Wazuh vs Elastic vs Graylog: Free SIEM Saves 78% [2026]

Splunk bills from $8.21 to $39.98 per GB per day depending on the tier, and a 50 GB/day security team can end up paying $182,000 to $273,000 a year just for ingest licensing. That math is why “open source SIEM” now pulls a solid 590 searches a month, and why three names keep coming up in the same breath: Wazuh, Elastic Security, and Graylog. All three ingest logs, correlate events, and flag threats without a per-GB invoice attached to every server you monitor. But “open source” means three very different things once you look past the marketing page, and picking wrong costs either your budget or your detection coverage.

This comparison breaks down Wazuh 4.14.7, Elastic Security 9.5, and Graylog 7.1.7 as they stand in August 2026: licensing structure, real ingestion benchmarks, deployment requirements, compliance depth, CVE history, and dollar-figure case studies from teams that already made the switch. Every number below is sourced from vendor documentation, GitHub, or published pricing pages current as of this month.

The stakes here are not academic. A SIEM sits at the center of every incident response plan a security team writes, and swapping platforms mid-year is expensive in a way that goes beyond the license line item: detection rules need rebuilding, dashboards need recreating, and analysts need retraining on a new query language. Get the initial choice wrong and you’re paying twice, once for the platform you shouldn’t have picked, and again for the migration off it eighteen months later. That’s why this comparison leans as heavily on documented case studies and published pricing as it does on raw feature lists.

Google · Preferred Sources

Don't miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

The Open Source SIEM Market in 2026: Why Teams Are Ditching Splunk

The global SIEM market sits between $10.67 billion and $12.06 billion in 2026 depending on which analyst firm you trust, and it’s still growing at roughly 11.5% to 14.5% a year. On-premises deployments hold 55.27% of that market against 44.73% for cloud, and large enterprises account for 65.39% of total spend. None of that growth is coming from teams happily paying list price. It’s coming from budget pressure meeting a maturing set of free alternatives.

The 2025 State of Open Source Report from Perforce OpenLogic, the Eclipse Foundation, and OSI found that 96% of organizations increased or maintained their open source usage over the prior year, with 26% reporting a significant increase. For the second year running, the top reason cited wasn’t flexibility or community support. It was cost efficiency, specifically the elimination of license fees. SIEM tooling is one of the more expensive line items in a security budget, which makes it one of the first places that pressure shows up.

Wazuh and Graylog are explicitly called out in industry analysis as gaining ground in “government and cost-sensitive verticals,” though analysts are careful to note their lack of turnkey managed support still limits penetration in complex global environments. That’s the real tradeoff underneath this whole category: you’re not choosing between good and bad tools, you’re choosing between paying with dollars or paying with engineering time.

It’s also worth being precise about what “open source” means for each of these three, because the label gets applied loosely across the market. Wazuh is unrestricted open source under Apache 2.0, full stop, with no feature paywall at any point. Elastic and Graylog are both open-core: a genuinely free foundation exists, but the security-specific capability most SOC teams actually need to justify calling the platform a “SIEM” rather than a log manager sits behind a commercial license. None of that makes Elastic or Graylog bad choices, but budgeting “$0 for our SIEM” against either of them is a planning mistake that shows up in month two.

SIEM vs XDR Convergence: Where Wazuh, Elastic, and Graylog Fit

SIEM and XDR used to be separate purchase decisions. In 2026 they’re converging: modern SIEM platforms have absorbed UEBA and SOAR capability, while XDR platforms have expanded past endpoints into identity, email, and cloud telemetry. All three tools in this comparison now blur that line on purpose. Wazuh markets itself directly as “unified XDR and SIEM.” Elastic Security ships an EDR component (Elastic Defend) alongside its SIEM core. Graylog Security layers MITRE ATT&CK mapping, UEBA, and Sigma rule support on top of what used to be a pure log manager.

If you’re also evaluating dedicated endpoint tools, our EDR vs XDR vs MDR comparison covers the per-endpoint cost gap on the commercial side, and our CrowdStrike vs SentinelOne vs Defender breakdown is worth reading alongside this piece if your team is deciding between a managed detection platform and a self-hosted SIEM. The short version: these three open source platforms compete more directly with each other than with CrowdStrike or Sentinel, because none of them require you to route data through a third party’s cloud unless you choose to.

Wazuh vs Elastic Security vs Graylog: Spec Comparison Table

SpecWazuhElastic SecurityGraylog
Latest version4.14.7 (July 29, 2026)9.5.1 / Security 9.5 (Aug 3, 2026)7.1.7 (Aug 5, 2026)
Core licenseApache 2.0, fully open sourceBasic (free) tier plus paid Gold/Platinum/EnterpriseSSPL “Open” tier plus paid Enterprise/Security
Self-hosted cost$0, no ingestion cap$0 on Basic license$0 on Graylog Open
GitHub stars16,567 (wazuh/wazuh)77,791 (elasticsearch)8,115 (graylog2-server)
GitHub forks2,44126,0441,124
Agent modelNative Wazuh agent (Windows, Linux, macOS, AIX)Elastic Agent via Fleet, plus BeatsSidecar/Forwarder, syslog, GELF
Built-in EDRFIM and HIDS, not a full EDR suiteElastic Defend (native EDR)None natively, relies on ingested sources
AI/automationRule-based SCA and vulnerability detectionAgentic SOC, AI alert triage, Elastic WorkflowsAI-powered automated investigations (new in 7.1)
Compliance mappingSCA policies referencing PCI DSS, HIPAA, GDPR, NISTFIPS 140-3 (GA in 9.4), broad regulatory coverageIlluminate content packs, MITRE ATT&CK mapping
Deployment optionsSelf-managed or Wazuh Cloud (managed)Self-managed, Elastic Cloud Hosted, or serverlessSelf-managed or Graylog Cloud
Entry cloud price$571/month (100 agents)~$99/month (Standard, resource-based)~$1,250/month (Operations, 10 GB/day)
Best fitBudget-constrained teams, endpoint-heavy monitoringHigh-EPS enterprises, security + observability convergenceLean SOC teams wanting AI-assisted triage

Wazuh 4.14.7: The Fully Open Source XDR and SIEM Platform

Wazuh describes itself on GitHub as “the open source security platform, unified XDR and SIEM protection for endpoints and cloud workloads,” and its licensing backs that claim up. Everything, the manager, the indexer, the dashboard, and every agent, ships under Apache 2.0 with no feature gate and no ingestion cap. Wazuh 4.14.7 shipped July 29, 2026, part of a steady monthly cadence that also included 4.14.6 (July 1), 4.14.5 (April 23), 4.14.4 (March 17), 4.14.3 (February 11), and 4.14.2 (January 14). A Wazuh 5.0.0 beta1 has been available since April 15, 2026, and it’s a significant architectural shift: a rewritten agent communication protocol (meaning 4.x agents need upgrading before they reconnect) and a new proprietary indexer replacing the OpenSearch-based backend Wazuh has relied on for years.

The platform’s core strength is endpoint-centric monitoring: File Integrity Monitoring (FIM), Host Intrusion Detection (HIDS), vulnerability detection, and Security Configuration Assessment (SCA) policies that check hosts against benchmarks. The 4.14.2 release added an SCA policy specifically for Microsoft Windows Server 2025, showing the ruleset stays current with new OS releases rather than lagging behind. Integrations extend into cloud territory too, with rules for Azure Log Analytics, Docker, and Microsoft Graph appearing across the 2026 release notes.

Wazuh’s 4.10.4 release (May 21, 2026) is worth flagging on its own: it fixed a path traversal vulnerability in the authd component through agent group name validation, masked the authd.pass field in API responses, and hardened cluster deserialization by restricting callable decoding. None of these were assigned public CVE IDs in Wazuh’s own release notes, which drew some third-party criticism, including a blog post from patchwindow.serverdigital.net describing 4.14.5 as “a security patch they didn’t call a security patch.” If you self-host Wazuh, track release notes closely rather than waiting for a CVE database alert.

Elastic Security 9.5: The Freemium AI-Powered SOC Platform

Elastic runs two parallel version lines in 2026: the long-term 8.19.x branch (currently at 8.19.20) and the newer 9.x line, which reached Elastic Stack 9.5.1 and Elastic Security 9.5 on August 3, 2026. Unlike Wazuh, Elastic’s licensing is genuinely freemium. The Basic tier is free and includes core Elasticsearch, Kibana, and baseline SIEM detection rules, but Elastic gates its more advanced capabilities, machine learning detections, Elastic Workflows automation, and Elastic Defend endpoint protection, behind Standard, Gold, Platinum, and Enterprise subscriptions.

2026 has been an aggressive feature year for Elastic Security. In March, Elastic announced Elastic Workflows, a native automation layer built directly into Elastic Security that the company explicitly pitched as eliminating “the SOAR automation tax,” meaning teams no longer need a separate SOAR product bolted onto their SIEM. By August, Elastic Security 9.5 added AI that “handles first-pass alert triage and investigation, so analysts can get back to threat hunting,” per Elastic’s own product update blog. Elastic also achieved FIPS 140-3 compliance for Elasticsearch and Kibana in the 9.4 release, timed ahead of a September 2026 federal compliance deadline, and the platform now runs as a native embedded security layer inside Google Distributed Cloud air-gapped environments for government, defense, finance, and telecom customers who can’t touch the public internet.

That momentum shows up in analyst coverage too: Elastic was named a Strong Performer in Forrester’s Extended Detection and Response Platforms evaluation for Q2 2026. On the security side, Elastic has also been the most transparent of the three about disclosing CVEs, including CVE-2026-49091 (Kibana improper output neutralization for logs, CVSS 8.0) and CVE-2026-42398 (Kibana SSRF, CVSS 7.7), both patched via the Elastic Security release notes channel, plus CVE-2026-72678, resolved in 8.19.20, 9.4.5, and 9.5.1.

Graylog 7.1.7: The AI SIEM Built for Lean Security Teams

Graylog occupies a middle position, an open-core product built on top of a genuinely free tier called Graylog Open. Graylog 7.1 reached general availability on May 4, 2026, and Graylog explicitly marketed it as “the AI-powered SIEM built for lean security teams,” with two headline capabilities: behavioral detection that “catches what rules miss” and automated investigations that reduce manual triage. The 7.1 branch has iterated fast since GA, hitting 7.1.1 (May 8), 7.1.3 (June 3), 7.1.5 (July 8), and 7.1.7 (August 5), alongside a parallel 7.0.x maintenance line and content-pack updates through Graylog Illuminate.

Graylog Open is genuinely unlimited on ingestion, no artificial data cap, source-available under the SSPL license. But the SIEM-specific capability, MITRE ATT&CK mapping, UEBA, Sigma rule support, and the automated investigation workflow that defines the 7.1 release, lives behind the paid Graylog Security tier, which starts at $18,000 a year at roughly 10 GB/day of ingestion. Graylog Enterprise, a step below Security with correlation and reporting but not the full SIEM content library, starts at $15,000 a year at the same volume tier.

End-of-life tracking on endoflife.date shows Graylog’s support lifecycle is fairly tight: version 6.3 support ended June 30, 2026, and 6.2 support ended April 28, 2026, while the current 7.1 branch has support through May 2027 and 7.0 through November 2026. If you’re running an older 6.x deployment, you’re now outside the patch window and should plan an upgrade regardless of which competitor you’re evaluating against.

Integrations and Ecosystem: Cloud, SOAR, and Third-Party Tool Support

A SIEM is only as useful as the log sources it can actually ingest, and this is one area where the size gap between these three platforms shows up directly in day-to-day usability. Elastic’s ecosystem is the deepest by a wide margin: Fleet-managed Elastic Agent integrations cover cloud providers, identity platforms like Entra ID and Active Directory, CI/CD pipelines (Elastic Security Labs open-sourced a dedicated CI/CD pipeline detector in 2026), and dozens of SaaS applications, all searchable from a single integrations catalog inside Kibana. That breadth is a direct consequence of Elastic’s larger engineering team and its 77,791-star open source community around the core Elasticsearch project.

Wazuh’s integration story is narrower but deliberately focused: strong native coverage for cloud provider APIs (Azure Log Analytics bookmarks appear across the 2026 release notes), container platforms (Docker-specific detection rules), and Microsoft Graph for Microsoft 365 telemetry. What Wazuh doesn’t offer is a broad third-party app marketplace the way Elastic does; you’re more likely to be writing a custom decoder for a niche log source on Wazuh than finding a pre-built integration for it.

Graylog sits in between, built around syslog, GELF, and Beats-compatible ingestion plus its own Sidecar and Forwarder components for distributed log collection. The Graylog Forwarder saw a 7.3 release in 2026 specifically aimed at improving distributed collection for organizations running multiple sites or cloud regions feeding into one central Graylog Security instance. None of the three platforms lock you into their own proprietary shipping agent exclusively; all three accept standard syslog and most accept OpenTelemetry-formatted data, which matters if your organization is already standardizing observability tooling around OTel.

Pricing Breakdown: What Free, Freemium, and Open-Core Actually Cost

“Open source” doesn’t mean “free at scale” for two of these three platforms. Here’s how the published 2026 pricing actually breaks down once you need the security-specific features, alongside Splunk and Microsoft Sentinel for reference.

PlatformSelf-hosted coreManaged/cloud entry priceSIEM-grade tier~50 GB/day estimated annual cost
WazuhFree, no cap$571/mo (Small, 100 agents)Included free; commercial support median $16,234/yr$7,800–$47,256/yr (infra only, self-hosted)
Elastic SecurityFree (Basic license)~$99/mo (Standard, Elastic Cloud Hosted)Serverless ingest from $0.09/GB$240,000–$320,000/yr total TCO (one published SIEM sizing study)
GraylogFree (Graylog Open)~$1,250/mo (Cloud Operations, 10 GB/day)$18,000/yr (Security, 10 GB/day)~$1,100 per GB/day/yr (Cloud Security, G-Cloud rate card at 50 GB/day)
Splunk Cloud (reference)N/AN/A$100–$150/GB/day/yr negotiated; higher at list price$182,000–$273,000/yr
Microsoft Sentinel (reference)N/A$4.30/GB pay-as-you-go (East US)$2.96/GB effective at 100 GB/day commitment~$78,500–$108,000/yr

Two things stand out. First, at moderate scale (50 GB/day) Wazuh’s self-hosted infrastructure cost is roughly an order of magnitude below every other option here, because you’re paying for compute and storage, not a per-GB or per-node license. Second, Elastic’s advertised $0.09 per GB ingest rate looks cheap in isolation, but a dedicated Elastic SIEM sizing analysis pricing a 50 GB/day deployment on Elastic Cloud Platinum with a hot-warm cluster put total cost of ownership, license plus infrastructure plus the engineering time to run it, at $240,000 to $320,000 a year. Cheap per-unit pricing and cheap total cost are not the same thing once cluster tuning enters the picture.

Benchmark Data: Ingestion Performance and Scalability

None of the three vendors publish a standardized events-per-second benchmark the way a database vendor might publish TPC numbers, so the honest answer is that ingestion capacity is a function of your indexer cluster, not the SIEM software layer itself. All three platforms lean on a Lucene-based search backend for their heavy lifting: Elastic runs on Elasticsearch natively, Graylog runs on Elasticsearch or OpenSearch underneath its processing pipeline, and Wazuh has historically run on an OpenSearch-based indexer, though that changes in the Wazuh 5.0 beta, which replaces it with a purpose-built indexer component.

What the 2026 release notes do confirm is a consistent focus on ingestion-adjacent performance work across all three vendors. Elastic’s 2026 blog archive references a rebuilt metrics engine storing telemetry data at “3.75 bytes per data point” with query performance up to 160 times faster than the prior engine, which, while framed around observability metrics rather than raw security log EPS, points to the same underlying Elasticsearch improvements that benefit SIEM ingestion. Wazuh’s 4.14.x branch shows repeated Syscollector optimization work and cluster synchronization performance fixes across releases from January through July 2026. Graylog’s changelog emphasizes processing pipeline and content pack efficiency rather than raw throughput claims.

Practically, this means sizing decisions come down to hardware and cluster architecture more than software choice. A single-node Elasticsearch cluster and a single-node Wazuh indexer will both fall over at similar log volumes; a properly sharded multi-node cluster on either platform scales into hundreds of GB per day. If your evaluation depends heavily on a specific EPS ceiling, the vendors’ own sizing guides (not third-party blog estimates) are the only source specific enough to plan against, and you should pressure-test any number with a proof-of-concept on your actual log mix before committing budget.

Deployment Requirements: RAM, CPU, and Disk for Each Platform

For a lab or small-environment proof of concept, the three platforms land in a similar hardware ballpark, though production sizing diverges quickly once you add multi-node clustering and longer retention.

  • Wazuh: a single-node manager plus indexer for a small lab runs comfortably on 4–8 GB RAM and 2–4 vCPU, with disk sized to retention (typically hundreds of GB for a small environment). Production deployments split the manager, indexer, and dashboard across separate nodes.
  • Elastic Security: a lab-scale Elasticsearch node needs 8–16 GB RAM and 4–8 vCPU, with Kibana running comfortably on 4–8 GB RAM. Production SIEM use almost always means a multi-node cluster with hot/warm/cold tiering for cost control on high-volume indices.
  • Graylog: the Graylog server process itself is light, typically 4–8 GB RAM and a couple of vCPUs, but it still depends on a separate Elasticsearch or OpenSearch cluster sized the same way Elastic’s own deployment would be.

At real SIEM scale, hundreds of GB per day, all three require multi-node clusters with tens of GB of RAM per node and high-throughput SSD storage. None of them is meaningfully lighter than the others at that tier; the cost difference between the three shows up in licensing, not in raw hardware footprint.

Compliance Coverage and Detection Rule Depth

Compliance-driven buyers care about two things: whether the platform can produce the reports an auditor wants, and whether its detection content maps to a recognized framework like MITRE ATT&CK, PCI DSS, HIPAA, or NIST. Wazuh ships Security Configuration Assessment policies that check hosts against specific benchmarks, including a dedicated policy for Windows Server 2025 added in the 4.14.2 release, and its FIM and vulnerability detection modules generate the kind of audit trail PCI DSS and HIPAA assessors expect, though Wazuh’s own release notes reference these capabilities functionally rather than listing every framework explicitly.

Elastic’s compliance story got a concrete boost in 2026 with FIPS 140-3 certification for Elasticsearch and Kibana, timed specifically ahead of a September 2026 federal deadline, which matters if you sell into U.S. government or defense contracts. Combined with the GDC air-gapped deployment option, Elastic Security is positioned as the strongest of the three for regulated, disconnected environments where a managed cloud SIEM isn’t an option.

Graylog leans on its Illuminate content packs to deliver framework-aligned detection content and MITRE ATT&CK mapping, and the Security tier explicitly bundles Sigma rule support, which matters if your team already maintains a Sigma-based detection library and wants portability instead of vendor lock-in. None of the three publish a hard number for “total detection rules shipped,” so if a specific rule count is a hard requirement for your evaluation, request it directly from each vendor rather than trusting a third-party estimate.

Retention policy is the piece of compliance that gets overlooked until an auditor asks for it. PCI DSS typically requires at least a year of retained logs with the most recent three months immediately available for review; HIPAA and most state breach-notification laws push similar multi-year expectations. Wazuh’s retention is bounded only by the disk you allocate to your indexer, so long retention is cheap but requires you to plan storage growth yourself. Elastic’s tiered storage (hot, warm, cold, frozen) is purpose-built for exactly this problem, letting older data move to cheaper storage automatically while staying queryable. Graylog offers similar archiving through its Enterprise and Security tiers, though the mechanics are less granular than Elastic’s tiering model. If your compliance obligation is the deciding factor, ask each vendor for a retention-cost worksheet before you commit rather than estimating from list pricing alone.

Security Track Record: 2026 CVEs and Patch Cadence

Ironically, the platform you deploy to catch threats is itself a target, and 2026 gave each vendor a distinct pattern. Elastic has the most publicly documented CVE trail of the three, which reflects both a larger install base and a genuinely transparent disclosure process through its public security announcements forum. Confirmed 2026 CVEs include CVE-2026-49091 (Kibana log output neutralization, CVSS 8.0), CVE-2026-42398 (Kibana SSRF, CVSS 7.7), and CVE-2026-72678, patched across the 8.19.20, 9.4.5, and 9.5.1 releases. Elastic’s cadence has been fast: most disclosed issues were patched within the same release cycle they were reported.

Wazuh’s release notes describe several security-relevant fixes without attaching public CVE identifiers, most notably the May 21, 2026 release (4.10.4), which patched a path traversal vulnerability in the authd component, masked a previously exposed credential field in API responses, and hardened cluster deserialization against unsafe callable decoding. That pattern, real fixes without CVE tracking, is a legitimate operational concern: teams that rely on CVE feed monitoring for patch prioritization will miss these unless they subscribe directly to Wazuh’s release notes.

Graylog’s 2026 changelogs are notably quieter on the security front, focused instead on feature and bug-fix content, though its end-of-life tracking is a security consideration in its own right: versions 6.2 and 6.3 are already past their support window as of mid-2026, meaning any organization still on those branches is running unpatched software by definition, independent of whether a specific CVE has been published against them.

The practical lesson across all three: patch cadence discipline matters more than any single CVE count. Elastic’s transparent disclosure process makes it easy to track exposure through standard vulnerability feeds, but it also means more advisories land in your inbox. Wazuh requires manually watching release notes since fixes don’t always carry a CVE tag. Graylog requires watching the end-of-life calendar as closely as the changelog, since falling off a support window is functionally the same risk as an unpatched CVE. Whichever platform you run, build patch tracking into your operational process on day one rather than treating it as a quarterly cleanup task.

Real-World Case Studies: Cost Savings from Splunk Migrations

Published migration numbers are where this comparison gets concrete. Here are five documented scenarios from 2025–2026 sources.

  • European managed security provider, Splunk to Wazuh: a documented case shows Splunk Enterprise licensing plus support at €69,000 a year, replaced by a Wazuh managed service at €15,000 a year with a one-off €22,000 migration cost, netting a 78% cost reduction and €54,000 in annual savings after the first year.
  • Multinational telecom, Splunk to Elastic: per Elastic’s own published migration case material, the company achieved 30–50% lower licensing cost and described the savings as “millions of dollars a year” after moving logging workloads off Splunk.
  • American financial services firm, Splunk to Elastic: the same Elastic case study documentation reports a 49% cost reduction per node and $11 million to $27 million in annual benefit following migration.
  • Small business, 50 endpoints, Splunk to Wazuh: a comparative cost analysis estimates Splunk Enterprise Security over three years at $150,000 to $450,000 for that endpoint count, against $3,600 to $10,800 for self-hosted Wazuh infrastructure over the same period, an order-of-magnitude gap.
  • Mid-market org at 20 GB/day, Splunk to Graylog: a published pricing comparison puts Graylog Enterprise plus infrastructure at roughly $25,000 a year against $33,000 to $40,000 a year for equivalent Splunk licensing, a 50–60% reduction.

The pattern across all five: savings scale with how much of the cost was previously per-GB licensing versus fixed infrastructure. Teams with high, steady log volume see the biggest percentage gains from switching off consumption-based pricing entirely.

Best Use Cases: Which SIEM Fits Your Security Team

Specs and pricing tables only get you so far. Here’s how the recommendation shifts based on team size, budget, and what you’re actually trying to protect.

  • Startup or lean security team, 1–3 analysts, sub-$50K budget: Wazuh self-hosted or Wazuh Cloud Small ($571/month). Zero license cost, endpoint-focused detection covers most early-stage compliance asks.
  • Compliance-heavy mid-market org (PCI DSS, HIPAA): Graylog Security or an Elastic Security paid tier. Both bundle framework-aligned content packs and audit-ready reporting that a pure self-hosted Wazuh deployment requires more manual work to replicate.
  • Enterprise already running the Elastic Stack for observability: Elastic Security. Converging logs, metrics, traces, and security detections into one platform avoids maintaining a separate ingestion pipeline just for SIEM.
  • Government, defense, or air-gapped environment: Elastic Security for its FIPS 140-3 certification and native GDC air-gapped support, or self-hosted Wazuh if a fully disconnected, zero-vendor-dependency deployment is a hard requirement.
  • MSP or MSSP managing many client environments: Wazuh’s flat per-agent pricing avoids the per-GB surprise bills that make multi-tenant cost forecasting difficult with consumption-based platforms.
  • Large enterprise SOC ingesting 500 GB/day or more: Elastic Security, given Elasticsearch’s proven track record at that scale and the option to negotiate enterprise cloud pricing directly.
  • Small IT team wanting AI-assisted triage without a big engineering hire: Graylog 7.1’s automated investigations feature is purpose-built for exactly this gap, reducing manual alert triage without requiring a dedicated detection engineering function.

Migration Guide: Moving from Splunk or Sentinel to Open Source SIEM

Every migration case study above followed roughly the same sequence, and skipping steps is where teams lose detection coverage during the switch.

  1. Audit your current log sources and daily EPS/GB volume. You cannot size a new indexer cluster without knowing what you’re actually ingesting today, not what your Splunk contract says you’re licensed for.
  2. Inventory your detection rules and map them to Sigma format where possible. Sigma is the closest thing this space has to a portable rule format, and both Elastic and Graylog support Sigma-based detections, which cuts rewrite time significantly.
  3. Stand up the new platform in parallel, not as a replacement. Run Wazuh, Elastic, or Graylog alongside Splunk or Sentinel for a minimum 30–60 day overlap window so you can validate detection parity before cutting over.
  4. Roll out agents or forwarders in waves, not all at once. Start with a low-risk environment (staging, internal tools) before touching production-critical log sources.
  5. Rebuild compliance reporting before you need it for an audit. Don’t discover a missing PCI DSS report template the week before an assessor arrives; validate reporting output during the parallel-run window.
  6. Set a hard retention cutover date and stick to it. Keep old platform data queryable read-only for your compliance-mandated retention period rather than paying for active dual-ingestion indefinitely.
  7. Decommission the old license only after a full audit cycle has run clean on the new platform. This is where the German MSP case study’s €22,000 migration cost went: overlap infrastructure and validation time, not tooling.
# Example: installing a Wazuh agent on a Linux host during migration
curl -sO https://packages.wazuh.com/4.x/yum/wazuh-agent-4.14.7-1.x86_64.rpm
sudo WAZUH_MANAGER='your-manager-ip' rpm -ihv wazuh-agent-4.14.7-1.x86_64.rpm
sudo systemctl daemon-reload
sudo systemctl enable wazuh-agent
sudo systemctl start wazuh-agent

Pros and Cons: Wazuh vs Elastic vs Graylog

Wazuh pros: zero license cost at any scale, strong endpoint-centric detection (FIM, HIDS, vulnerability scanning), fast release cadence, no vendor lock-in. Wazuh cons: security fixes often ship without public CVE IDs, weaker native compliance reporting out of the box, the 5.0 beta migration path requires re-establishing agent connections, smaller community than Elastic.

Elastic Security pros: largest ecosystem and GitHub community by a wide margin, best-in-class scalability, native AI-driven triage and Elastic Workflows automation, FIPS 140-3 certified, converges security with observability data. Elastic Security cons: real SIEM-grade capability requires paid tiers, total cost of ownership at scale can exceed $200K/year once infrastructure and engineering time are counted, most publicly documented CVE trail of the three (a byproduct of transparency, but still a patching burden).

Graylog pros: genuinely unlimited free ingestion on the Open tier, new AI-powered automated investigations in 7.1, Sigma rule support for portability, simpler operational learning curve than Elastic. Graylog cons: the SIEM-specific features that most buyers actually want (MITRE mapping, UEBA, automated investigations) sit behind a $18,000/year minimum, smallest GitHub community of the three, tighter version support windows that require more frequent upgrades.

The Verdict: Which Open Source SIEM Wins in 2026

There isn’t a single winner, but the data points to a clear decision tree. If your primary constraint is budget and your environment is endpoint-heavy, Wazuh is the strongest choice: it’s the only one of the three that’s completely free at any ingestion volume, and the documented case studies show 52% to 78% total cost reductions against Splunk at real-world scale. If you’re already running Elastic for logs, metrics, or observability, or you need FIPS 140-3 certification and air-gapped deployment for a regulated environment, Elastic Security is worth the paid tier, its scalability and AI-driven triage are the most mature of the three, even if the total cost of ownership at 50 GB/day can climb into six figures.

Graylog earns its spot for teams in between: organizations that have outgrown a pure log manager but don’t have the engineering headcount to run and tune an Elastic cluster. Its $18,000/year Security tier is real money, but it’s still 50% to 60% cheaper than equivalent Splunk licensing at comparable volume, and the 7.1 automated investigation feature genuinely reduces the manual triage burden on a small team.

Our recommendation for most teams evaluating this category in 2026: start with Wazuh in a proof-of-concept if cost is the dominant factor, evaluate Elastic Security if you already have Elasticsearch skills in-house or need certified compliance for a regulated sector, and consider Graylog if you want AI-assisted detection without committing engineering resources to run and scale a full Elastic deployment yourself.

Frequently Asked Questions

Is Wazuh really free, or are there hidden costs?
The software itself, manager, indexer, dashboard, and every agent, is free under Apache 2.0 with no ingestion cap. The only real cost is infrastructure (compute, storage) and the engineering time to run and tune it, or a Wazuh Cloud managed plan starting at $571/month if you’d rather not self-host.

Which platform is best for PCI DSS or HIPAA compliance?
Elastic Security and Graylog Security both ship framework-aligned content packs and stronger out-of-box reporting. Wazuh can meet the same requirements through its SCA policies and FIM/vulnerability modules, but expect more manual report-building work.

Can I migrate from Splunk to Wazuh without losing detection coverage?
Yes, if you run a parallel deployment for 30–60 days and map your existing detection rules to Sigma format before cutover, as documented in migration case studies referenced above. Skipping the parallel-run period is the most common cause of coverage gaps.

Does Elastic Security require deep Elasticsearch experience to run?
At small scale, no, Elastic Cloud Hosted abstracts most cluster management. At SIEM-grade volume (50+ GB/day), yes, the published total cost of ownership studies specifically call out engineering effort as a major cost component alongside licensing.

Is Graylog a true SIEM or just a log management tool?
Graylog Open is closer to a log manager. Graylog Security, the paid tier starting at $18,000/year, adds the MITRE ATT&CK mapping, UEBA, and automated investigation features that make it a legitimate SIEM competitor to Elastic and Wazuh.

Which platform handles the highest daily log volume?
All three ultimately depend on Elasticsearch or OpenSearch-based indexing underneath, so raw capacity is a function of cluster sizing rather than software choice. Elastic has the most documented enterprise deployments at very high volume (hundreds of GB to TB/day).

Do these tools replace a dedicated EDR or XDR platform entirely?
Partially. Elastic Security includes native EDR via Elastic Defend. Wazuh covers FIM and HIDS but isn’t a full EDR replacement. Graylog has no native endpoint agent and relies entirely on ingested telemetry. See our EDR vs XDR vs MDR comparison for how these compare against dedicated commercial endpoint platforms.

What happened to Wazuh 5.0?
Wazuh 5.0.0-beta1 has been available since April 15, 2026, but remains in beta as of this writing. It introduces a rewritten agent communication protocol and a new proprietary indexer replacing the OpenSearch backend. Teams should wait for general availability before planning a production upgrade.

Can I run more than one of these platforms at the same time?
Yes, and some teams do deliberately: using Wazuh for endpoint FIM and vulnerability scanning while forwarding aggregated alerts into Elastic or Graylog for correlation and long-term retention. This adds operational overhead but can combine Wazuh’s free endpoint depth with Elastic’s or Graylog’s stronger correlation and reporting layer.

How often should I expect to patch each platform?
Wazuh has shipped a new 4.14.x point release roughly every four to six weeks through 2026. Elastic ships security updates on a similar cadence, often multiple times a month across its Kibana and Elasticsearch components. Graylog’s 7.1.x branch has released a new point version almost monthly since its May 2026 GA. Budget for regular patch windows regardless of which platform you choose.

Related Coverage

Nadia Dubois

Nadia Dubois

AI & Innovation Editor

Nadia Dubois is the AI & Innovation Editor at Tech Insider, where she tracks the rapid evolution of artificial intelligence, from foundation models to real-world enterprise deployment. She previously covered AI and startups for La Tribune and contributed to MIT Technology Review's European coverage. Nadia specializes in generative AI, AI regulation, and the intersection of technology and European industrial policy. She holds a dual degree in Computational Linguistics and Journalism from Sciences Po Paris.

View all articles