Open-source SIEM — Elastic, Wazuh and their peers — is a genuinely attractive answer to a real pain: commercial SIEM licensing, priced on data volume, gets brutally expensive as logging grows, and open-source appears to make that cost disappear. It does not; it moves it. Self-hosting an open-source SIEM replaces the licence fee with the cost and responsibility of running, scaling, tuning and operating the platform yourself, and for a SIEM — which is operationally demanding and only as good as the effort behind it — that true operating cost is substantial. Open-source SIEM can be an excellent choice, but only for a firm that understands and can carry the cost the licence fee was hiding.
Where the cost actually lives
A commercial SIEM’s price includes a great deal of operational work you would otherwise do yourself: the infrastructure, the scaling, the maintenance, the tuning, and often support. Open-source hands all of that back. You run and scale the infrastructure, which for the data volumes a SIEM ingests is non-trivial and grows with your logging. You maintain and upgrade the platform. You tune the detections — and this is the crucial part, because a SIEM that is not well-tuned is either a flood of false positives everyone ignores or a set of gaps that miss real attacks, and tuning is ongoing skilled work regardless of the licence. And you operate it around the clock, because a SIEM no one is watching is not providing detection. The licence was free; none of this is.
Why SIEM specifically is demanding
- It is operationally heavy. A SIEM ingests, stores and correlates large volumes of data continuously; running that infrastructure reliably at scale is real engineering, and it is yours with open-source.
- Tuning is the whole game. The value of any SIEM is in well-tuned detection; poorly tuned, it fails whether commercial or open-source. Open-source gives you the engine and none of the tuning, which is skilled, continuous work.
- It needs watching. Detection without response is worthless; someone has to monitor and act, in-house or managed, and that operational capability is a cost the licence comparison omits.
- The skills are scarce. Running an open-source SIEM well requires security-engineering skills that are expensive and hard to hire, which is often the real constraint.
Deciding honestly
- Cost the operation, not the licence. Model the infrastructure, maintenance, tuning and monitoring effort over time; that total is the real comparison with a commercial SIEM, and it is frequently closer than the free licence suggests.
- Be honest about your capability. Open-source SIEM rewards firms with strong security-engineering capability and punishes those without; if you lack it, the true cost of buying it in may erase the saving.
- Weigh it against managed options. A managed SIEM or managed detection service may deliver the outcome more cheaply than self-hosting open-source once the operating cost is counted.
- Match the choice to the stakes. For a lean team with the skills, open-source can be ideal; for a firm relying on the SIEM for serious regulatory or security assurance, the operating burden is higher-stakes.
Open-source SIEM is a real and often excellent option, and for a firm with the security-engineering capability to run it well, the escape from volume-based licensing is a genuine benefit. The trap is treating the absent licence as an absent cost, when the true cost — infrastructure, tuning, operation and the scarce skills to do them — is simply relocated from the vendor to you. Costing that operating reality honestly is what separates the firms for whom open-source SIEM is a smart saving from those who adopt it for the licence and discover the operating bill.
Free · 4 minutes
Do you actually know what you are running — and what it is about to cost you?
Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.
Who this is for
This reading is for:
- CISOs and CTOs weighing Elastic, Wazuh or similar against commercial SIEM
- Firms attracted by open-source SIEM to escape licensing costs
- Lean security teams considering self-hosted monitoring
- Boards approving a SIEM decision on total cost, not licence
Sixteen Pillars helps firms cost the true operating burden of open-source SIEM – infrastructure, tuning, operation, scarce skills – against commercial and managed options. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming