Expert Guide

The Best Free SIEM Tools in 2026

Seven free SIEM options compared on volume and source limits, login rules and the first paid step, read from vendor pages on 10 October 2026.

Product links may be affiliate links. How we rate 7 tools compared
TL;DR

Wazuh is the strongest free SIEM for a team that can run its own servers: its GPLv2 license costs $0 and sets no volume terms. Splunk Free is the most familiar name, but its license indexes 500 MB a day, removes user logins and stops searches after repeated violations, so it suits a lab or a single-instance trial, not production volume. Graylog Open is the free option whose vendor states no daily cap at all, but its Enterprise tier is priced from 10 GB a day, with a stated starting price on the pricing page.

Every option here costs you servers, storage and analyst time. Pick by the limit you will hit first, and check it against your own log sources before you install anything. All facts were checked on vendor pages on 10 October 2026.

Key facts7 tools compared: Wazuh, Security Onion, OpenSearch with Security Analytics, Elastic Security…
  • Updated: October 11, 2026
  • Top pick: Wazuh (best for: Teams with an engineer who can run servers, agents and detection rules)
  • Top pick price as of October 11, 2026: Wazuh: Free under GPLv2, self-hosted; no paid price found on the pages we read, so none is quoted
  • 7 tools compared: Wazuh, Security Onion, OpenSearch with Security Analytics, Elastic Security, Basic tier, Splunk Free, Graylog Open, ManageEngine EventLog Analyzer, Free Edition
  • Security Onion (best for: Network security monitoring teams that want Zeek, Suricata and Elastic in one build): Free and open under its LICENSE file; a Pro offering exists, but its price is not on the page
  • OpenSearch with Security Analytics (best for: Teams already running an Elastic-style stack that want Sigma rules on top): Free under the Apache License 2.0; you pay only for the servers and storage that run it
  • Elastic Security, Basic tier (best for: Teams that want Elastic search and SIEM features with a free self-managed start): Basic is free under the Elastic License; Platinum is closed to new customers and Enterprise is quoted

A free SIEM is free to license, not free to operate. Each option asks for something else: a server, disk space, a parser for each log source, detection content and someone who reads the alerts.

What separates them is the limit you hit first: a daily volume, a number of log sources, the users who can sign in, or the point where the vendor's price begins.

How we ranked: first the license and whether it is open source or free to license, then the limit a small security team meets first, then how much detection content ships with the free build.

We did not install these products. The table reports what each vendor says on its own pages, and where a page is silent we say so.

Cyberpresso data: Toolradar's October 2026 security ranking evaluated 855 security tools, and 5 of its 10 top picks have a free plan.

Of the seven free options below, only Splunk Free publishes a daily volume cap in its free license, ManageEngine caps its free edition at five log sources, and Graylog Open says it has no volume limit. Four tools were left out, and the reasons are given further down.

Top Picks

Based on features, real-world fit, and value for money.

Best Free SIEM Tools in 2026: What the Free Tiers Actually Allow: 7 tools compared, updated Oct 2026
ToolPricingBest for
WazuhFree under GPLv2, self-hosted; no paid price found on the pages we read, so none is quotedTeams with an engineer who can run servers, agents and detection rules
Security OnionFree and open under its LICENSE file; a Pro offering exists, but its price is not on the pageNetwork security monitoring teams that want Zeek, Suricata and Elastic in one build
OpenSearch with Security AnalyticsFree under the Apache License 2.0; you pay only for the servers and storage that run itTeams already running an Elastic-style stack that want Sigma rules on top
Elastic Security, Basic tierBasic is free under the Elastic License; Platinum is closed to new customers and Enterprise is quotedTeams that want Elastic search and SIEM features with a free self-managed start
Splunk FreeFree license that never expires and indexes 500 MB a day; Enterprise Security is quote-onlyLabs and single-instance trials that want Splunk search skills without a bill
Graylog OpenFree permanently with no daily ingest cap; Enterprise starts at $15,000 a year from 10 GB a dayTeams with high log volume that can live without SSO, teams or LDAP roles
ManageEngine EventLog Analyzer, Free EditionFree edition at $0, never expires, up to 5 log sources; Professional starts at $795 a year for 10 sourcesSmall teams with five or fewer critical log sources, such as one firewall and a few servers

Pricing read from each vendor's own published pricing page, checked Oct 2026. Every vendor here publishes a price.

Best for: Teams with an engineer who can run servers, agents and detection rules

PricingFree under GPLv2, self-hosted; no paid price found on the pages we read, so none is quoted

+GPLv2 license with no per-GB fee, so your cost is hardware, storage and staff time.
+The GitHub page describes it as a free and open source platform for threat prevention, detection and response.
+Self-hosted, so log data stays on your servers unless you forward it somewhere else.
−You install, patch and tune it yourself, and the free license comes with no service contract.
−Detection value depends on the decoders and rules your team maintains, so the first month is setup work.
Visit Wazuh →

Best for: Network security monitoring teams that want Zeek, Suricata and Elastic in one build

PricingFree and open under its LICENSE file; a Pro offering exists, but its price is not on the page

+Pairs network visibility from Suricata and Zeek with log search, which a log-only SIEM does not give you.
+Includes its own interfaces for alerting, dashboards, hunting, PCAP, detections and case management, according to the project's GitHub description.
+The repository shows 4.9k stars and a LICENSE file that governs use.
−It is a full Linux distribution with its own stack, so it is a bigger commitment than a log-only tool.
−The Pro offering is mentioned without a price, so the paid step is unknown until you ask.
Visit Security Onion →

Best for: Teams already running an Elastic-style stack that want Sigma rules on top

PricingFree under the Apache License 2.0; you pay only for the servers and storage that run it

+The OpenSearch FAQ says the whole project is released under the Apache License, Version 2.0.
+Security Analytics ships log types for Windows, Linux, AWS CloudTrail, Microsoft 365, Okta and GitHub, among others.
+Supports correlation rules as well as its detectors, according to its documentation.
−You assemble and host the whole stack, from storage to dashboards.
−Detection quality depends on the Sigma rules you select and tune.
Visit OpenSearch with Security Analytics →

Best for: Teams that want Elastic search and SIEM features with a free self-managed start

PricingBasic is free under the Elastic License; Platinum is closed to new customers and Enterprise is quoted

+The subscriptions page lists SIEM, prebuilt detection rules and a detection engine for correlation and threshold rules.
+Built on the Elastic Stack, so teams that already run Elasticsearch can reuse the skills.
−The page does not say which tier includes the SIEM and detection rows, so confirm that before you plan around them.
−The Elastic License is not an open-source license, so it does not carry the freedoms of an open-source license.
Visit Elastic Security, Basic tier →

Best for: Labs and single-instance trials that want Splunk search skills without a bill

PricingFree license that never expires and indexes 500 MB a day; Enterprise Security is quote-only

+The free license does not expire, so a lab can run for as long as it needs to.
+Same search language as the paid product, so the skills carry over to Splunk Enterprise.
−The daily cap works out to about 15 GB a month. Each day over the cap raises a license violation warning, and repeated warnings stop searching.
−There are no user accounts or logins, no distributed search and no indexer clustering, so the free build cannot grow into a team tool.
Visit Splunk Free →

Best for: Teams with high log volume that can live without SSO, teams or LDAP roles

PricingFree permanently with no daily ingest cap; Enterprise starts at $15,000 a year from 10 GB a day

+Graylog's pricing page says Open is free permanently and is not a trial.
+Local role-based access control is included, so each analyst can have a login.
+The paid step has a stated starting point, shown on the pricing page as a yearly price and a daily volume.
−SSO, teams and LDAP role-based access are paid-only, so a larger team hits the paid tier on access control, not on volume.
−The pricing page gives no retention or search limits for Open, so check the documentation before you rely on the history.
Visit Graylog Open →

Best for: Small teams with five or fewer critical log sources, such as one firewall and a few servers

PricingFree edition at $0, never expires, up to 5 log sources; Professional starts at $795 a year for 10 sources

+The free edition includes centralized log collection, log search reports, compliance reports and forensic analysis.
+The paid Professional tier is priced by log source count, from 10 to 1,000 sources, so the step up is easy to forecast.
−Five sources is a small ceiling: a firewall, a domain controller and three servers fill it.
−It is a commercial product, so the free edition is also a route to Professional.
Visit ManageEngine EventLog Analyzer, Free Edition →

What it is

A SIEM collects logs from servers, endpoints, identity providers, cloud accounts and network devices, normalizes them and runs rules that flag combinations worth an analyst's time. A free SIEM does the same job on a license that costs nothing.

What the free license leaves out is the difference: daily volume, user accounts, clustering, or the detections and support the vendor keeps for its paid tier.

Our general ranking of paid and free platforms is in the best SIEM tools guide, so this page covers only the free tiers and their limits.

The seven options fall into three groups. Wazuh, OpenSearch with its Security Analytics plugin and Security Onion are free and open platforms you install yourself.

Splunk Free and the ManageEngine free edition are commercial products with a free license that carries a hard limit. Elastic's Basic tier is the free tier of a commercial product, under the Elastic License. Graylog Open is a free edition of a commercial log platform, with a narrower feature set than its paid tiers.

The license matters for what you can do with the software. The OpenSearch FAQ states that the Elastic License is not open source, and Elastic's subscriptions page places its Basic tier under that license.

Why it matters

Free tiers decide where your first SIEM lives, and the cap you hit first is usually the one you hit during an incident. The logs you need most in an investigation, the firewall, the identity provider and the cloud audit trail, are the same logs that push a volume cap over the line.

Size the plan on the peak day, not the average day. Splunk's license is measured per day, so one heavy day produces a violation warning, and repeated warnings stop searches.

The cost moves to people and hardware.

Wazuh, OpenSearch and Security Onion cost nothing to license and a good deal to run: servers, storage, parsers and the hours to keep rules current. Graylog and ManageEngine publish a starting price for the next step, tied to daily volume or log sources, so that step is something you can forecast from your own estate.

Splunk Enterprise Security is quoted on request.

For a team with no one to run a platform, managed detection services are a better use of budget than a free install nobody watches, and the incident response platforms guide covers what comes after detection.

Run the numbers for a team that sends 10 GB a day.

Splunk Free's daily cap is a twentieth of that volume, so the free license is out at that size. Graylog Open has no cap, but its Enterprise tier starts at $15,000 a year, or about $1,250 a month. Wazuh and OpenSearch carry no license cost at that volume, so the bill is the servers, storage and analyst time it takes to run them.

For a team with five sources or fewer, ManageEngine's free edition is enough. Past five sources, its Professional tier at 10 sources starts at $795 a year, about $66 a month.

Four tools are left out, and none of them is a free SIEM license.

Microsoft Sentinel offers up to 5 MB a day per user of free ingestion for key security logs, and its commitment tiers start at 100 GB a day with no per-GB list price on the page we read. Logz.io lists no permanent free plan, only a free trial, and its log management is $0.92 per ingested GB per day with 7 days of retention.

Sumo Logic's pricing page names only a free trial, and its first paid plan is priced on contact. Axiom has a permanent free Personal plan at $0 a month, with 500 GB a month of data loading and 25 GB of storage. Its paid Cloud plan adds a $25 monthly platform fee plus usage. It is a log analytics platform rather than a security SIEM, so we did not rank it.

Key features to look for

Daily volume capEssential
Splunk Free caps daily indexing and issues a license violation warning for each day over it. Graylog Open says it has no daily ingest cap. The self-hosted platforms have no cap in their licenses, so the hardware you run sets the limit.
Log source limitEssential
ManageEngine's free edition supports up to five log sources. A firewall, a domain controller and three servers use all five, so choose the first sources with care.
Logins and user rolesEssential
Splunk Free removes all user accounts and logins, and Splunk Web opens straight into an administrator session. Graylog Open keeps local role-based access control, but SSO, teams and LDAP roles stay on the paid tiers.
Detection content
OpenSearch Security Analytics starts from open Sigma rules and supports correlation rules. Elastic's subscriptions page lists prebuilt detection rules, but the page does not say which tier includes them.
Upgrade path
Splunk Enterprise Security is quoted on request, while Graylog Enterprise and ManageEngine Professional each publish a starting price tied to volume or log sources. Compare those three before you install anything.

Pricing

Prices and limits were read on vendor pages on 10 October 2026, in US dollars. Graylog's pricing page describes Open as free with no daily ingest cap, and Enterprise as starting at $15,000 a year on volume.

ManageEngine's EventLog Analyzer page lists a free edition at $0 for up to five log sources and a Professional tier from $795 a year, priced by source count from 10 to 1,000.

Splunk's pricing page shows a free trial and a quote form for Enterprise Security, with no list price.

The free license limits come from Splunk's documentation on the free license. We found no list price for Wazuh on the pages we read, so none is quoted.

The Elastic subscriptions page gives no USD price for self-managed licensing.

PlanPriceBest for
WazuhFreeGPLv2, self-hosted; you pay for servers and staff time
Security OnionFreeFree and open platform; the Pro offering has no price on the page
OpenSearch with Security AnalyticsFreeApache License 2.0; Sigma-based detectors; hosting cost only
Elastic Security, BasicFreeElastic License, not open source; SIEM and prebuilt rules listed, tier split not stated
Splunk FreeFree500 MB a day, no expiry, no logins, no distributed search
Splunk Enterprise SecurityQuote onlyPricing page offers a quote form and a free trial, with no list price
Graylog OpenFreeNo daily ingest cap; local role-based access; narrower features than paid tiers
Graylog Enterprise$15,000 a yearStarts at 10 GB a day on daily volume, or 100 GCUs on annual consumption
ManageEngine EventLog Analyzer, Free EditionFreeUp to 5 log sources; never expires
ManageEngine EventLog Analyzer, Professional$795 a yearStarting price; pricing depends on 10 to 1,000 log sources
Mistakes to avoid
×Sizing for the average day. Splunk Free's cap is per day, so one heavy day produces a violation warning even when the rest of the week is quiet. Size for the peak day and keep a month of daily volume to check against.
×Counting only the license. The three open platforms cost nothing to license but a real amount to run: servers, storage, parsers and the hours to keep detection rules current. If you also need endpoint coverage, see the <a href="/reviews/best-edr-endpoint-protection">EDR guide</a>.
×Choosing on the feature list alone. Splunk Free removes logins and clustering, and Graylog Open narrows the features. Test the one workflow your analysts use every day before you commit.
×Counting sources at the end. ManageEngine's free edition covers five sources, and its Professional tier starts at 10. Count the sources you need on day one before you install.
Expert tips
→Start with identity and endpoint logs. They usually produce more detections per gigabyte than chatty network logs, which matters when the free cap is small. Our <a href="/blog/ai-for-soc">AI for SOC guide</a> covers where automated triage helps once the logs are flowing.
→Track daily ingest from day one. A trend line shows when you will cross a cap, so you can move up before the warnings start.
→Test Wazuh or OpenSearch on a copy of one month of logs before you point production sources at them. Our <a href="/reviews/best-network-security-monitoring-tools">network security monitoring guide</a> covers the Zeek and Suricata side if you need packet-level visibility.
→Count analyst time as a cost. A free SIEM that nobody tunes produces alerts nobody reads, and our <a href="/blog/how-much-does-a-siem-cost">SIEM cost breakdown</a> shows where the real money goes.

The bottom line

Wazuh is the best free SIEM for a team with the people to run it, and it carries no license fee or volume terms. Graylog Open is the free option whose vendor states no volume limit, at the price of narrower features.

OpenSearch with Security Analytics and Elastic's Basic tier suit teams already on those stacks.

Splunk Free works for a lab or a single-instance trial, not for production volume, and ManageEngine's free edition only fits five log sources.

If you need detection content and a vendor on the phone, a free license is the wrong tool, and our best SIEM tools guide compares the paid platforms.

The Wazuh listing on Toolradar, the Graylog listing and the Splunk listing show how each sits in the wider market.

For what a paid platform costs, read how much a SIEM costs.

Methodology: we read vendor pricing and documentation pages on 10 October 2026, including OpenSearch's FAQ and Splunk's free license documentation, the GitHub pages for Wazuh and Security Onion, and the Toolradar security ranking.

We did not install or test any of these products. Where a vendor page did not state a figure, the page says so instead of estimating it.

Cite this: Cyberpresso, "Best Free SIEM Tools in 2026", October 2026.

Frequently asked questions

What is the best free SIEM tool in 2026?
Wazuh is the strongest free SIEM for a team that can run its own servers. Its GPLv2 license carries no fee and no volume terms, so your cost is hardware, storage and staff time. If you want a free option whose vendor states no daily volume limit, Graylog Open says it has none, with a narrower feature set.
Is Splunk Free enough for a SOC?
Not for a production SOC. Splunk Free indexes 500 MB a day, which is about 15 GB a month, removes user logins, and does not support distributed search or indexer clustering. It suits a lab, a demo or a single-instance trial of Splunk search.
Wazuh or Splunk: which is cheaper?
Wazuh has no license fee, so its cost is servers and analyst time. Splunk Free is also free to license but caps indexing at about 15 GB a month. Splunk Enterprise Security has no list price on the pages we read, so there is no paid number to compare.
Is there a free SIEM with no log volume limit?
Graylog Open is the one whose vendor says it has no daily ingest cap and no volume limit of any kind. Wazuh's GPLv2 license sets no volume terms either. Both still cost hardware, storage and admin time, and Graylog Open leaves SSO, teams and LDAP roles to its paid tiers.
When does a free SIEM need a paid step?
Move up when the free limit binds: volume above the Splunk cap, more than five log sources in ManageEngine's free edition, SSO or LDAP roles in Graylog, or detection content you need. Graylog Enterprise and ManageEngine Professional both publish a starting price tied to volume or source count, so the next bill is predictable before you buy.

Sources

Prices and plan details come from each vendor's own pricing page, re-checked by the Toolradar pricing tracker.

Related guides

Some offers on this page may be paid placements or contain affiliate links.

Get the Cyberpresso brief

Free daily newsletter, read in 5 minutes.

Subscribe free