Guided scenario
Open-source log management
Log bills can grow faster than the systems that produce them, and some teams need logs on their own infrastructure. This shortlist orders log-management tools by open-source licensing, a self-hosting option, and a free tier noted at last review. Also weigh live tail and search at volume, alerting, retention tiers, and the effort of self-hosting.
Axiom
axiom.co
Axiom is a cloud-native observability and event-data platform for logs, metrics, traces, and events, queried with its own APL query language.
Better Stack
betterstack.com
Better Stack is a combined uptime monitoring, incident management, and status page platform for availability tracking, on-call workflows, and status communication.
Datadog Log Management
www.datadoghq.com/product/log-management
Datadog Log Management is the log analytics product within Datadog's broader observability platform, letting teams centralize logs alongside metrics and traces.
Elastic (ELK)
www.elastic.co/log-management
Elastic (ELK) is the search-powered stack of Elasticsearch, Logstash/Beats, and Kibana, widely used for log management, search, and analytics.
Grafana Loki
grafana.com/oss/loki
Grafana Loki is an open-source, horizontally-scalable log aggregation system designed to be cost-efficient by indexing on labels in a Prometheus-style model.
Graylog
graylog.org
Graylog is a log management and security analytics platform for collecting, searching, and analyzing log data, with SIEM-adjacent capabilities.
Logz.io
logz.io
Logz.io is a cloud observability platform offering managed log management built on open-source tools such as OpenSearch and ELK.
Mezmo
www.mezmo.com
Mezmo (formerly LogDNA) is a telemetry pipeline and log analysis platform that ingests, transforms, and routes logs, metrics, and traces.
OpenObserve
openobserve.ai
OpenObserve is an open-source, OpenTelemetry-native observability platform for logs, metrics, and traces that ships as a single Rust binary with built-in dashboards and alerting.
Splunk
www.splunk.com/en_us/products/log-observer-connect.html
Splunk is a platform for searching, monitoring, and analyzing machine-generated data, widely used for enterprise log management and operational and security analytics.
Pairs well with
Tools commonly used alongside this setup. Chosen editorially, not ranked.
Chronosphere
Monitoring & APM
Chronosphere is an observability platform built for cloud-native and Kubernetes environments, with a particular focus on controlling the cost of metrics data at scale. Founded in 2019 and compatible with Prometheus and OpenTelemetry, it covers APM, infrastructure monitoring, and log management for teams operating very large deployments. Pricing is enterprise and quote-based with no free tier, placing it in the premium tier. While its origins trace to the open-source M3 project, the platform itself is proprietary and closed-source, and it holds SOC2 and ISO27001 compliance.
Atlassian Statuspage
Uptime / Status
Atlassian Statuspage is a hosted status page service for communicating incidents and uptime to users, and is one of the canonical tools in this category. Founded in 2013 and now part of Atlassian, it is aimed at teams that need to share service status with customers and stakeholders. It is an incident-communication tool rather than an active monitor, so it does not run synthetic checks and is often paired with a separate monitoring service. It offers a free plan with limited subscribers and components plus paid tiers above it, and holds SOC2 and ISO27001 compliance.
Elastic Security
SIEM / Security Analytics
Elastic Security is a SIEM and endpoint security solution built on the Elastic Stack for threat detection and investigation. It is aimed at teams already using Elasticsearch for security analytics, and includes threat detection rules and SOAR-style automation. Elastic Security offers a free, open Basic tier that can be self-hosted, alongside the managed Elastic Cloud, supporting both deployment models. It holds SOC 2, ISO 27001, and HIPAA compliance. Building on the Elastic Stack lets teams reuse familiar search and analytics tooling for security use cases.
