alternatives to

Splunk

Platform for indexing, searching and alerting on machine data such as logs, sold as software or a cloud service. A closed product from Cisco.

Side by side

10 alternatives to Splunk
ToolFitStarsLicenceTermsSelf-hostedLanguageLatestLast push
GraylogFull replacement8.2kOtherSource availableYesJava7.1.92026-10-06
GrafanaPartial77kAGPL-3.0Open sourceYesTypeScriptv13.2.32026-10-06
LokiPartial29kAGPL-3.0Open sourceYesGov3.7.82026-10-06
OpenObservePartial22kAGPL-3.0Open sourceYesTypeScriptv1.1.0-rc12026-10-06
WazuhPartial17kOtherOpen sourceYesC++v4.14.82026-10-06
OpenSearchPartial14kApache-2.0Open sourceYesJava3.9.02026-10-06
QuickwitPartial12kApache-2.0Open sourceYesRustv0.9.12026-10-06
Security OnionPartial4.9kOtherSource availableYesShell3.3.0-202609112026-10-06
ParseablePartial2.5kAGPL-3.0Open sourceYesRustv3.2.42026-10-06
VictoriaLogsPartial2.3kApache-2.0Open sourceYesGov1.53.02026-10-06

Every alternative

Language
Licence
Fit
Terms
Deploy with

10 alternatives

GraylogFull replacement

Free and open log management

Log collection, search, dashboards and alerts, with its own query syntax instead of SPL.

Language
Java
Licence
Other
Stars
8.2k
Latest
7.1.9
Last push
2026-10-06
GrafanaPartial

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

Dashboards and alerts over logs stored in Loki or other backends.

Language
TypeScript
Licence
AGPL-3.0
Stars
77k
Latest
v13.2.3
Last push
2026-10-06
LokiPartial

Like Prometheus, but for logs.

Log storage and querying, without Splunk's apps and SIEM features.

Language
Go
Licence
AGPL-3.0
Stars
29k
Latest
v3.7.8
Last push
2026-10-06
OpenObservePartial

Open source observability platform for logs, metrics, traces, RUM (web, android, ios), Session replay, pipelines, SLO and LLM observability. A sophisticated, simple and highly performant alternative to Datadog, Splunk, and Elasticsearch with 140x lower storage costs and single binary deployment.

Log search, dashboards and alerts.

Language
TypeScript
Licence
AGPL-3.0
Stars
22k
Last push
2026-10-06
WazuhPartial

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Security events, file integrity and compliance checks from its own agents; not a general log search platform.

Language
C++
Licence
Other
Stars
17k
Latest
v4.14.8
Last push
2026-10-06
OpenSearchPartial

🔎 Open source distributed and RESTful search engine.

Log search and analytics with OpenSearch Dashboards.

Language
Java
Licence
Apache-2.0
Stars
14k
Latest
3.9.0
Last push
2026-10-06
Security OnionPartial

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.

Network and host security monitoring with alerting, hunting and case management, not general log analytics.

Language
Shell
Licence
Other
Stars
4.9k
Last push
2026-10-06
ParseablePartial

Parseable is an open source, unified infrastructure observability platform built in Rust on a data lake architecture. It tracks logs, metrics, traces, and events across apps, agents, and systems, reducing storage costs by up to 90% through columnar telemetry compression.

Log ingestion, SQL search and alerts on object storage, without Splunk's apps and SPL.

Language
Rust
Licence
AGPL-3.0
Stars
2.5k
Latest
v3.2.4
Last push
2026-10-06
VictoriaLogsPartial

Fast and easy to use database for logs, which can efficiently handle terabytes of logs

Log storage and querying only.

Language
Go
Licence
Apache-2.0
Stars
2.3k
Latest
v1.53.0
Last push
2026-10-06

Head to head

About Splunk

Vendor
Cisco

Splunk website ↗