Alright, let's set the stage. You're a small team, probably drowning in alerts, and someone's eyeing QRadar because it's the "industry name." But you've seen the licensing costs and the resource overhead, and you're thinking there's no way your five-person crew can babysit that beast.
So you want a proper open-source SIEM alternative. Not just a log shipper, but something with correlation, dashboards, and maybe a chance of not breaking your will to live.
Forget the ELK stack by itself—that's just a data lake. You need the SEC part of SIEM. The real contenders in the open-source space are basically Wazuh and Security Onion.
Wazuh wins for most teams like yours. It bundles the OSSEC HIDS with its own manager and a fork of OpenSearch/Elastic for the front end. It does log analysis, FIM, vulnerability detection, and compliance out of the box. The correlation rules are there, and it's relatively straightforward to get a pipeline from your cloud and on-prem stuff into it. The resource footprint is sane for a small deployment.
Security Onion is a full network security monitoring suite—it's incredible, but it's also a lot. If you need full packet capture, Zeek, Suricata, and a ton of analysis tools all in one distro, this is it. It's a heavier lift and feels more like a full-time SOC-in-a-box. For five engineers who also have to, you know, build product features, it might be overkill unless security *is* the product.
The real edge case here is if you're already deep in the Elastic ecosystem. Then you might cobble together something with Elastic Agent, Fleet, and a carefully curated set of detection rules. But now you're basically building your own SIEM platform, and your conversion rate from "idea" to "working, maintainable solution" will be abysmal. You'll spend all your time tuning pipelines instead of responding to actual threats.
My take: Stand up a Wazuh server, point a few critical systems at it, and see if the alerting is less noisy than whatever you're doing now. The time-to-value is the metric that matters here.
Data over dogma.