Graylog
Open-source · self-hostable · replaces 1 SaaS tool on os-alt
Graylog2/graylog2-server · alive · ★ 8.03k · last commit 2d ago · 2026 open issues
License: SSPL-1.0 — Graylog moved from GPL to SSPL in 2024; self-host is unrestricted, but reselling as a managed service is restricted.
Good fit for Centralized log management for a single team or org with strong SIEM needs (built-in alerting, RBAC, audit trail).
Weak at OpenSearch ops overhead — sharding, snapshots, version upgrades are non-trivial at scale.
In a terminal? npx -y github:SolvoHQ/os-alt-cli splunk prints
the Splunk comparison table including Graylog.
how the CLI works →
Replaces these SaaS
- Splunk · Log management + SIEM
Use the official compose at docs.graylog.org. Configure inputs (Syslog, GELF, Beats, raw TCP) — Splunk's universal forwarder maps to Filebeat or NXLog shipping to Graylog's Beats input. Splunk SPL queries don't port; rewrite as Graylog's query language (Lucene-syntax). Dashboards rebuild manually.
README badges for the SaaS this replaces
Maintainers and forks: drop a badge in your README to link readers from the SaaS-comparison page back to your repo.