports) | No (external dashboards) | PCI-DSS, CIS |
| Splunk ES | Yes (extensive report library) | Yes (dashboard studio) | PCI-DSS, HIPAA, GDPR, SOX, NIST, CIS, ISO 27001 |
| IBM QRadar | Yes (compliance reports) | Yes (custom dashboards) | PCI-DSS, HIPAA, SOX, GDPR, ISO 27001 |
| LogRhythm | Yes (compliance modules) | Yes (dashboard builder) | PCI-DSS, HIPAA, SOX, GDPR, NIST, CMMC |
| Exabeam | Yes (compliance reports) | Yes (custom dashboards) | PCI-DSS, HIPAA, SOX, GDPR |
| Securonix | Yes (compliance analytics) | Yes (custom reports) | PCI-DSS, HIPAA, SOX, GDPR, NIST |
| Sumo Logic | Yes (compliance dashboards) | Yes (dashboard builder) | PCI-DSS, HIPAA, SOC 2, GDPR, FedRAMP |
| Rapid7 InsightIDR | Yes (compliance reports) | Yes (custom dashboards) | PCI-DSS, HIPAA, SOC 2 |
| Datadog Security | Yes (security reports) | Yes (dashboard builder) | PCI-DSS, HIPAA, SOC 2, GDPR |
| Elastic Sec. (Platinum) | Yes (compliance reports) | Yes (Kibana dashboards) | PCI-DSS, HIPAA, CIS, NIST |
| Graylog Security | Yes (Illuminate reports) | Yes (custom dashboards) | PCI-DSS, HIPAA (via Illuminate) |
| Devo | Yes (compliance reports) | Yes (custom dashboards) | PCI-DSS, HIPAA, SOX, GDPR, NIST |
| Hunters | Yes (SOC reports) | Yes (custom dashboards) | PCI-DSS, HIPAA |
| Stellar Cyber | Yes (compliance reports) | Yes (custom dashboards) | PCI-DSS, HIPAA, NIST, CIS |
| Microsoft Sentinel | Yes (workbooks + reports) | Yes (workbooks, Power BI) | PCI-DSS, HIPAA, SOC 2, GDPR, NIST, ISO 27001, FedRAMP |
| Google Chronicle | Yes (reports) | Yes (custom dashboards) | PCI-DSS, HIPAA, SOC 2 |
| AWS Security Lake | Via consumer tools | Via Athena/QuickSight | Framework support depends on consumer |
| Amazon Security Lake | Via consumer tools | Via Athena/QuickSight | Framework support depends on consumer |
| Panther | Yes (detection reports) | Yes (Snowflake dashboards) | PCI-DSS, HIPAA, SOC 2 |
Tools
33 tools.
Amazon GuardDuty
Amazon GuardDuty is an intelligent threat detection service that continuously monitors AWS accounts and workloads for malicious activity and unauthorized behavior.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Apache Metron
Apache Metron was an open-source big data security analytics platform designed to process and analyze massive volumes of security telemetry in real time.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none
AWS Security Lake
AWS Security Lake is a purpose-built security data lake service that automatically centralizes security data from AWS services, SaaS providers, on-premises systems, and cloud sources into a purpose-built data lake stored in S3.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Datadog Security
Datadog Security is the security monitoring suite within the Datadog observability platform, providing Cloud SIEM, Cloud Security Management (CSM), Application Security Management (ASM), and Cloud Workload Security (CWS).
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Devo
Devo is a cloud-native security data analytics platform designed for high-speed data ingestion and real-time analysis at massive scale.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Elastic Security Basic
Elastic Security is the SIEM and security analytics solution built into the Elastic Stack (Elasticsearch, Kibana, Beats/Elastic Agent).
License: LicenseRef-Elastic-2.0 (source-available) · Kind: web · Deploy: native, docker, k8s · SSO: none
Elastic Security Platinum
Elastic Security Platinum is the commercial tier of Elastic Security that adds machine learning anomaly detection, endpoint protection (Elastic Defend), cross-cluster search, SSO/OIDC authentication, and advanced response actions to the fre…
License: Proprietary (proprietary) · Kind: web · Deploy: native, docker, k8s · SSO: none
Exabeam
Exabeam is a next-generation SIEM platform known for its advanced User and Entity Behavior Analytics (UEBA) capabilities.
License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none
Google Chronicle
Google Chronicle (now part of Google Security Operations) is a cloud-native security analytics platform built on Google’s infrastructure that provides petabyte-scale security data retention, sub-second search across months of data, and auto…
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC
Grafana Loki (Security Use)
Grafana Loki is a horizontally scalable, highly available log aggregation system designed to be cost-effective and operationally simple.
License: AGPL-3.0-only (OSS) · Kind: web · Deploy: native, docker, k8s · SSO: none
Graylog Open Source
Graylog is an open-source log management platform designed for collecting, indexing, and analyzing log data from any source.
License: SSPL-1.0 (source-available) · Kind: web · Deploy: native, docker · SSO: none
Graylog Security
Graylog Security is the commercial SIEM tier of the Graylog platform that adds anomaly detection, security-specific content, correlation engine, compliance reporting, and OIDC/SAML authentication to Graylog’s strong log management foundatio…
License: Proprietary (proprietary) · Kind: web · Deploy: native, docker · SSO: none
Hayabusa
Hayabusa is a fast, open-source Windows event log (EVTX) analyzer written in Rust by Yamato Security, applying 4,000+ Sigma-based rules mapped to MITRE ATT&CK for threat hunting and forensics.
License: GPL-3.0-only (OSS) · Kind: web · Deploy: native · SSO: none
Hunters
Hunters is a cloud-native SOC (Security Operations Center) platform that automates threat detection, investigation, and response across the entire security stack.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
IBM QRadar
IBM QRadar is an enterprise SIEM platform providing log management, network flow analysis, vulnerability assessment correlation, and advanced threat detection.
License: Proprietary (proprietary) · Kind: web · Deploy: native, saas, appliance · SSO: none
LogRhythm
LogRhythm is an enterprise SIEM platform that combines log management, network and endpoint monitoring, UEBA, and SOAR capabilities into an integrated security operations platform.
License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none
Matano
Matano is an open-source serverless security data lake platform designed for AWS. It enables security teams to collect, normalize, and analyze petabyte- scale security logs using a detection-as-code approach.
License: Apache-2.0 (OSS) · Kind: web · Deploy: saas, native · SSO: none
Microsoft Sentinel
Microsoft Sentinel is Azure’s cloud-native SIEM and SOAR platform that provides intelligent security analytics across the enterprise.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC
MozDef
MozDef (Mozilla Defense Platform) is an open-source security incident management and automation platform developed by Mozilla’s Enterprise Information Security team.
License: MPL-2.0 (OSS) · Kind: web · Deploy: native, docker · SSO: none
OpenSearch Security Analytics
OpenSearch Security Analytics is a security plugin built into OpenSearch that provides SIEM-like detection, correlation, and alerting capabilities directly within the OpenSearch platform.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native, docker, k8s · SSO: OIDC
OSSEC
OSSEC (Open Source Security Event Correlator) is a host-based intrusion detection system (HIDS) that provides log analysis, file integrity monitoring, rootkit detection, active response, and real-time alerting.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none
OSSIM / AlienVault Open Source
OSSIM (Open Source Security Information Management) is an open-source SIEM platform originally developed by AlienVault, now maintained by AT&T Cybersecurity.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none
Panther
Panther is a cloud-native SIEM platform built around the detection-as-code paradigm, where all detection rules are written in Python and managed through Git version control workflows.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: SAML
Rapid7 InsightIDR
Rapid7 InsightIDR is a cloud SIEM platform that combines log search, UEBA, network traffic analysis, endpoint detection, and deception technology into a unified threat detection and response solution.
License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none
Security Onion
Security Onion is a comprehensive open-source network security monitoring (NSM) and SIEM platform that combines full packet capture, network-based and host-based intrusion detection, log management, and case management into a single distrib…
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none
Securonix
Securonix is a cloud-native SIEM platform built around User and Entity Behavior Analytics (UEBA) as a core capability rather than an add-on.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Sigma
Sigma is an open, vendor-agnostic YAML format for log-based security detection rules, with a community rule repository and the pySigma framework to convert rules to many SIEM query languages.
License: LicenseRef-DRL-1.1 (source-available) · Kind: web · Deploy: saas · SSO: none
Splunk Enterprise Security
Splunk Enterprise Security (ES) is the market- leading commercial SIEM platform, providing comprehensive security monitoring, advanced threat detection, incident investigation, and compliance reporting.
License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none
Stellar Cyber
Stellar Cyber is an Open XDR platform designed specifically for security teams and MSSPs that need to detect and respond to threats across their entire attack surface.
License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none
Sumo Logic
Sumo Logic is a cloud-native log analytics and SIEM platform that provides real-time security monitoring, threat detection, and compliance reporting as a SaaS service.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: SAML
TheHive
TheHive is a SOC incident-response case-management platform. TheHive 5 is proprietary freemium (ex-AGPL); the companion Cortex engine stays AGPL-3.0.
License: Proprietary (proprietary) · Kind: web · Deploy: native, docker, saas · SSO: none
Velociraptor
Velociraptor is an open-source digital forensics and incident response (DFIR) tool focused on endpoint visibility and artifact collection at scale.
License: AGPL-3.0-only (OSS) · Kind: web · Deploy: native, docker · SSO: OIDC
Wazuh
Wazuh is a comprehensive open-source security platform that provides unified XDR and SIEM capabilities.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: SAML