Subscribe
Skip to content
Subscribe

Security Operations

SIEM alternatives that still see the data (2026)

A 2026 shortlist of platforms teams reach for when the legacy SIEM is too slow, too expensive, or blind to data it never ingested. Public docs, not a lab bake-off.

Expertise: Security Operations · Level: Intermediate · 18 min read

Ingestion is the tax, not the feature.

The invoice hits before the hunt. A cloud audit trail you never onboarded. A SaaS source you skipped because the ingest meter is already red. A PCAP that lived on a sensor the SIEM never met. Mean time to detect is often a coverage problem wearing a staffing badge.

Six platforms. One post-SIEM mesh that queries where data already sits. Two open stacks you operate. One search-native SIEM. One hyperscaler console. One detection-as-code lake. Public pages, licenses, and live threads. Not a bake-off.

Technical check: we cross-check first-party product pages, public licenses, and live HN and Stack Exchange threads. Rank is a technical recommendation, not a recap of other lists, and not a lab bake-off.

PlatformBest forLicense
VegaQuerying data the SIEM never ingestedCommercial
WazuhOSS SIEM and XDR you operateGPLv2; Cloud from $571/month
Elastic SecuritySearch-native SIEM you can self-hostELv2 / subscription
Microsoft SentinelMicrosoft-estate cloud SIEMAzure consumption
PantherDetection-as-code on a lakeCommercial
Security OnionHunt grid with NSM and host telemetryFree + ELv2 components
Where it sits
Ingest, then hunt
Query in their cloud None on this list
Ingest on your stack
Query where it lives
1

Vega

Best for querying data the SIEM never ingested

Vega

Vega’s own homepage opens with “Welcome to the Post-SIEM Era.” They sell an Agentic Cyber Defense Platform on a Security Analytics Mesh: hunt, detection, and triage against data where it already lives. Vega is post-SIEM, not a cheaper console.

Key features

  • Security Analytics Mesh that queries sources in place. No migration, ingest, or parsing tax on their page
  • Natural language, KQL, or MCP against datasets treated as one OCSF view
  • Multi-cell notebooks for investigations that they call rerunnable
  • Object storage across the three major clouds, with a single unified view in their docs

Why we like it

This is the honest federated option on a list still full of ingest products. If the pain is data the SIEM never saw, a mesh that refuses to copy it is the architectural answer their site actually makes. Founded 2024. Young. Treat the 82% cost claim as first-party marketing. We did not measure it.

Limits

They do not publish a price card. The AWS Marketplace listing is contract-based, with no public per-GB card. Vega is not a drop-in EDR. They refuse the SIEM label. A 2024-founded platform still has to earn detections, parsers, and staff muscle that older stacks already have.

License

Commercial. Demo and contact sales. No public per-GB card on vega.io.

2

Wazuh

Best for an OSS SIEM and XDR you operate

Wazuh

Wazuh is the open platform most teams actually mean when they say “we will just run a SIEM.” Unified XDR and SIEM on an agent plus a server, indexer, and dashboard. File integrity, config assessment, vuln detection, log analysis, active response. Source is GPLv2 on GitHub.

Key features

  • Agent on Linux, Windows, macOS, and a long Unix list; agentless syslog and API collection for network gear
  • Server decoders and rules, plus an indexer and dashboard with PCI, GDPR, CIS, HIPAA, and NIST views
  • Active response on the device
  • Wazuh Cloud if you do not want to run the cluster: Small starts at $571/month, 14-day trial, no card

Why we like it

No license cost on the software you compile and run. That is a real alternative to an ingest invoice, if you can staff the cluster. The live HN thread is less about the agent and more about the unpaid work: parsers, rules, and learning the nominal feed.

ArnoVW wrote it in October 2024, on a self-hosted Docker deploy: “The real thing that takes time is the installation and configuration of the rules and agents. That’s something that you have to do for any SIEM really, irrespective of open source / paid: you have to understand your nominal feed and that takes time.”

Limits

Out-of-the-box parsers are not the reason people pick a commercial SIEM. A later HN comment on the same thread put it bluntly: the value of a modern SIEM is mostly integrations and log parses, and Wazuh is far from that in that writer’s experience. You operate the indexer. You own the upgrades. Cloud shifts that labor onto a monthly tier.

License

GPLv2 for the source, including decoders and rules unless a file says otherwise. Wazuh Cloud is a paid SaaS on top of that, starting at $571/month for up to 100 agents.

3

Elastic Security

Best for a search-native SIEM you can still self-host

Elastic Security

Elastic Security is the SIEM and XDR skin on Elasticsearch. Their 2026 pitch is an agentic SOC priced on compute and storage, not per device. You can still deploy hosted, serverless, or self-managed, including air-gapped. That last option is why it stays on a list next to Wazuh and Security Onion.

Key features

  • SIEM and XDR on one Elasticsearch bill. Native automation, no separate SOAR license on their page
  • Query years of archived data in place. They call rehydration a data tax they dropped
  • Model-agnostic AI. Public detection rules on GitHub, ECS and OCSF, versioned APIs
  • Cloud, on-prem, and air-gapped. Self-managed license is nodes and RAM rather than a per-GB SIEM meter

Why we like it

If the team already speaks Elasticsearch, this is the SIEM that does not force a second query language. Frozen data you can still search is the lake move without leaving the stack. The default distribution stays usable under Elastic License 2.0. Paid Gold, Platinum, and Enterprise features need a subscription.

Limits

Self-hosting a production SIEM on Elasticsearch is an engineering job. Security Onion exists in part because that job is unpleasant. ELv2 is not OSI open source: no offering it as a managed service, no stripping license keys. Cloud is resource-based or usage-based. You still ingest. You still decide what never arrives.

License

Default distribution under Elastic License 2.0. Source is also offered under SSPL and AGPLv3. Cloud and paid features are subscription. Contact sales for a number.

4

Microsoft Sentinel

Best for a cloud-native SIEM on a Microsoft estate

Microsoft Sentinel

Sentinel is the one hyperscaler SIEM on this list. Cloud-native ingest, a built-in data lake, SOAR, UEBA, and Security Copilot inside the Microsoft Defender portal. After March 31, 2027, Microsoft says the Azure portal path goes away and Sentinel lives in Defender only.

Key features

  • Analytics tier and a cheaper data lake tier, pay-as-you-go or commitment
  • Hundreds of connectors. The product page says 400+ in one block and 450+ in the FAQ. We did not pick a number
  • Free ingest on named Microsoft sources: Azure Activity, Office 365 audit, and several Defender alert tables
  • 31-day trial: first 10 GB/day of analytics ingest waived, 20-workspace cap per tenant

Why we like it

If the estate is already Entra, M365, and Defender, the free tables and the Defender console are the actual reason teams leave a legacy SIEM. Commitment tiers start at 100 GB/day. The lake is how they argue you can keep voluminous logs without putting every byte in analytics.

Limits

It is still an ingest SIEM. Non-Microsoft sources land on the Azure bill, plus Logic Apps and anything else you bolt on. The connector count disagreement on their own page is a documentation smell. Sentinel without a Microsoft center of gravity is just another consumption SIEM.

License

Azure consumption. Requires an Azure subscription. Trial and free tables as documented on Microsoft Learn and the pricing page.

5

Panther

Best for detection-as-code on a lake you can own

Panther

Panther calls itself an AI SOC platform and a cloud-native SIEM with detections as code. Python rules in Git. CI/CD. A security data lake. Two deployments: Connected, inside your AWS account against your Snowflake or Databricks, or Hosted, where they ingest into an isolated environment. Their homepage also banners a Databricks acquisition.

Key features

  • Python detections, unit tests, GitHub review. AI builder that emits a rule you can still read
  • Connected mode: detections and agents run against the warehouse. Data stays in your account
  • Hosted mode when you do not want a warehouse mandate
  • Panther Analysis Tool, Sigma conversion, and a managed detection library

Why we like it

This is the lesser-known lake option for teams who already treat detections like software. If the complaint about a legacy SIEM is “the rule lives in a GUI we cannot review,” Panther’s page is the counter. They name Splunk, Sumo Logic, and Elastic as sources customers leave. That is their claim, not a migration we watched.

Limits

No public list price. You book a demo. Connected mode assumes you already run Snowflake or Databricks, or will. Hosted mode is ingest again, just into their lake. The Databricks deal is in progress on their banner. Ask what that does to the product before you sign a multi-year Connected contract.

License

Commercial. Quote and demo. No self-serve rate card on panther.com.

6

Security Onion

Best for a hunt grid with NSM and host telemetry

Security Onion

Security Onion is the free and open platform Doug Burks started in 2008: network visibility, host visibility, honeypots, log management, and cases. Suricata, Zeek, Elastic Agent, osquery, Strelka, OpenCanary, and the Elastic stack, plus their own alert, hunt, PCAP, and case UIs. Latest first-party version on the company site is 3.2.0.

Key features

  • Signature detection and protocol metadata from Suricata and Zeek, plus full PCAP
  • Elastic Agent for host collection, live osquery, Fleet management
  • Distributed grid from a setup wizard. Appliances and Pro if you want the company to carry hardware and extras
  • Onion AI and MCP listed on the current feature set. Local model support is a Pro conversation

Why we like it

This is the grid you stand next to a SPAN port when the cloud SIEM never saw the packet. Security Onion Solutions is the official appliances, training, and services shop. Buying from them funds the project. The software itself stays free to download.

Limits

It is a platform you operate. Sensors want disk and CPU. Elastic components and Security Onion components accept Elastic License 2.0 at install. That is not a GPLv2 tree. Pro and Onion AI are commercial add-ons. It will not replace a SaaS SIEM for a team that refuses to run Linux.

License

Free and open platform. Most bundled tools are open source. Elastic and Security Onion components are ELv2. Pro, appliances, and training are paid through Security Onion Solutions.

What the internet thinks about SIEM alternatives

Live threads. We quoted the argument, not the score.

Hacker News

“I’m in a fortune 100 and we are looking at replacing splunk for sentinel because of cost of splunk. I don’t use either in my day to day and have no horse in the race, but if my company is doing it then the cost of splunk must not be trivial.”

hunter-gatherer, 21 Sep 2023, on the Cisco-Splunk thread. The leave motion is the invoice. We already used the one HN link on the Wazuh note above.

Stack Overflow

“Elastics free and open license allows the usage of detections. Machine Learning is a paid feature but correlations (EQL) and normal detections (query) can be build.”

SHolzhauer on a basic Elastic SIEM. The free tier is detections. ML is the upsell.

Information Security

“A SIEM generally needs to be more than a base ELK deployment. It generally needs more than basic Splunk deployment, too. There’s a reason that folks pay so much for the Enterprise Security add-on for Splunk.”

Matthew Kosmoski on ELK-as-SIEM. The gap is detections, cases, and compliance content. Security Onion exists because a raw stack leaves that gap.

FAQs

Can I replace a legacy SIEM with one of these in a quarter?

Sometimes the console. Rarely the coverage. Parsers, detections, and the sources you never sent are the work. Wazuh and Security Onion make that work yours. Sentinel and Panther sell onboarding. Vega sells skipping the copy. None of the public pages we read promise a quiet 90 days.

Does Vega replace Wazuh or Sentinel?

No. Vega queries data you already hold. Wazuh still needs an agent and a server. Sentinel still needs an Azure workspace and connectors. You can put a mesh on top of a lake or a leftover SIEM. You cannot skip telemetry and call it visibility.

Are Wazuh, Elastic Security, and Security Onion the same stack?

No. Wazuh is its own agent, server, indexer, and dashboard. Elastic Security is SIEM and XDR on Elasticsearch. Security Onion bundles Suricata, Zeek, Elastic Agent, and the Elastic stack with its own hunt and case UIs. Overlap on search. Different jobs on the wire and on the host.

Is this a scored bake-off?

No. Order is editorial. We did not install these in a lab or assign points. A platform is here if it is live, has a public license or price shape, and maps to a job teams name when they leave a legacy SIEM.