7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

4 alternatives ranked by real activity

Open-source Microsoft Sentinel alternatives

A curated, ranked list of the 4 best open-source alternatives to Microsoft Sentinel.

The best open-source alternative to Microsoft Sentinel is Wazuh. If that doesn't suit you, other good options are Graylog, Security Onion and Tracecat.

Microsoft Sentinel alternatives are mainly security tools, but some are also monitoring & observability tools. 4 of them shipped code in the last 30 days, 4 can be self-hosted, and none uses a permissive licence.

Last updated October 3, 2026 · ranked by GitHub stars, growth and recent commits

Wazuh

Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads.

GitHub stars
17k
Last commit
today
Latest release
v4.14.8
Self-hosted
Yes
wazuh.comWazuh homepage screenshot

Wazuh is a free and open-source platform for threat prevention, detection and response. It protects workloads across on-premises, virtualized, containerized and cloud environments and combines XDR and SIEM functions in one product. The code is written mainly in C++.

The solution consists of an endpoint security agent installed on monitored systems and a management server that collects and analyzes the agents' data. It is integrated with the Wazuh Indexer, which offers a search engine and visualization for navigating security alerts. Agents scan for malware, rootkits and suspicious anomalies, read system and application logs, and monitor files for changes to content, permissions, ownership and attributes.

Rule-based analysis of collected logs, including data received from network devices through syslog, helps surface misconfigurations, policy violations and attempted or successful attacks. Repository topics also cover vulnerability detection, configuration assessment, incident response and compliance such as PCI DSS. The repository lists its license as 'Other', so review the license files for the exact terms.

Key features

  • Endpoint agents with a central management server
  • Intrusion and malware detection
  • Log data analysis with rule-based alerts
  • File integrity monitoring
  • Vulnerability detection and configuration assessment
  • Cloud and container workload coverage
Read more about WazuhWebsite GitHub

Graylog

Graylog is a free, open log management platform written in Java that collects, searches and analyzes logs, with a focus on security use cases.

GitHub stars
8.2k
Last commit
today
Self-hosted
Yes
graylog.orgGraylog homepage screenshot

Graylog is a log management server written in Java and described by its maintainers as free and open. It centralizes log data from many systems so teams can search, view and analyze events in one place instead of connecting to each machine individually.

The repository topics point to support for common log formats and transports, including GELF and syslog, along with Kafka and AMQP inputs. Topics also place the project in log analysis, log collection, secure logging and SIEM territory, which reflects its use for monitoring and security work. Specific features were not available when this entry was written, because the vendor website could not be read.

Key features

  • Centralized log collection and search
  • GELF and syslog input formats
  • Kafka and AMQP integration
  • Log analysis and viewing
  • Security-oriented logging
Read more about GraylogWebsite GitHub

Security Onion

Security Onion is a free Linux platform for threat hunting, network and host security monitoring and log management, with a unified web console.

GitHub stars
4.9k
Last commit
today
Latest release
3.3.0-20260911
Self-hosted
Yes
securityonion.netSecurity Onion homepage screenshot

Security Onion is a no-cost, open Linux distribution built for threat hunting, security monitoring across an enterprise, and log management. It bundles a suite of tools designed to work together so defenders get visibility into both network and host activity from a single platform.

The Security Onion Console is a unified web interface for analyzing events and managing the deployment, with its own tools for alerting, dashboards, hunting, packet capture, detections and case management. Underneath it uses the Elastic Stack for search, Suricata for network intrusion detection, Elastic Fleet for host monitoring, Zeek for network metadata and other tools such as osquery and CyberChef. The installer and configuration are largely shell scripts.

The repository license appears as 'Other' on GitHub. Security Onion is deployed on your own hardware or virtual machines, either standalone or as a distributed grid. It suits security operations centers, incident responders and blue teams that want an integrated, open alternative to commercial monitoring platforms.

Key features

  • Unified Security Onion Console web interface
  • Network intrusion detection with Suricata
  • Network metadata from Zeek
  • Elastic Stack search and dashboards
  • Case management and threat hunting
  • Packet capture and detections
Read more about Security OnionWebsite GitHub

Tracecat

Tracecat is a security automation platform, open source, in which security teams and AI agents build workflows, handle cases and automate incident response.

GitHub stars
3.8k
Last commit
today
Latest release
1.0.1
Licence
AGPL-3.0
Self-hosted
Yes
Hosted version
Available
tracecat.comTracecat homepage screenshot

Tracecat is open-source software for automating security operations, used by teams and AI agents together. It aims to give security teams everything they need to build agents and automate cyber defense in one place, from alert handling to incident response, with unlimited agents, cases, lookup tables and workflows.

Its building blocks include agents and skills built from prompts, tools and MCP, case management for tracking and resolving incidents with agent help, workflows that execute deterministic logic with resilience on Temporal, tables for storing and querying structured data, and a Tracecat MCP that turns prompts into automations from Claude Code, Codex and similar tools. The stack is Python with FastAPI and a Next.js interface.

Tracecat is licensed under AGPL-3.0 and can be self-hosted, with a managed cloud also offered by the vendor. It suits security operations, detection engineering and incident response teams that want a programmable, AI-ready alternative to proprietary SOAR tools.

Key features

  • AI agents with prompts, tools and MCP
  • Case management for incidents
  • Workflows running on Temporal
  • Tables for structured data lookups
  • Tracecat MCP for prompt-driven automation
  • Unlimited agents, cases and workflows

Pricing: The open-source edition is free to self-host with no execution limits. Enterprise is priced by quote and scales with usage, deployment model and support needs.

Read more about TracecatWebsite GitHub

Microsoft Sentinel alternatives: questions

What is the best open-source alternative to Microsoft Sentinel?
Wazuh is the top-ranked open-source alternative to Microsoft Sentinel on Enlisted: Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads. Other strong options are Graylog, Security Onion and Tracecat.
Are these Microsoft Sentinel alternatives free?
All 4 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 1 also offers a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Microsoft Sentinel alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 4 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all