OpenSearch Security Analytics
Open source SIEM plugin for OpenSearch with native Sigma rule support and free alerting.
Technical Architecture & Overview
Security Analytics is the OpenSearch project SIEM plugin. It ships more than 2,000 prepackaged Sigma rules across common log sources, maps them to OpenSearch queries, and provides detection rule management, correlating alerts, and dashboards. Because it runs inside OpenSearch, storage, retention, and clustering follow the platform rather than a separate SIEM license.
Targeted Technical Use Cases
AWS or self-hosted OpenSearch users adding threat detection without new vendor licensing.
Evaluation & Trade-offs
Core Strengths
- +Sigma-native rule pipeline.
- +Apache-2.0 licensed with no feature paywall.
- +Runs on the OpenSearch stack many teams already operate.
Trade-Offs & Limitations
- -Younger feature set than commercial SIEMs.
- -Correlation depth is thinner than dedicated platforms.
Defensive Security Application
Sigma-based detection and alerting over logs already collected in OpenSearch.
Frequently Asked Questions
What is OpenSearch Security Analytics?→
Security Analytics is the OpenSearch project SIEM plugin. It ships more than 2,000 prepackaged Sigma rules across common log sources, maps them to OpenSearch queries, and provides detection rule management, correlating alerts, and dashboards. Because it runs inside OpenSearch, storage, retention, and clustering follow the platform rather than a separate SIEM license.
What is OpenSearch Security Analytics used for?→
AWS or self-hosted OpenSearch users adding threat detection without new vendor licensing.
What are the strengths of OpenSearch Security Analytics?→
- +Sigma-native rule pipeline.
- +Apache-2.0 licensed with no feature paywall.
- +Runs on the OpenSearch stack many teams already operate.
What are the limitations of OpenSearch Security Analytics?→
- +Younger feature set than commercial SIEMs.
- +Correlation depth is thinner than dedicated platforms.
How is OpenSearch Security Analytics used defensively?→
Sigma-based detection and alerting over logs already collected in OpenSearch.