SIEM

Security Information and Event Management solutions for log management and security monitoring

Try these 57 AI SIEM Tools

Alien Vault Ossim
Free

Alien Vault Ossim View Alien Vault Ossim

A tool collection for filtering and visualizing logon events, designed for experienced DFIR specialists in threat hunting and incident response.

Amazon Detective
Free

Amazon Detective View Amazon Detective

Democratizing graph-based security analysis by collecting assets and relationships from services and systems into an intuitive graph view.

Alterix
Free

Alterix View Alterix

A Security Information and Event Management (SIEM) system with a focus on security and minimalism.

Apache Metron
Free

Apache Metron View Apache Metron

HoneyView is a tool for analyzing honeyd logfiles graphically and textually.

AWS CloudTrail
Free

AWS CloudTrail View AWS CloudTrail

A dynamic GUI for advanced log analysis, allowing users to execute SQL queries on structured log data.

aws-logsearch
Free

aws-logsearch View aws-logsearch

Graylog offers advanced log management and SIEM capabilities to enhance security and compliance across various industries.

Blauhaunt
Free

Blauhaunt View Blauhaunt

A collection of detections for Panther SIEM with detailed setup instructions.

Cowralyze
Free

Cowralyze View Cowralyze

A compliant audit log tool that provides a searchable, exportable record of read/write events.

ElastAlert
Free

ElastAlert View ElastAlert

Logdissect is a CLI utility and Python library for analyzing log files and other data.

Elastic Security
Free

Elastic Security View Elastic Security

SysmonSearch makes event log analysis more effective by aggregating Microsoft Sysmon logs and providing detailed analysis through Elasticsearch and Kibana.

ELAT (Event Log Analysis Tool)
Free

ELAT (Event Log Analysis Tool) View ELAT (Event Log Analysis Tool)

A Command Line Map-Reduce tool for analyzing cowrie log files over time and creating visualizations and statistics.

Elastic
Free

Elastic View Elastic

A compliant audit log tool that provides a searchable, exportable record of read/write events.

Event Query Language (EQL)
Free

Event Query Language (EQL) View Event Query Language (EQL)

A tool for advanced HTTPD logfile security analysis and forensics, implementing various techniques to detect attacks against web applications.

Graylog
Free

Graylog View Graylog

Apache Metron is a centralized tool for security monitoring and analysis that integrates various open-source big data technologies.

GrokEVT
Free

GrokEVT View GrokEVT

Access a repository of Analytic Stories and security guides mapped to industry frameworks, with Splunk searches, machine learning algorithms, and playbooks for threat detection and response.

HoneyView
Free

HoneyView View HoneyView

A pure Python parser for Windows Event Log files with access to File and Chunk headers, record templates, and event entries.

HonnyPotter
Free

HonnyPotter View HonnyPotter

Track user activity and API usage on AWS and in hybrid and multicloud environments.

HpfeedsHoneyGraph
Free

HpfeedsHoneyGraph View HpfeedsHoneyGraph

A method for log volume reduction without losing analytical capability.

IBM QRadar
Free

IBM QRadar View IBM QRadar

RedELK enhances Red Team operations with SIEM capabilities to monitor and alert on Blue Team activities.

LastActivityView
Free

LastActivityView View LastActivityView

A Command Line Map-Reduce tool for analyzing cowrie log files over time and creating visualizations and statistics.

LogRhythm Axon
Free

LogRhythm Axon View LogRhythm Axon

A tool collection for filtering and visualizing logon events, designed for experienced DFIR specialists in threat hunting and incident response.

Log-Killer
Free

Log-Killer View Log-Killer

A visualization app for hpfeeds logs.

Log Parser Lizard
Free

Log Parser Lizard View Log Parser Lizard

A cloud-native SIEM platform that provides security analytics, intuitive workflow, and simplified incident response to help security teams defend against cyber threats.

LogESP
Free

LogESP View LogESP

A framework for generating log events without the need for infrastructure, allowing for simple, repeatable, and randomized log event creation.