Log management and SIEM/Splunk alternatives/2026

The best Splunk alternatives, compared honestly

Splunk is still the deepest search and detection engine in the category, and Gartner named it a SIEM Leader for the eleventh consecutive time in 2025, placing it highest in Ability to Execute. What sends teams looking is not the product, it is the commercial surface: Splunk publishes no list price for its platform at all, and even the AWS Marketplace listing for Splunk Cloud says only that you should request a private offer. This page compares eight alternatives on the axis that decides these migrations: how each one bills, whether you can look the price up without a sales call, and what its free tier actually allows.

Quick answer

The best Splunk alternative depends on which half of Splunk you are replacing:

  • Both logs and SIEM in one stack → Elastic: Elasticsearch, Kibana and Elastic Security under one roof, AGPL-3.0 for self-hosting, and published serverless rates of $0.09 to $0.11 per GB ingested.
  • Security detection on a Microsoft estate → Microsoft Sentinel: a 2025 Gartner SIEM Leader with a real public rate card, roughly $4.30 per GB pay-as-you-go falling to about $2.31 at a 5,000 GB per day commitment.
  • Just logs, with a published price and an exit path → Grafana Loki: free for 50 GB a month, then a $19 platform fee plus $0.40 per GB to write, and the same AGPL-3.0 stack runs on your own hardware.
  • Zero licence budget → Graylog Open for logs, with no ingest cap and no per-user fees, or Wazuh for security, GPLv2 with unlimited agents.

8 platforms reviewed · billing model, published pricing and free-tier limits · last updated August 2026

Why teams look elsewhere

What pushes teams off Splunk

Splunk did not get worse at searching data; it is still the reference implementation for detection engineering and threat hunting. Every pattern below is about commercial plumbing and licensing, and each one is taken from Splunk's own pricing page, its own administration manual, Cisco's newsroom or the AWS Marketplace listing.

🏷️

There is no published price

Splunk's pricing page names three models, Workload Pricing, Ingest Pricing and Entity Pricing, and contains no dollar amounts. Every route ends in a form. The AWS Marketplace listing for Splunk Cloud is just as blunt: pricing depends on your requirements and eligibility, and you request a private offer.

🧪

Splunk Free is a lab licence, not a small tier

It indexes 500 MB per day and never expires, but the admin manual lists what is missing: no login, so no users and no roles; alerting is not available; distributed search, search head clustering and indexer clustering are not available; TCP and HTTP forwarding are not available. Three licence warnings in 30 days stop search.

🧮

Two meters, one irreversible decision

Ingest pricing bills the GB per day you bring in, so cost tracks volume and the workaround is to stop collecting data. Workload pricing bills the compute your searches, alerts and dashboards consume, so cost tracks curiosity and the workaround is to search less. Both discourage exactly the behaviour you bought the tool for.

🔒

SPL does not travel

Dashboards, saved searches, correlation searches and risk rules are all written in Splunk's own query language, and nothing converts them to KQL, LogQL, ES|QL or SQL. The real migration cost is rewriting a decade of content rather than moving data, and it grows every quarter you postpone the decision.

🏢

The buying motion moved to Cisco

Cisco closed its acquisition of Splunk on 18 March 2024 at $157 per share, about $28 billion, the largest deal in its history. Renewals increasingly run through Cisco paper, and AppDynamics has been folded in: the AppDynamics Cloud SKU is end of life, with customers moved to Cisco Observability Platform at contract end.

🗓️

A support treadmill under the platform

Splunk supports several concurrent Enterprise lines, currently 10.4, 10.2, 10.0, 9.4 and 9.3. The 9.x line reaches end of support in December 2026, so anyone still on it is planning an upgrade project now; 10.4 carries support through May 2028. For self-managed clusters that is real engineering time on top of the licence.

The shortlist

8 Splunk alternatives worth evaluating

"Splunk alternative" means two separable things, and conflating them is why most shortlists are useless. One lane is log management: get everything into one searchable place and answer questions fast. The other is SIEM: correlation rules, prebuilt detections, case management and compliance reporting. Because the trigger here is commercial rather than a missing feature, this ranking optimises for a price you can look up, a free tier you can actually run, and a licence that lets you leave. Each pick lists one honest strength and one real weakness.

Elastic#1
Best overall: covers both lanes, and publishes per-GB rates

The only pick that credibly replaces both halves of Splunk in one stack: Elasticsearch and Kibana for ad-hoc log search, Elastic Security for detections, running self-managed or as a service. Elasticsearch and Kibana added AGPL-3.0 as a licence option on 29 August 2024, so the self-hosted path is OSI open source again, and client libraries stay Apache-2.0. Serverless security pricing is public and effective from 1 November 2025: Security Analytics Essentials from $0.09/GB ingested and $0.017 per GB month retained, Complete at $0.11/GB and $0.019, with 50 GB of egress free then $0.05/GB. Weakness: three licences coexist (AGPL-3.0, SSPL and Elastic License 2.0), the main pricing page publishes no figures of its own, and operating Elasticsearch at Splunk volumes means owning shard layout and index lifecycle tuning.

Microsoft Sentinel#2
Best SIEM replacement on a Microsoft estate

A 2025 Gartner Magic Quadrant SIEM Leader, and the alternative most likely to already have connectors for your identity provider, endpoints and mail, because they are all Microsoft. Rates are genuinely public on the Azure price list: roughly $4.30/GB pay-as-you-go, about $2.96/GB at a 100 GB per day commitment, about $2.31/GB at 5,000 GB per day and up to 52% off pay-as-you-go at the top tier, with a data lake tier near $0.50/GB for high-volume low-value logs. Commitment tiers can be raised any time and lowered after 31 days, and a promotional 50 GB tier is open to sign-ups until 31 December 2026 with the promotional price held to 31 March 2027. Microsoft also gives up to 5 MB per user per day of free ingestion for key security logs. Weakness: it is Azure-shaped, KQL is exactly as non-portable as SPL, rates vary by region, and workspace design rather than product choice decides your invoice.

Grafana Loki#3
Best open-source log stack with a real price page

If the Splunk workload is logs rather than security, this is the cheapest credible landing spot with published numbers. Grafana Cloud is free for 50 GB of logs a month with 14-day retention; Pro is a $19 monthly platform fee with 50 GB included, then $0.050/GB to process, $0.400/GB to write and $0.100/GB to retain on 30-day retention with 8 by 5 email support. Loki itself is AGPL-3.0, so the same queries and dashboards run on your own hardware for the cost of the disks. Weakness: Loki indexes labels rather than full text, so wide-open exploratory search across unindexed fields feels different and often slower than SPL, high-cardinality labels are the classic footgun, and it is not a SIEM. Enterprise also sits behind a $25,000 annual spend commitment.

Graylog#4
Most Splunk-shaped tool with a usable free self-host

The closest thing to the Splunk workflow you can run for nothing: streams, pipelines, dashboards and, unlike Splunk Free, threshold and event-based alerts plus full API access in the free edition. Graylog's own feature page is explicit that Open has no per-user fees, no ingestion caps and no time-limited trial. A separate Graylog Security edition covers the SIEM lane when you need it. Weakness: Graylog Open is Server Side Public License v1, which the Open Source Initiative does not approve, so it is source-available rather than open source; and the things a SIEM buyer actually wants are in the paid editions, namely correlation rules, behavioural analytics, prebuilt detection content, data lake, archive restore, compliance packs and audit reporting.

OpenSearch#5
Best fully permissive licence with no vendor above it

Apache-2.0 throughout, and since 16 September 2024 the project is owned by the OpenSearch Software Foundation under the Linux Foundation rather than by Amazon, so no single vendor controls the roadmap. The 3.x line ships independently, the foundation counts more than 400 member organisations, and the Security Analytics plugin brings detection rules into the same cluster you already run for logs. It is also the engine underneath several other tools on this list, which makes the skills transferable. Weakness: it is a search engine, not a finished product. You own the cluster, the index lifecycle policies, the dashboards and most of the detection content, and nobody is on call for it but you.

Wazuh#6
Best free SIEM when the workload is security

If what you run on Splunk is really a SOC and the budget is zero, this is the honest answer rather than a compromise. The core is GPLv2, the bundled indexer and dashboard are OpenSearch-derived under Apache-2.0, and you can run the manager, indexer, dashboard and unlimited agents with no licence fee and no cap on agents, users or logs. It covers the standard SIEM loop, including correlation rules, real-time alerting, threat-intelligence integration and compliance reporting, and adds endpoint work Splunk charges separately for: file integrity monitoring, vulnerability detection and active response. Weakness: you are the scale-out team, the analyst tooling is plainer than a commercial SIEM console, and enterprise support is a paid relationship rather than a licence entitlement.

Sumo Logic#7
Lowest-friction managed migration, with the meter inverted

The nearest like-for-like if you want to stay on a managed log-analytics platform and change as little else as possible. Its Flex model inverts Splunk's incentive: ingest and indexing are free, and credits are consumed by what you search and store, across Continuous, Frequent and Infrequent tiers, with Infrequent scanning at roughly 0.016 credits per GB. Credit rates are published, from about $0.15 per credit on Essentials to $0.25 per credit on Enterprise Suite for US annual terms. That makes "collect everything, decide later" affordable in a way ingest pricing never is. Weakness: credits are a second currency you have to model, regional and quarterly-payment uplifts apply, and a scan-metered platform punishes long exploratory hunts, which is the exact opposite failure mode to Splunk's.

VictoriaLogs#8
Leanest self-hosted log store

For teams whose actual requirement is fast search over a lot of logs and nothing else. Apache-2.0, production-ready from v1.0.0, available as single-node or cluster, and it runs as a zero-config single binary rather than a cluster you tune. Instead of an inverted index it builds bloom filters over tokenised fields, which is why it fits on smaller hardware than a comparable Elasticsearch or Loki deployment. Weakness: no SIEM, no detection content, no case management, and a much smaller ecosystem of integrations and community knowledge than Elastic or Grafana. Its efficiency comparisons are also the vendor's own benchmarks, so treat them as a starting hypothesis and test on your data.

Deliberately left out: Google SecOps, CrowdStrike Falcon Next-Gen SIEM, Exabeam, Devo and Panther are all credible enterprise SIEMs, but every one of them is quote-only, so they fail the same test this page holds Splunk to. Datadog and New Relic answer the observability question rather than the log-management and SIEM question, and carry billing complaints of their own. Quickwit was acquired by Datadog in January 2025 and its independent future is unclear, so it is not a safe recommendation in 2026.

Side by side

Splunk alternatives compared

Prices as of August 2026, from each vendor's own pricing page. The column that decides most of these migrations is "Public list price", because the trigger is not a missing capability: it is that you cannot budget for Splunk Platform without opening a sales cycle, while several of the alternatives let you model the whole bill in a spreadsheet on a Tuesday afternoon. Splunk's own row is included as the baseline.

ToolTypeBills byPublic list priceFree tierSelf-host / licenceBest for
Splunk Log platform plus SIEM Ingest GB/day or workload compute quote only, even on AWS Marketplace 500 MB/day, no login, no alerting proprietary, Free licence crippled Deep detection engineering on Cisco paper
Elastic Search engine plus SIEM GB ingested and GB retained $0.09–$0.11/GB serverless security Self-managed basic tier, cloud trial AGPL-3.0, SSPL or ELv2 Replacing both halves of Splunk at once
Microsoft Sentinel Cloud-native SIEM GB analysed, plus cheaper lake tier ~$4.30/GB list, ~$2.31 at 5,000 GB/day 5 MB/user/day of key security logs Azure only SOCs already living in Microsoft 365
Grafana Loki Log store plus dashboards GB processed, written and retained $19/mo plus $0.40/GB written 50 GB logs/mo, 14-day retention AGPL-3.0 Log-only teams that want an exit path
Graylog Log management, optional SIEM Free self-host; paid tiers quoted Partial: Open is free, editions quoted No ingest cap, no user fees, alerting included SSPL v1, source-available Splunk-like workflow at zero licence cost
OpenSearch Search engine, DIY logging Your own infrastructure only Not applicable: free software Everything, no limits Apache-2.0, Linux Foundation Teams that need a permissive licence
Wazuh Open-source SIEM and XDR Your own infrastructure only Not applicable: free software Unlimited agents, users and logs GPLv2, indexer Apache-2.0 Security workloads with no licence budget
Sumo Logic Managed log analytics Search and storage credits, ingest free $0.15–$0.25 per credit published Trial only SaaS only Staying managed while ingesting everything
VictoriaLogs Single-binary log store Your own infrastructure only Not applicable: free software Everything, no limits Apache-2.0 Fast log search on modest hardware

Numbers that do not fit in cells: Splunk Observability Cloud is the one Splunk product with a public price list, starting at $15 per host per month for infrastructure monitoring, $55 for APM, $75 for the End-to-End tier and $75 per database instance, with RUM at $14 per 10,000 sessions. Sentinel rates are Azure list prices and vary by region. Elastic's serverless prices took effect on 1 November 2025. Pricing and free tiers change often; check each vendor for current terms. Compiled August 2026.

Official pages: Splunk · Elastic · Microsoft Sentinel · Grafana · Graylog · OpenSearch · Wazuh · Sumo Logic · VictoriaLogs

A fair call

When Splunk is still the right choice

Migrating off Splunk is rarely a data-movement project. The cost is rewriting SPL: saved searches, dashboards, correlation searches, risk rules and the Splunkbase add-ons that parse your long-tail enterprise sources. Budget a dual-run overlap of at least one full detection cycle, and read the case for staying before you commit.

Splunk is still right if…

  • Your team does detection engineering at depth. SPL plus the Enterprise Security content library, risk-based alerting and twenty years of community apps is the most capable hunting toolkit in the category, which is precisely why Gartner placed Splunk highest in Ability to Execute in 2025.
  • You already buy from Cisco. Post-acquisition, Splunk can be folded into an existing Cisco Enterprise Agreement, so the missing public price stops being your problem: procurement already holds the paper and the discount.
  • You ingest long-tail enterprise systems. Splunkbase add-ons parse mainframe, storage array and appliance formats that open-source log stacks simply do not recognise out of the box, and writing those parsers yourself is not free.
  • The apparent disadvantage cuts the other way at scale. Quote-only pricing means the price is negotiable. A team with real volume and real leverage frequently lands below what a published per-GB rate would have charged them, which no public price list will do for you.

Look elsewhere if…

  • You cannot get a budget approved without a number: Grafana Cloud or Elastic publish rates you can model before any call.
  • The bill is driven by volume you never search: Sumo Logic makes ingest free and charges for what you actually scan.
  • Your SOC lives in Microsoft 365 and Azure: Microsoft Sentinel gets the connectors and the identity signals for free.
  • You need to self-host at zero licence cost: Graylog Open for logs, Wazuh for security, OpenSearch or VictoriaLogs if you would rather build on a permissive licence.
  • Data residency or air-gap rules rule out SaaS entirely: only the self-hostable picks can satisfy that, and Splunk's own free licence cannot.

There is also a middle path worth trying first. A telemetry pipeline such as Cribl Stream sits in front of Splunk, dropping and reshaping data before it is billed and routing the bulk to cheap storage; its free licence covers up to 1 TB per day of processing in exchange for anonymised telemetry. It is not a Splunk replacement, which is why it is not ranked above, but it can buy you the time to plan a migration properly instead of under budget pressure.

Common questions

Common questions about Splunk alternatives

What is the best Splunk alternative in 2026?

Elastic is the closest single replacement, because Elasticsearch, Kibana and Elastic Security cover both jobs people use Splunk for: ad-hoc log search and security detection. It self-hosts under AGPL-3.0 and its serverless security tiers publish rates of $0.09 to $0.11 per GB ingested. If the Splunk workload is specifically security and the estate already runs Microsoft 365 or Azure, Microsoft Sentinel is the stronger pick. If it is only logs, Grafana Loki or Graylog will get you there faster and cheaper.

Why do teams leave Splunk?

Almost never because the product got worse: Splunk was a Leader in the 2025 Gartner Magic Quadrant for SIEM for the eleventh consecutive time and placed highest in Ability to Execute. The recurring reasons are commercial. Splunk publishes no list price for its platform, so every budget conversation starts with a sales call. The Free licence is a lab build rather than a small production deployment. And SPL, the query language your dashboards and detections are written in, does not convert to anything else, so the lock-in compounds with every year of content you write.

How much does Splunk cost in 2026?

Splunk does not say. Its pricing page names three models, Workload Pricing, Ingest Pricing and Entity Pricing, and contains no dollar amounts at all. The AWS Marketplace listing for Splunk Cloud is equally explicit: pricing is based on your specific requirements and eligibility, and you request a private offer for a quote. The one exception is Splunk Observability Cloud, which does publish per-host rates starting at $15 per host per month for infrastructure monitoring, $55 for APM and $75 for the End-to-End tier. Any per-GB figure you see quoted for Splunk Enterprise or Splunk Cloud comes from third-party cost estimators, not from Splunk.

Is Splunk Free good enough for a small production deployment?

No, and Splunk's own documentation is clear about why. The Free licence indexes 500 MB per day and never expires, but it has no login at all, so there are no users and no roles. Alerting is not available. Distributed search, search head clustering and indexer clustering are not available. Forwarding in TCP or HTTP formats is not available, and neither is deployment management or report acceleration. Three licence warnings in a rolling 30-day window stop search entirely. It is an evaluation sandbox, not a small production tier.

Is there a truly open-source Splunk alternative?

Yes, and the licence distinctions matter. OpenSearch and VictoriaLogs are Apache-2.0. Grafana Loki is AGPL-3.0, and Elasticsearch and Kibana added AGPL-3.0 as an option on 29 August 2024, which made them OSI open source again. Wazuh's core is GPLv2 with an OpenSearch-based indexer and dashboard under Apache-2.0. Graylog Open is the exception: it is Server Side Public License v1, which the Open Source Initiative does not approve, so it is source-available rather than open source. That is a licensing question, not a quality one, but it is the kind of thing procurement asks about late.

Can I cut my Splunk bill without migrating off Splunk?

Often, yes, and it is worth trying first. A telemetry pipeline such as Cribl Stream sits between your log sources and Splunk, dropping, sampling and reshaping data before it is billed, and routing the low-value bulk to cheap object storage instead. Cribl Stream ships a free licence for up to 1 TB per day of processing in exchange for anonymised telemetry, and Cribl Cloud offers the same 1 TB per day without multiple worker groups. That buys you time to plan a migration properly rather than under budget pressure, and if the reduction is large enough you may not need one.