Vigil

B
B tier on SIEM SoftwareScore 7.2 · #2 of 26
Android app
Not listed
Free plan
Yes
Runs on
api, Linux, Mac, self-hosted, Web, Windows
vigil-siem.com
The Vigil homepage

Summary

Vigil is a self-hosted, open-source system that ingests endpoint events, evaluates Sigma detections in real time, and returns structured JSON for AI agents. It runs without a cloud account and is released under the Apache 2.0 license. Its detection library contains 41 Sigma rules across 10 MITRE ATT&CK tactics. HQL can search event history with aggregations, timelines, endpoint filters, time ranges, and field values. A single binary collects Windows Event Logs or Linux journald and sends batches every five seconds; onboarding uses short-lived enrollment tokens. Vigil Connect supports Wazuh and Elastic, while Splunk and Microsoft Sentinel are listed as coming soon. For destructive actions, the CLI blocks and polls until a person approves. The Claude Code integration is deployed with npx @vigil/skill and does not require an MCP server or running process. The free Open Source plan lists unlimited events, multi-endpoint support, forensic collection, and JSON output. Cloud is listed as coming soon; Enterprise details require contacting the provider.

Who it is for

Vigil is aimed at teams that want self-hosted endpoint event detection and structured output for AI agents. It may suit users who need HQL event hunting and explicit human approval for destructive actions.

What is good

  • Self-hosted and requires no cloud account.
  • Apache 2.0 licensed and open source.
  • Includes 41 Sigma rules across 10 tactics.
  • HQL searches full event history.
  • Destructive actions require human approval.

What to know first

  • Splunk and Microsoft Sentinel are listed as coming soon.
  • Cloud is listed as coming soon.
  • Enterprise pricing requires contacting the provider.

Everything Xiaomi review

Vigil: the full review

Vigil provides self-hosted event collection, Sigma detections, and HQL hunting under a free open-source plan. Its listed current SIEM integrations are Wazuh and Elastic; two others are still marked as coming soon.

Vigil is an open-source security event platform for teams that want to collect endpoint data and build detection or AI-agent workflows on infrastructure they control. It suits developers and security teams comfortable operating a self-hosted service. Its strongest case is a free, capable core; its main compromise is that the managed Cloud plan is not yet available.

Overview

Vigil ingests Windows Event Logs or Linux journald, evaluates Sigma detections in real time, and returns structured JSON for AI agents. Its single-binary collector sends event batches every five seconds, while short-lived enrollment tokens support secure agent onboarding. Self-hosting without a cloud account gives operators control over deployment, but also leaves them responsible for running the service.

The Apache 2.0 open-source release includes 41 Sigma rules spanning 10 MITRE ATT&CK tactics. That is a useful starting point rather than a complete detection program; custom rules let teams adapt coverage to their own environments.

Key features

Hunting and response controls

HQL searches full event history using aggregations, timelines, endpoint filters, time ranges, and field values. That gives analysts tools to investigate beyond an initial alert, though it favors users willing to work in a query language. Vigil returns structured JSON for AI agents, and destructive actions require explicit human approval: the CLI blocks and polls until a person responds. That safeguard is valuable where automated workflows must not take consequential action unchecked.

Integrations and collection

Vigil Connect currently supports Wazuh and Elastic. It extracts only the alert ID, severity, source SIEM, and untouched raw alert JSON, keeping the integration focused rather than enriching or reshaping alerts. Splunk and Microsoft Sentinel support are coming soon. The Claude Code integration is deployed with npx @vigil/skill and needs neither an MCP server nor a running process, making it a focused option for that workflow.

Pricing

Open Source — 0.00 USD per free

The free plan includes unlimited events on ClickHouse, Sigma rules, HQL threat hunting, multiple endpoints, Windows and Linux agents, forensic collection, and JSON output for AI agents. There is no event quota to constrain a growing deployment, but self-hosting means the operator takes on the service’s day-to-day upkeep.

Cloud and Enterprise

Cloud is billed as Coming soon, with managed ClickHouse and Postgres, automatic updates, a web dashboard, email and Slack alerts, API key management, SSO / SAML, dedicated infrastructure, and a 99.9% uptime SLA. It is the intended fit for teams that want managed operations, but it cannot serve as an available alternative today.

Enterprise uses custom pricing and adds dedicated infrastructure, SSO / SAML, custom SLAs, on-premise deployment, custom detection development, a dedicated Slack channel, annual invoicing, a SOC 2 report, and custom integrations. Those support and deployment options suit organizations with specific security or service requirements; the plan’s cost is not a fixed published price.

Platforms

Vigil supports API, Linux, macOS, self-hosted, web, and Windows. Its described endpoint collection specifically covers Windows Event Logs and Linux journald, so the broader platform list should not be read as a claim that every platform has the same agent coverage.

Who it's for

Vigil is a strong match for security teams and developers who want an open-source, self-hosted event pipeline with Sigma detection, historical hunting, and structured output for AI workflows. It is less suited to teams that need a managed service immediately, broad integrations beyond Wazuh and Elastic, or a solution that does not require operating infrastructure.

Pros and cons

  • Pros: The free plan has unlimited events, multiple endpoints, forensic collection, and AI-ready JSON, avoiding a usage cap for self-hosted teams.
  • Pros: HQL covers full-history searches with timelines and aggregations, while human approval gates destructive actions in CLI workflows.
  • Pros: Apache 2.0 licensing and deployment without a cloud account give operators control over hosting.
  • Cons: Self-hosting puts service operation on the team; the managed Cloud plan is still coming soon.
  • Cons: Vigil Connect currently supports only Wazuh and Elastic, limiting teams that depend on other SIEM integrations.
  • Cons: The included 41 rules across 10 tactics are a starting library, so teams may need custom detections for their own coverage.

Alternatives

For a wider SIEM shortlist, browse SIEM Software. Choose Wazuh instead if you want a freemium, free and open-source self-hosted option with a paid Small plan starting at 571.00 USD per month. Elastic Security is another freemium alternative with a free plan and a Security Analytics Essentials tier priced at 0.09 USD per m.

nano SIEM is worth considering for a self-hosted, account-free open-source engine under AGPL-3.0; its Hobby plan is 26.00 USD per month. Sumo Logic suits readers seeking a web-based option whose Free plan has 20 daily credits, seven-day log retention, and up to three users.

CrowdStrike Falcon Surface is a paid alternative with a free trial. ManageEngine Log360 is a paid option with a free trial. Rapid7 Surface Command is a paid option with a free trial. UTMStack is a freemium alternative with a free trial and a listed advanced plan for an average of 300 devices and 750 GB of hot storage.

Verdict

Choose Vigil if you want a free, self-hosted foundation for endpoint event collection, Sigma detection, HQL hunting, and AI-assisted workflows with a human gate on destructive actions. Look elsewhere if managed hosting or integrations beyond Wazuh and Elastic are essential now.

Vigil plans and pricing

All plans
Open Source Free Free Unlimited events (ClickHouse) · Sigma detection rules · Threat hunting (HQL) · Multi-endpoint support · Windows & Linux agents · Forensic collection · JSON output for AI agents vigil-siem.com · 2 Oct 2026
Cloud Not published Coming soon Managed ClickHouse + Postgres · Automatic updates · 99.9% uptime SLA · Web dashboard · Email + Slack alerts · API key management · SSO / SAML · Dedicated infra vigil-siem.com · 2 Oct 2026
Enterprise Not published Contact us Dedicated infrastructure · SSO / SAML · Custom SLA · On-premise deployment · Custom detection development · Dedicated Slack channel · Annual invoicing · SOC 2 report · Custom integrations vigil-siem.com · 2 Oct 2026

Compared on SIEM software

Free plan
Yesvigil-siem.com
Custom detection rules
Yesvigil-siem.com
Real-time alerting
Yesvigil-siem.com
Deployment
self-hostedvigil-siem.com
Query language
HQLvigil-siem.com

Facts

Product purpose
Vigil ingests endpoint events, evaluates Sigma detections in real time, and returns structured JSON for AI agents.vigil-siem.com · 2 Oct 2026
License
Vigil is released under the Apache 2.0 license.vigil-siem.com · 2 Oct 2026
Detection library
Vigil ships with 41 Sigma rules across 10 MITRE ATT&CK tactics.vigil-siem.com · 2 Oct 2026
Event hunting
HQL can query full event history with aggregations, timelines, endpoint filters, time ranges, and field values.vigil-siem.com · 2 Oct 2026
Human approval
Destructive actions require explicit human approval, with the CLI blocking and polling until a response.vigil-siem.com · 2 Oct 2026
Agent collection
The single binary collects Windows Event Logs or Linux journald and ships batches every five seconds.vigil-siem.com · 2 Oct 2026
Platforms
The agent is a dependency-free single binary for Windows, Linux, and macOS, and Vigil includes a web dashboard.vigil-siem.com · 2 Oct 2026
Security onboarding
Vigil supports secure agent onboarding through short-lived enrollment tokens.vigil-siem.com · 2 Oct 2026
SIEM integrations
Vigil Connect supports Wazuh and Elastic now, while Splunk and Microsoft Sentinel integrations are listed as coming soon.vigil-siem.com · 2 Oct 2026
Raw alert handling
Vigil Connect extracts only id, severity, source_siem, and the untouched raw alert JSON.vigil-siem.com · 2 Oct 2026
Claude Code
The Claude Code integration is deployed with npx @vigil/skill and requires no MCP server or running process.vigil-siem.com · 2 Oct 2026
Support
Enterprise includes a dedicated Slack channel, custom integrations, custom SLAs, and a SOC 2 report.vigil-siem.com · 2 Oct 2026

Best Vigil alternatives

See all 20

Where it ranks on Everything Xiaomi

Is Vigil yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources