License & Deployment Mix: 33 tools – 13 OSS, 14 SaaS. (OSS and SaaS counts can overlap when an open-source tool also offers a vendor-hosted edition.)

What Is SIEM?

Security Information and Event Management (SIEM) is a security technology that collects, normalizes, correlates, and analyzes log data from across an organization’s entire IT environment – servers, network devices, applications, endpoints, cloud services, and identity providers – to detect security threats, support incident investigation, and meet compliance requirements.

SIEM platforms combine two historically separate functions:

  • SIM (Security Information Management) – long-term log collection, storage, and compliance reporting
  • SEM (Security Event Management) – real-time event correlation, alerting, and dashboarding

Modern SIEM has evolved far beyond simple log aggregation. Today’s platforms incorporate User and Entity Behavior Analytics (UEBA), machine learning for anomaly detection, threat intelligence feeds, Security Orchestration Automation and Response (SOAR) capabilities, and detection-as-code workflows. The boundary between SIEM, XDR, and security data lakes is increasingly blurred.

Enterprise SIEM platforms provide:

  • Log collection and normalization – ingest logs from hundreds of source types (syslog, agents, API collectors, cloud connectors) and normalize them into a common schema for cross-source correlation
  • Correlation rules – define detection logic that matches patterns across multiple log sources and time windows; MITRE ATT&CK mapping; chained rules for multi-stage attack detection
  • UEBA (User and Entity Behavior Analytics) – ML-driven baselines of normal user and device behavior; detect anomalies such as impossible travel, unusual access patterns, privilege escalation, and lateral movement
  • Threat intelligence – ingest IOC feeds (STIX/ TAXII, MISP, commercial feeds) and automatically correlate against incoming logs for known-bad IPs, domains, file hashes, and TTPs
  • Incident response – case management, alert triage, investigation timelines, evidence collection, and analyst collaboration; SOAR playbooks for automated response actions
  • Compliance reporting – pre-built report templates for PCI-DSS, HIPAA, SOX, GDPR, SOC 2, NIST, and CIS; scheduled report generation; audit trail and evidence export
  • Threat hunting – ad-hoc search across historical log data; query languages (SPL, KQL, Lucene, SQL) for proactive investigation; saved searches and hunt notebooks
  • Dashboards and visualization – real-time security dashboards; drill-down from summary metrics to individual events; geographic and timeline visualizations
  • Multi-tenancy – centralized management of multiple customer environments with data isolation; per-tenant rules, dashboards, and retention policies; essential for MSPs and MSSPs

SIEM is the backbone of Security Operations Centers (SOCs). Without SIEM, security teams lack the centralized visibility needed to detect attacks that span multiple systems, correlate seemingly unrelated events into coherent incident timelines, and demonstrate compliance to auditors.

The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.

Comparison

This evaluation covers the full SIEM and security log-analytics landscape: self-hosted open source, commercial, and cloud-native platforms.


Overview Comparison

ToolTypeLicenseDeploymentLanguage / PlatformPricing Model
WazuhXDR/SIEMGPL-2.0Self-hostedC, Python / LinuxFree; paid cloud option
Security OnionNSM/SIEM distributionGPL-2.0Self-hostedPython, Lua / LinuxFree; paid support
OSSIMTraditional SIEMAGPL-3.0Self-hostedPython, C / LinuxFree (USM Anywhere is paid)
OpenSearch Security AnalyticsLog analytics / SIEMApache-2.0Self-hosted, cloudJava / Cross-platformFree; AWS managed option
Graylog (OSS)Log managementApache-2.0Self-hostedJava / Cross-platformFree; Operations/Security editions paid
Elastic Security (Basic)SIEM (free tier)ELv2Self-hosted, cloudJava, Go / Cross-platformFree; Platinum/Enterprise paid
Apache MetronBig-data analyticsApache-2.0Self-hostedJava / Hadoop ecosystemFree
MozDefIncident response / SIEMMPL-2.0Self-hostedPython / LinuxFree
MatanoServerless SIEM (AWS)Apache-2.0AWS (serverless)Rust, Python / AWSFree (AWS infra costs)
SigmaDetection rule formatLGPL-2.1N/A (rule format)YAML / Cross-platformFree
TheHiveIncident responseProprietarySelf-hosted, SaaSScala / Cross-platformFreemium (TheHive 5, ex-AGPL); SSO is paid
VelociraptorForensics / huntingApache-2.0Self-hostedGo / Cross-platformFree; Rapid7 cloud option
Grafana LokiLog aggregationAGPL-3.0Self-hosted, cloudGo / Cross-platformFree; Grafana Cloud paid
HayabusaEvent log analyzerApache-2.0Local (CLI)Rust / Cross-platformFree
OSSECHIDS / log analysisGPL-2.0Self-hostedC / Cross-platformFree; Atomic OSSEC paid
Splunk Enterprise SecurityTraditional SIEMProprietarySelf-hosted, cloudC++, Python / Cross-platformPer GB/day ingest or workload pricing
IBM QRadarTraditional SIEMProprietarySelf-hosted, SaaSJava / Linux appliancePer EPS or per device
LogRhythmTraditional SIEM + SOARProprietarySelf-hosted, cloud.NET, C++ / Windows/LinuxPer log source or per node
ExabeamUEBA / Next-Gen SIEMProprietaryCloud, self-hostedJava / LinuxPer user or per GB
SecuronixUEBA / Cloud SIEMProprietaryCloud (Snowflake)Java / Cloud-nativePer user
Sumo LogicCloud SIEM + analyticsProprietaryCloud (SaaS)Go, Java / Cloud-nativePer GB/day ingest (credits)
Rapid7 InsightIDRCloud SIEM + UEBAProprietaryCloud (SaaS)Ruby, Go / Cloud-nativePer asset
Datadog SecurityCloud SIEM + observabilityProprietaryCloud (SaaS)Go, Python / Cloud-nativePer GB analyzed
Elastic Security (Platinum)Next-Gen SIEMELv2 + SubscriptionSelf-hosted, cloudJava, Go / Cross-platformPer node (subscription)
Graylog SecurityNext-Gen SIEMBSL-1.1Self-hosted, cloudJava / Cross-platformPer GB/day ingest
DevoHigh-perf log analyticsProprietaryCloud (SaaS)Java / Cloud-nativePer GB/day ingest
HuntersSOC platform (SIEM+XDR)ProprietaryCloud (SaaS)Cloud-nativePer data source
Stellar CyberOpen XDR + SIEMProprietarySelf-hosted, cloudPython / Linux, cloudPer user or per asset
Microsoft SentinelAzure-native SIEMCloud serviceCloud (Azure)KQL / Azure Log AnalyticsPer GB ingested (pay-as-you-go or commitment)
Google ChronicleGoogle Cloud SIEMCloud serviceCloud (GCP)UDM / Google infrastructureFixed-price (storage-based)
AWS Security LakeSecurity data lakeCloud serviceCloud (AWS)OCSF / S3 + AthenaPer GB stored + query costs
Amazon Security LakeSecurity data lakeCloud serviceCloud (AWS)OCSF / S3 + AthenaPer GB stored + query costs
PantherDetection-as-code SIEMProprietaryCloud (SaaS)Python, Go / SnowflakePer TB ingested

Log Collection & Processing

ToolAgentsSyslogAPI CollectionCloud ConnectorsNormalization Schema
WazuhYes (Wazuh agent)YesYes (API integration module)AWS, Azure, GCPWazuh rule taxonomy
Security OnionYes (Elastic/Wazuh agent)YesYes (Logstash input)Limited (manual)ECS + custom
OSSIMYes (OSSEC agent)YesYes (plugin-based)AWS, AzureUSM taxonomy
OpenSearch Sec. AnalyticsVia Fluent Bit/LogstashYesYes (ingest pipelines)AWS nativeOCSF (emerging)
Graylog (OSS)Yes (Sidecar/Beats)YesYes (input plugins)Via integrationsGELF + custom
Elastic Security (Basic)Yes (Elastic Agent)YesYes (Logstash, Beats)AWS, Azure, GCP, O365ECS (Elastic Common Schema)
Apache MetronNo (Kafka consumers)YesYes (parsers)ManualMetron telemetry schema
MozDefNo (log forwarding)YesYes (plugins)LimitedMozDef event format
MatanoNo (S3 sources)Via S3Yes (Lambda sources)AWS native, O365, OktaApache Iceberg + custom
SigmaN/AN/AN/AN/AN/A (rule format only)
TheHiveNo (alert ingestion)NoYes (API + feeds)Via SIEM integrationTheHive case format
VelociraptorYes (VR agent)NoYes (VQL)NoVQL result format
Grafana LokiYes (Promtail/Alloy)YesYes (Loki API)AWS, GCP, AzureLabels + LogQL
HayabusaNo (offline analysis)NoNoNoSigma-compatible
OSSECYes (OSSEC agent)YesNoNoOSSEC log format
Splunk ESYes (Universal Forwarder)YesYes (Splunk Connect, HEC)1000+ apps (Splunkbase)CIM (Common Information Model)
IBM QRadarYes (WinCollect, agents)YesYes (DSM, protocol sources)AWS, Azure, GCP, O365QRadar event taxonomy
LogRhythmYes (System Monitor)YesYes (Open Collector)AWS, Azure, O365LogRhythm schema
ExabeamYes (agent)YesYes (cloud connectors)500+ integrationsExabeam data model
SecuronixYes (SNYPR agent)YesYes (connectors)350+ connectorsSecuronix event schema
Sumo LogicYes (installed collector)YesYes (hosted collector)AWS, Azure, GCP, O365CIM-compatible
Rapid7 InsightIDRYes (Insight Agent)YesYes (event sources)AWS, Azure, O365Rapid7 data model
Datadog SecurityYes (Datadog Agent)YesYes (integrations)700+ integrationsDatadog event schema
Elastic Sec. (Platinum)Yes (Elastic Agent)YesYes (Logstash, Beats, Fleet)AWS, Azure, GCP, O365ECS (Elastic Common Schema)
Graylog SecurityYes (Sidecar/Beats)YesYes (input plugins)Via Illuminate packsGELF + Illuminate
DevoYes (Devo Agent)YesYes (relay, API)400+ integrationsDevo data model
HuntersNo (API ingestion)YesYes (native connectors)AWS, Azure, GCP, O365Hunters data schema
Stellar CyberYes (sensor)YesYes (connectors)AWS, Azure, GCPOpen XDR schema
Microsoft SentinelYes (AMA, MMA)YesYes (data connectors)Azure native, AWS, GCPASIM (Advanced SIEM Information Model)
Google ChronicleYes (forwarders)YesYes (feeds, API)Google Cloud native, AWS, AzureUDM (Unified Data Model)
AWS Security LakeNo (source integration)Via sourcesYes (OCSF sources)AWS nativeOCSF
Amazon Security LakeNo (source integration)Via sourcesYes (OCSF sources)AWS nativeOCSF
PantherNo (log transport)YesYes (S3, SQS, HTTP)AWS, GCP, O365, OktaPanther schemas + custom

Detection & Analytics

ToolCorrelation RulesUEBAML / AIThreat IntelligenceDetection-as-Code
WazuhYes (XML rules)NoNoYes (CDB lists, VirusTotal)Partial (XML rules in files)
Security OnionYes (Suricata + Sigma)NoNoYes (STIX/TAXII, MISP)Yes (Sigma rules)
OSSIMYes (directives)NoNoYes (OTX built-in)No (GUI-based)
OpenSearch Sec. AnalyticsYes (Sigma rules)NoYes (anomaly detection)No (manual integration)Yes (Sigma-native)
Graylog (OSS)Yes (pipeline rules)NoNoNo (via lookup tables)Partial (pipeline code)
Elastic Security (Basic)Yes (EQL, KQL rules)NoNo (paid feature)Yes (Elastic TI module)Yes (detection rules as code)
Apache MetronYes (Stellar rules)NoYes (Spark ML)Yes (enrichment)Yes (Stellar expressions)
MozDefYes (alerts)NoNoYes (IntelMQ)Partial (Python alerts)
MatanoYes (Python detections)NoNoYes (enrichment tables)Yes (Python, native)
SigmaYes (rule format)NoNoNoYes (purpose-built)
TheHiveNo (alert consumer)NoNoYes (MISP, Cortex analyzers)No (response platform)
VelociraptorYes (VQL artifacts)NoNoYes (Sigma + Yara)Yes (VQL artifacts)
Grafana LokiYes (LogQL alerting)NoNoNoPartial (LogQL rules)
HayabusaYes (Sigma rules)NoNoNoYes (Sigma-native)
OSSECYes (XML rules)NoNoYes (CDB lists)Partial (XML rules in files)
Splunk ESYes (correlation searches, SPL)Yes (UBA add-on)Yes (MLTK)Yes (TI framework)Yes (SPL + conf files)
IBM QRadarYes (custom rules, building blocks)Yes (UBA app)Yes (QRadar AI)Yes (X-Force, STIX/TAXII)Partial (API-managed rules)
LogRhythmYes (AI Engine rules)Yes (UEBA module)Yes (AI Engine)Yes (TI framework)Partial (rule export/import)
ExabeamYes (correlation rules)Yes (core feature)Yes (behavioral ML)Yes (TI enrichment)Partial (rule API)
SecuronixYes (policies)Yes (core feature)Yes (ML models)Yes (TI feeds)Partial (policy API)
Sumo LogicYes (CSE rules)Yes (entity risk)Yes (anomaly detection)Yes (CrowdStrike TI)Yes (rules as code)
Rapid7 InsightIDRYes (detection rules)Yes (UBA built-in)Yes (behavioral analytics)Yes (Threat Command)Partial (API-managed)
Datadog SecurityYes (detection rules)NoYes (anomaly detection)Yes (TI enrichment)Yes (Terraform + API)
Elastic Sec. (Platinum)Yes (EQL, KQL, ESQL)Yes (ML jobs)Yes (anomaly detection, ML)Yes (TI module, STIX)
Graylog SecurityYes (correlation engine)Yes (anomaly detection)Yes (ML module)Yes (TI framework)Partial (API-managed rules)
DevoYes (correlation rules)Yes (behavioral)Yes (ML models)Yes (TI feeds, MISP)Yes (LINQ rules as code)
HuntersYes (detection stories)Yes (entity analytics)Yes (graph-based ML)Yes (multi-feed)Yes (detection stories)
Stellar CyberYes (correlation rules)Yes (ML-based)Yes (AI-driven)Yes (multi-feed TI)Partial (rule API)
Microsoft SentinelYes (analytics rules, KQL)Yes (UEBA built-in)Yes (Fusion ML, BYO ML)Yes (TI connectors, MDTI)Yes (ARM templates, KQL as code)
Google ChronicleYes (YARA-L rules)Yes (entity analytics)Yes (VirusTotal ML)Yes (VirusTotal, Mandiant TI)Yes (YARA-L rules as code)
AWS Security LakeNo (data lake only)NoNoNo (via consumers)No (data layer)
Amazon Security LakeNo (data lake only)NoNoNo (via consumers)No (data layer)
PantherYes (Python detections)NoNoYes (enrichment)Yes (Python, native DAC)

Incident Response

ToolCase ManagementPlaybooks / SOARAutomated ResponseTicketing Integration
WazuhNoNo (active response scripts)Yes (active response)Via API / webhook
Security OnionYes (SOC cases)NoNoTheHive integration
OSSIMYes (tickets)NoYes (policy actions)Built-in ticketing
OpenSearch Sec. AnalyticsNoNoNoVia OpenSearch alerting
Graylog (OSS)NoNoNoVia alert notifications
Elastic Security (Basic)Yes (cases)NoNoVia Kibana alerting
Apache MetronNoNoNoManual
MozDefYes (investigations)Yes (playbooks)Yes (automated actions)Via API
MatanoNoNoNoVia SNS / Lambda
SigmaN/AN/AN/AN/A
TheHiveYes (core feature)Yes (via Cortex)Yes (Cortex responders)Jira, GLPI, RT integration
VelociraptorNoNoYes (VQL remediation)Via API
Grafana LokiNoNoNoVia Grafana alerting
HayabusaNoNoNoNo (offline tool)
OSSECNoNoYes (active response)No
Splunk ESYes (notable events)Yes (SOAR / Phantom)Yes (adaptive response)Jira, ServiceNow, PagerDuty
IBM QRadarYes (offenses)Yes (SOAR module)Yes (custom actions)Jira, ServiceNow, Resilient
LogRhythmYes (cases)Yes (SmartResponse)Yes (automated response)Jira, ServiceNow
ExabeamYes (case management)Yes (playbooks)Yes (automated response)Jira, ServiceNow
SecuronixYes (incidents)Yes (SOAR module)Yes (response actions)Jira, ServiceNow
Sumo LogicYes (insights)Yes (Cloud SOAR)Yes (automated actions)Jira, ServiceNow, PagerDuty
Rapid7 InsightIDRYes (investigations)Yes (InsightConnect)Yes (containment actions)Jira, ServiceNow
Datadog SecurityYes (signals + cases)Yes (Workflow Automation)Yes (automated workflows)Jira, PagerDuty, Slack
Elastic Sec. (Platinum)Yes (cases)Yes (via Elastic rules)Yes (response actions)Jira, ServiceNow, Swimlane
Graylog SecurityNoNoYes (event definitions)Via alert notifications
DevoYes (cases)Yes (SOAR module)Yes (automated response)Jira, ServiceNow
HuntersYes (stories + cases)Yes (automated investigation)Yes (response actions)Jira, ServiceNow, Slack
Stellar CyberYes (incidents)Yes (playbooks)Yes (automated response)Jira, ServiceNow
Microsoft SentinelYes (incidents)Yes (Logic Apps / SOAR)Yes (automated response)Jira, ServiceNow, Dynamics 365
Google ChronicleYes (cases)Yes (Chronicle SOAR)Yes (automated playbooks)Jira, ServiceNow
AWS Security LakeNo (data lake only)NoNoVia consumer tools
Amazon Security LakeNo (data lake only)NoNoVia consumer tools
PantherNoNoYes (automated remediation)Jira, Slack, PagerDuty

Storage & Scale

ToolData ArchitectureRetentionHot / Warm / ColdEPS CapacityMulti-Tenancy
WazuhOpenSearch (Wazuh Indexer)Configurable (ISM policies)Yes (OpenSearch ISM)10K+ EPS (scales horizontally)Yes (multi-cluster)
Security OnionElasticsearch + RedisConfigurableYes (ILM)10K+ EPSNo (single instance)
OSSIMMySQL + flat files90 days defaultNo2K-5K EPSNo
OpenSearch Sec. AnalyticsOpenSearchConfigurable (ISM)Yes (ISM policies)50K+ EPS (scales horizontally)Yes (index-level isolation)
Graylog (OSS)Elasticsearch/OpenSearch + MongoDBConfigurable (index sets)Yes (index rotation)20K+ EPSNo (single tenant)
Elastic Security (Basic)ElasticsearchConfigurable (ILM)Yes (ILM + frozen tier)50K+ EPSNo (basic license)
Apache MetronHDFS + HBaseConfigurableYes (HDFS tiering)100K+ EPS (Kafka/Storm)No
MozDefElasticsearchConfigurableNo5K-10K EPSNo
MatanoS3 (Apache Iceberg tables)Unlimited (S3 lifecycle)Yes (S3 tiers)Scales with LambdaYes (AWS account isolation)
SigmaN/AN/AN/AN/AN/A
TheHiveElasticsearch/OpenSearch + CassandraConfigurableNoN/A (alert ingestion)Yes (organizations)
VelociraptorFile-based + LevelDBConfigurableNoN/A (forensics focus)Yes (multi-org)
Grafana LokiObject storage (S3, GCS)Configurable (retention)Yes (compactor)100K+ EPS (scales horizontally)Yes (tenant ID header)
HayabusaN/A (offline)N/AN/AN/AN/A
OSSECFlat filesConfigurableNo5K EPSNo
Splunk ESSplunk indexes (proprietary)Configurable (buckets)Yes (SmartStore + S3)100K+ EPS (indexer clustering)Yes (multi-tenant search heads)
IBM QRadarAriel DB (proprietary)ConfigurableYes (data offloading)50K+ EPS (distributed)Yes (domain separation)
LogRhythmElasticsearch + SQLConfigurableYes (archive tiers)40K+ EPSYes (entity separation)
ExabeamExabeam Data Lake365 days typicalYes (hot/cold)50K+ EPSYes (multi-tenant)
SecuronixSnowflake / Hadoop365+ daysYes (Snowflake tiers)100K+ EPSYes (cloud-native)
Sumo LogicProprietary cloud storageConfigurable (30-5000 days)Yes (infrequent tier)100K+ EPS (cloud scale)Yes (partitions)
Rapid7 InsightIDRRapid7 Insight cloud13 months defaultNo (cloud-managed)Cloud-scaleYes (multi-org)
Datadog SecurityDatadog cloud storage15 months default (logs)Yes (Online Archives)Cloud-scaleYes (multi-org)
Elastic Sec. (Platinum)ElasticsearchConfigurable (ILM)Yes (ILM + searchable snapshots)100K+ EPS (cluster scaling)Yes (spaces + RBAC)
Graylog SecurityElasticsearch/OpenSearch + MongoDBConfigurable (index sets)Yes (index rotation)50K+ EPSYes (Graylog Enterprise)
DevoDevo data lake (proprietary)400+ daysYes (online/nearline)1M+ EPS (claimed)Yes (multi-domain)
HuntersSnowflake (backend)ConfigurableYes (Snowflake tiers)Cloud-scaleYes (multi-tenant)
Stellar CyberClickHouse + ElasticsearchConfigurableYes (tiered storage)100K+ EPSYes (multi-tenant)
Microsoft SentinelAzure Log Analytics + ADX90 days hot, 12 years archiveYes (Analytics/Basic/Archive)Cloud-scale (no hard limit)Yes (workspace-per-tenant or Lighthouse)
Google ChronicleGoogle infrastructure12 months default (extendable)Managed (opaque)Petabyte-scaleYes (multi-tenant)
AWS Security LakeS3 (Apache Iceberg + Parquet)Configurable (S3 lifecycle)Yes (S3 tiers)Cloud-scaleYes (AWS Organizations)
Amazon Security LakeS3 (Apache Iceberg + Parquet)Configurable (S3 lifecycle)Yes (S3 tiers)Cloud-scaleYes (AWS Organizations)
PantherSnowflake (backend)ConfigurableYes (Snowflake tiers)Cloud-scaleYes (multi-account)

SSO / OIDC Comparison

These tools assume an Authentik-class OIDC provider as the IdP. OIDC is the preferred SSO protocol.

ToolOIDCSAMLSCIMAuthentik Notes
WazuhYes*Yes*NoVia OpenSearch Dashboards OIDC/SAML backend; Authentik as IdP; requires manual security config
Security OnionNoNoNoLocal auth; reverse proxy SSO possible
OSSIMNoNoNoLocal auth; LDAP integration
OpenSearch Sec. AnalyticsYesYesNoNative OIDC and SAML via OpenSearch Security plugin; Authentik as IdP
Graylog (OSS)NoNoNoLocal auth + LDAP; no SSO in OSS edition
Elastic Security (Basic)NoNoNoBasic license lacks SSO; Platinum required for OIDC/SAML
Apache MetronNoNoNoKnox Gateway for auth; no native OIDC/SAML
MozDefYes*NoNoOIDC via Mozilla configuration; limited documentation
MatanoN/AN/AN/AServerless; AWS IAM auth; no web UI
SigmaN/AN/AN/ARule format; no web UI
TheHiveYesNoNoNative OIDC (TheHive 5+); Authentik as OIDC IdP
VelociraptorYesNoNoNative OIDC support; Authentik as IdP
Grafana LokiYes*Yes*NoVia Grafana (OIDC/SAML); Authentik as IdP
HayabusaN/AN/AN/ACLI tool; no web UI
OSSECNoNoNoNo web UI in base OSSEC; relies on external dashboards
Splunk ESYesYesYesNative OIDC and SAML; SCIM via Splunk Cloud; Authentik as IdP
IBM QRadarNoYesNoSAML SSO; no native OIDC; LDAP/AD integration
LogRhythmNoYesNoSAML SSO; no OIDC; LDAP/AD integration
ExabeamYesYesYesNative OIDC and SAML; SCIM provisioning; Authentik as IdP
SecuronixYesYesYesNative OIDC and SAML; SCIM directory sync
Sumo LogicYesYesYesNative OIDC and SAML; SCIM provisioning; Authentik as IdP
Rapid7 InsightIDRNoYesYesSAML SSO; SCIM provisioning; no native OIDC
Datadog SecurityYesYesYesNative OIDC and SAML; SCIM directory sync; Authentik as IdP
Elastic Sec. (Platinum)YesYesNoNative OIDC and SAML via Elasticsearch security; Authentik as IdP
Graylog SecurityYesYesNoNative OIDC and SAML in Security/Enterprise edition; Authentik as IdP
DevoNoYesYesSAML SSO; SCIM provisioning; no native OIDC
HuntersYesYesNoNative OIDC and SAML; Authentik as IdP
Stellar CyberNoYesNoSAML SSO; no native OIDC; LDAP integration
Microsoft SentinelYes*YesYesEntra ID (Azure AD); OIDC federation; SAML; SCIM; Authentik as external IdP
Google ChronicleYes*YesYesGoogle Workspace / Cloud Identity; OIDC federation; Authentik as external IdP
AWS Security LakeYes*YesNoAWS IAM Identity Center; OIDC federation; Authentik as external IdP
Amazon Security LakeYes*YesNoAWS IAM Identity Center; OIDC federation; Authentik as external IdP
PantherYesYesYesNative OIDC and SAML; SCIM provisioning; Authentik as IdP

* = requires extension, plugin, specific configuration, or cloud identity federation

Best SSO support: Splunk ES, Exabeam, Securonix, Sumo Logic, Datadog, Panther (OIDC + SAML + SCIM)

No SSO: Security Onion, OSSIM, Graylog (OSS), Elastic (Basic), Apache Metron, OSSEC

OIDC among OSS: OpenSearch Security Analytics, TheHive, Velociraptor, Wazuh (via OpenSearch)


Monitoring Integration

monitoring stack integration for monitoring the SIEM platform itself and for sharing data between monitoring and SIEM.

ToolTelegraf MetricsFluent Bit LogsGrafana Dashboards
WazuhYes – Wazuh API stats via HTTP input; OpenSearch metrics via elasticsearch inputYes – Wazuh logs via tail input; forward to OpenSearchYes – Wazuh indices via OpenSearch data source; pre-built community dashboards
Security OnionYes – Elasticsearch metrics; system metrics of SO nodesYes – SO logs via syslog/tailYes – Elasticsearch data source; custom dashboards
OSSIMYes – system metrics; MySQL metricsYes – OSSIM logs via syslogLimited – no native Grafana integration
OpenSearch Sec. AnalyticsYes – OpenSearch stats via elasticsearch inputYes – OpenSearch logs via tailYes – native Grafana OpenSearch data source
Graylog (OSS)Yes – Graylog API metrics via HTTP input; Elasticsearch metricsYes – Graylog server logs via tailYes – Elasticsearch data source; Graylog metrics
Elastic Security (Basic)Yes – Elasticsearch cluster stats via elasticsearch inputYes – Elasticsearch logs via tailYes – native Elasticsearch data source
Apache MetronYes – Kafka, Storm, HBase metrics via JMX/JolokiaYes – Metron logs via tailLimited – custom dashboards
MozDefYes – Elasticsearch metrics; system metricsYes – MozDef logs via tailLimited – custom dashboards
MatanoYes – AWS CloudWatch metrics via cloudwatch inputYes – Lambda logs via CloudWatchYes – CloudWatch data source
SigmaN/AN/AN/A
TheHiveYes – TheHive API stats via HTTP inputYes – TheHive logs via tailYes – TheHive metrics via API; custom dashboards
VelociraptorYes – VR server metrics via HTTP inputYes – VR server logs via tailYes – custom dashboards
Grafana LokiYes – Loki metrics (Prometheus endpoint)Yes – Loki logs via tailYes – native Loki data source (same Grafana instance)
HayabusaN/A (offline tool)N/AN/A
OSSECYes – system metrics of OSSEC serverYes – OSSEC logs via tailLimited – custom dashboards
Splunk ESYes – Splunk REST API metrics via HTTP inputYes – Splunk internal logs via syslog forwardingYes – Splunk data source plugin (unofficial)
IBM QRadarYes – QRadar API health metrics via HTTP inputYes – QRadar syslog forwardingLimited – QRadar API for custom dashboards
LogRhythmYes – system metrics of LR nodesYes – LogRhythm logs via syslogLimited – custom dashboards
ExabeamYes – Exabeam API health metricsYes – Exabeam logs via syslogLimited – API-based custom dashboards
SecuronixLimited – cloud service; API health onlyYes – syslog forwardingLimited – API-based
Sumo LogicLimited – cloud service; Health Events APIYes – via Sumo Logic APILimited – cloud service
Rapid7 InsightIDRLimited – cloud service; API healthNo (cloud-managed)Limited – cloud service
Datadog SecurityLimited – cloud service; API metricsNo (cloud-managed)Limited – Datadog has its own dashboards
Elastic Sec. (Platinum)Yes – Elasticsearch cluster stats via elasticsearch inputYes – Elasticsearch logs via tailYes – native Elasticsearch data source
Graylog SecurityYes – Graylog API metrics; Elasticsearch metricsYes – Graylog logs via tailYes – Elasticsearch data source
DevoLimited – cloud service; API healthYes – syslog forwardingLimited – API-based
HuntersLimited – cloud serviceNo (cloud-managed)Limited – cloud service
Stellar CyberYes – ClickHouse/ES metrics; platform metricsYes – platform logs via syslogYes – built-in Grafana or custom
Microsoft SentinelLimited – Azure Monitor metrics via Azure inputYes – Azure diagnostic logsYes – Azure Monitor data source
Google ChronicleLimited – cloud serviceNo (cloud-managed)Limited – cloud service
AWS Security LakeYes – CloudWatch metricsYes – CloudTrail/CloudWatch logsYes – CloudWatch data source
Amazon Security LakeYes – CloudWatch metricsYes – CloudTrail/CloudWatch logsYes – CloudWatch data source
PantherLimited – cloud service; API healthNo (cloud-managed)Limited – cloud service

Compliance & Reporting

ToolBuilt-in ReportsCustom DashboardsCompliance Frameworks
WazuhYes (regulatory reports)Yes (OpenSearch Dashboards)PCI-DSS, HIPAA, GDPR, NIST 800-53, TSC, CIS
Security OnionLimitedYes (Kibana)No pre-built compliance
OSSIMYes (compliance reports)Yes (USM dashboards)PCI-DSS, HIPAA, ISO 27001
OpenSearch Sec. AnalyticsLimited (findings)Yes (OpenSearch Dashboards)No pre-built compliance
Graylog (OSS)NoYes (custom dashboards)No pre-built compliance
Elastic Security (Basic)LimitedYes (Kibana dashboards)No pre-built compliance (basic)
Apache MetronNoLimitedNo pre-built compliance
MozDefLimitedYes (custom dashboards)No pre-built compliance
MatanoNoVia Athena/QuickSightNo pre-built compliance
SigmaN/AN/AN/A
TheHiveYes (case reports)LimitedNo pre-built compliance
VelociraptorYes (hunt reports)LimitedCIS benchmarks (via hunts)
Grafana LokiNoYes (Grafana dashboards)No pre-built compliance
HayabusaYes (timeline reports)NoMITRE ATT&CK mapping
OSSECYes (regulatory reports)No (external dashboards)PCI-DSS, CIS
Splunk ESYes (extensive report library)Yes (dashboard studio)PCI-DSS, HIPAA, GDPR, SOX, NIST, CIS, ISO 27001
IBM QRadarYes (compliance reports)Yes (custom dashboards)PCI-DSS, HIPAA, SOX, GDPR, ISO 27001
LogRhythmYes (compliance modules)Yes (dashboard builder)PCI-DSS, HIPAA, SOX, GDPR, NIST, CMMC
ExabeamYes (compliance reports)Yes (custom dashboards)PCI-DSS, HIPAA, SOX, GDPR
SecuronixYes (compliance analytics)Yes (custom reports)PCI-DSS, HIPAA, SOX, GDPR, NIST
Sumo LogicYes (compliance dashboards)Yes (dashboard builder)PCI-DSS, HIPAA, SOC 2, GDPR, FedRAMP
Rapid7 InsightIDRYes (compliance reports)Yes (custom dashboards)PCI-DSS, HIPAA, SOC 2
Datadog SecurityYes (security reports)Yes (dashboard builder)PCI-DSS, HIPAA, SOC 2, GDPR
Elastic Sec. (Platinum)Yes (compliance reports)Yes (Kibana dashboards)PCI-DSS, HIPAA, CIS, NIST
Graylog SecurityYes (Illuminate reports)Yes (custom dashboards)PCI-DSS, HIPAA (via Illuminate)
DevoYes (compliance reports)Yes (custom dashboards)PCI-DSS, HIPAA, SOX, GDPR, NIST
HuntersYes (SOC reports)Yes (custom dashboards)PCI-DSS, HIPAA
Stellar CyberYes (compliance reports)Yes (custom dashboards)PCI-DSS, HIPAA, NIST, CIS
Microsoft SentinelYes (workbooks + reports)Yes (workbooks, Power BI)PCI-DSS, HIPAA, SOC 2, GDPR, NIST, ISO 27001, FedRAMP
Google ChronicleYes (reports)Yes (custom dashboards)PCI-DSS, HIPAA, SOC 2
AWS Security LakeVia consumer toolsVia Athena/QuickSightFramework support depends on consumer
Amazon Security LakeVia consumer toolsVia Athena/QuickSightFramework support depends on consumer
PantherYes (detection reports)Yes (Snowflake dashboards)PCI-DSS, HIPAA, SOC 2

Tools

33 tools.

Amazon GuardDuty

Amazon GuardDuty is an intelligent threat detection service that continuously monitors AWS accounts and workloads for malicious activity and unauthorized behavior.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none

Website

Apache Metron

Apache Metron was an open-source big data security analytics platform designed to process and analyze massive volumes of security telemetry in real time.

License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

AWS Security Lake

AWS Security Lake is a purpose-built security data lake service that automatically centralizes security data from AWS services, SaaS providers, on-premises systems, and cloud sources into a purpose-built data lake stored in S3.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none

Website

Datadog Security

Datadog Security is the security monitoring suite within the Datadog observability platform, providing Cloud SIEM, Cloud Security Management (CSM), Application Security Management (ASM), and Cloud Workload Security (CWS).

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML

Website

Devo

Devo is a cloud-native security data analytics platform designed for high-speed data ingestion and real-time analysis at massive scale.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML

Website

Elastic Security Basic

Elastic Security is the SIEM and security analytics solution built into the Elastic Stack (Elasticsearch, Kibana, Beats/Elastic Agent).

License: LicenseRef-Elastic-2.0 (source-available) · Kind: web · Deploy: native, docker, k8s · SSO: none

Website

Elastic Security Platinum

Elastic Security Platinum is the commercial tier of Elastic Security that adds machine learning anomaly detection, endpoint protection (Elastic Defend), cross-cluster search, SSO/OIDC authentication, and advanced response actions to the fre…

License: Proprietary (proprietary) · Kind: web · Deploy: native, docker, k8s · SSO: none

Website

Exabeam

Exabeam is a next-generation SIEM platform known for its advanced User and Entity Behavior Analytics (UEBA) capabilities.

License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none

Website

Google Chronicle

Google Chronicle (now part of Google Security Operations) is a cloud-native security analytics platform built on Google’s infrastructure that provides petabyte-scale security data retention, sub-second search across months of data, and auto…

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC

Website

Grafana Loki (Security Use)

Grafana Loki is a horizontally scalable, highly available log aggregation system designed to be cost-effective and operationally simple.

License: AGPL-3.0-only (OSS) · Kind: web · Deploy: native, docker, k8s · SSO: none

Website · Source

Graylog Open Source

Graylog is an open-source log management platform designed for collecting, indexing, and analyzing log data from any source.

License: SSPL-1.0 (source-available) · Kind: web · Deploy: native, docker · SSO: none

Website

Graylog Security

Graylog Security is the commercial SIEM tier of the Graylog platform that adds anomaly detection, security-specific content, correlation engine, compliance reporting, and OIDC/SAML authentication to Graylog’s strong log management foundatio…

License: Proprietary (proprietary) · Kind: web · Deploy: native, docker · SSO: none

Website

Hayabusa

Hayabusa is a fast, open-source Windows event log (EVTX) analyzer written in Rust by Yamato Security, applying 4,000+ Sigma-based rules mapped to MITRE ATT&CK for threat hunting and forensics.

License: GPL-3.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Hunters

Hunters is a cloud-native SOC (Security Operations Center) platform that automates threat detection, investigation, and response across the entire security stack.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML

Website

IBM QRadar

IBM QRadar is an enterprise SIEM platform providing log management, network flow analysis, vulnerability assessment correlation, and advanced threat detection.

License: Proprietary (proprietary) · Kind: web · Deploy: native, saas, appliance · SSO: none

Website

LogRhythm

LogRhythm is an enterprise SIEM platform that combines log management, network and endpoint monitoring, UEBA, and SOAR capabilities into an integrated security operations platform.

License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none

Website

Matano

Matano is an open-source serverless security data lake platform designed for AWS. It enables security teams to collect, normalize, and analyze petabyte- scale security logs using a detection-as-code approach.

License: Apache-2.0 (OSS) · Kind: web · Deploy: saas, native · SSO: none

Website · Source

Microsoft Sentinel

Microsoft Sentinel is Azure’s cloud-native SIEM and SOAR platform that provides intelligent security analytics across the enterprise.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC

Website

MozDef

MozDef (Mozilla Defense Platform) is an open-source security incident management and automation platform developed by Mozilla’s Enterprise Information Security team.

License: MPL-2.0 (OSS) · Kind: web · Deploy: native, docker · SSO: none

Website · Source

OpenSearch Security Analytics

OpenSearch Security Analytics is a security plugin built into OpenSearch that provides SIEM-like detection, correlation, and alerting capabilities directly within the OpenSearch platform.

License: Apache-2.0 (OSS) · Kind: web · Deploy: native, docker, k8s · SSO: OIDC

Website · Source

OSSEC

OSSEC (Open Source Security Event Correlator) is a host-based intrusion detection system (HIDS) that provides log analysis, file integrity monitoring, rootkit detection, active response, and real-time alerting.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

OSSIM / AlienVault Open Source

OSSIM (Open Source Security Information Management) is an open-source SIEM platform originally developed by AlienVault, now maintained by AT&T Cybersecurity.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Panther

Panther is a cloud-native SIEM platform built around the detection-as-code paradigm, where all detection rules are written in Python and managed through Git version control workflows.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: SAML

Website

Rapid7 InsightIDR

Rapid7 InsightIDR is a cloud SIEM platform that combines log search, UEBA, network traffic analysis, endpoint detection, and deception technology into a unified threat detection and response solution.

License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none

Website

Security Onion

Security Onion is a comprehensive open-source network security monitoring (NSM) and SIEM platform that combines full packet capture, network-based and host-based intrusion detection, log management, and case management into a single distrib…

License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

Securonix

Securonix is a cloud-native SIEM platform built around User and Entity Behavior Analytics (UEBA) as a core capability rather than an add-on.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML

Website

Sigma

Sigma is an open, vendor-agnostic YAML format for log-based security detection rules, with a community rule repository and the pySigma framework to convert rules to many SIEM query languages.

License: LicenseRef-DRL-1.1 (source-available) · Kind: web · Deploy: saas · SSO: none

Website · Source

Splunk Enterprise Security

Splunk Enterprise Security (ES) is the market- leading commercial SIEM platform, providing comprehensive security monitoring, advanced threat detection, incident investigation, and compliance reporting.

License: Proprietary (proprietary) · Kind: web · Deploy: native · SSO: none

Website

Stellar Cyber

Stellar Cyber is an Open XDR platform designed specifically for security teams and MSSPs that need to detect and respond to threats across their entire attack surface.

License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none

Website

Sumo Logic

Sumo Logic is a cloud-native log analytics and SIEM platform that provides real-time security monitoring, threat detection, and compliance reporting as a SaaS service.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: SAML

Website

TheHive

TheHive is a SOC incident-response case-management platform. TheHive 5 is proprietary freemium (ex-AGPL); the companion Cortex engine stays AGPL-3.0.

License: Proprietary (proprietary) · Kind: web · Deploy: native, docker, saas · SSO: none

Website · Source

Velociraptor

Velociraptor is an open-source digital forensics and incident response (DFIR) tool focused on endpoint visibility and artifact collection at scale.

License: AGPL-3.0-only (OSS) · Kind: web · Deploy: native, docker · SSO: OIDC

Website · Source

Wazuh

Wazuh is a comprehensive open-source security platform that provides unified XDR and SIEM capabilities.

License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: SAML

Website · Source

ResorsIT Tools Catalog Search