Curated list of the leading open‑source Security Information and Event Management (SIEM) platforms together with compatible next‑generation firewalls for comprehensive threat detection, correlation, and response.
Get targeted exposure with custom position pinning and highlighted placement.
Full‑text search and analytics engine (Elasticsearch, Logstash, Kibana) enhanced with Elastic Security SIEM. Seamlessly integrates with OPNsense or pfSense NGFWs via Syslog and API for enriched log ingestion and automated blocking.
Open‑source host‑based intrusion detection and SIEM built on the ELK stack. Native modules forward alerts to OPNsense/OPNsense‑NGFW, enabling real‑time rule‑based firewall policy updates.
Scalable log management platform with built‑in SIEM capabilities. Supports Syslog and GELF inputs from next‑gen firewalls such as OPNsense, pfSense, and Untangle for unified visibility and automated response.
Community edition of the AlienVault Unified Security Management platform. Integrates directly with pfSense and OPNsense NGFWs, correlating firewall events with IDS/IPS data for actionable threat intel.
Modular, open‑source SIEM built on Elastic Stack, Wazuh, and TheHive. Provides ready‑made connectors for OPNsense and pfSense firewalls, allowing automatic rule enforcement based on detected anomalies.
Comprehensive network security monitoring distro that includes the Elastic SIEM, Suricata, and Zeek. Can be paired with OPNsense NGFW to feed firewall logs into its dashboards and trigger dynamic blocklists.
Open‑source, standards‑based SIEM that aggregates alerts from IDS/IPS, firewalls, and endpoint agents. Works well with OPNsense and pfSense via the Prelude‑OPNsense connector for real‑time correlation.
Big‑data powered SIEM platform (now part of Apache) that ingests telemetry from next‑gen firewalls like OPNsense using Kafka connectors, enabling advanced analytics and threat hunting.
Open‑source incident response platform that can act as a SIEM when combined with Cortex analyzers. Integrates with OPNsense and pfSense via Syslog to enrich alerts and automate containment actions.
Message bus for security automation that can be used as a lightweight SIEM layer. When paired with OPNsense’s DXL connector, it enables real‑time sharing of firewall events with other security tools.