Vigil
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- api, Linux, Mac, self-hosted, Web, Windows

Summary
Vigil is a self-hosted, open-source system that ingests endpoint events, evaluates Sigma detections in real time, and returns structured JSON for AI agents. It runs without a cloud account and is released under the Apache 2.0 license. Its detection library contains 41 Sigma rules across 10 MITRE ATT&CK tactics. HQL can search event history with aggregations, timelines, endpoint filters, time ranges, and field values. A single binary collects Windows Event Logs or Linux journald and sends batches every five seconds; onboarding uses short-lived enrollment tokens. Vigil Connect supports Wazuh and Elastic, while Splunk and Microsoft Sentinel are listed as coming soon. For destructive actions, the CLI blocks and polls until a person approves. The Claude Code integration is deployed with npx @vigil/skill and does not require an MCP server or running process. The free Open Source plan lists unlimited events, multi-endpoint support, forensic collection, and JSON output. Cloud is listed as coming soon; Enterprise details require contacting the provider.
Who it is for
Vigil is aimed at teams that want self-hosted endpoint event detection and structured output for AI agents. It may suit users who need HQL event hunting and explicit human approval for destructive actions.
What is good
- Self-hosted and requires no cloud account.
- Apache 2.0 licensed and open source.
- Includes 41 Sigma rules across 10 tactics.
- HQL searches full event history.
- Destructive actions require human approval.
What to know first
- Splunk and Microsoft Sentinel are listed as coming soon.
- Cloud is listed as coming soon.
- Enterprise pricing requires contacting the provider.
Everything Xiaomi review
Vigil: the full review
Vigil provides self-hosted event collection, Sigma detections, and HQL hunting under a free open-source plan. Its listed current SIEM integrations are Wazuh and Elastic; two others are still marked as coming soon.
Vigil is an open-source security event platform for teams that want to collect endpoint data and build detection or AI-agent workflows on infrastructure they control. It suits developers and security teams comfortable operating a self-hosted service. Its strongest case is a free, capable core; its main compromise is that the managed Cloud plan is not yet available.
Overview
Vigil ingests Windows Event Logs or Linux journald, evaluates Sigma detections in real time, and returns structured JSON for AI agents. Its single-binary collector sends event batches every five seconds, while short-lived enrollment tokens support secure agent onboarding. Self-hosting without a cloud account gives operators control over deployment, but also leaves them responsible for running the service.
The Apache 2.0 open-source release includes 41 Sigma rules spanning 10 MITRE ATT&CK tactics. That is a useful starting point rather than a complete detection program; custom rules let teams adapt coverage to their own environments.
Key features
Hunting and response controls
HQL searches full event history using aggregations, timelines, endpoint filters, time ranges, and field values. That gives analysts tools to investigate beyond an initial alert, though it favors users willing to work in a query language. Vigil returns structured JSON for AI agents, and destructive actions require explicit human approval: the CLI blocks and polls until a person responds. That safeguard is valuable where automated workflows must not take consequential action unchecked.
Integrations and collection
Vigil Connect currently supports Wazuh and Elastic. It extracts only the alert ID, severity, source SIEM, and untouched raw alert JSON, keeping the integration focused rather than enriching or reshaping alerts. Splunk and Microsoft Sentinel support are coming soon. The Claude Code integration is deployed with npx @vigil/skill and needs neither an MCP server nor a running process, making it a focused option for that workflow.
Pricing
Open Source — 0.00 USD per free
The free plan includes unlimited events on ClickHouse, Sigma rules, HQL threat hunting, multiple endpoints, Windows and Linux agents, forensic collection, and JSON output for AI agents. There is no event quota to constrain a growing deployment, but self-hosting means the operator takes on the service’s day-to-day upkeep.
Cloud and Enterprise
Cloud is billed as Coming soon, with managed ClickHouse and Postgres, automatic updates, a web dashboard, email and Slack alerts, API key management, SSO / SAML, dedicated infrastructure, and a 99.9% uptime SLA. It is the intended fit for teams that want managed operations, but it cannot serve as an available alternative today.
Enterprise uses custom pricing and adds dedicated infrastructure, SSO / SAML, custom SLAs, on-premise deployment, custom detection development, a dedicated Slack channel, annual invoicing, a SOC 2 report, and custom integrations. Those support and deployment options suit organizations with specific security or service requirements; the plan’s cost is not a fixed published price.
Platforms
Vigil supports API, Linux, macOS, self-hosted, web, and Windows. Its described endpoint collection specifically covers Windows Event Logs and Linux journald, so the broader platform list should not be read as a claim that every platform has the same agent coverage.
Who it's for
Vigil is a strong match for security teams and developers who want an open-source, self-hosted event pipeline with Sigma detection, historical hunting, and structured output for AI workflows. It is less suited to teams that need a managed service immediately, broad integrations beyond Wazuh and Elastic, or a solution that does not require operating infrastructure.
Pros and cons
- Pros: The free plan has unlimited events, multiple endpoints, forensic collection, and AI-ready JSON, avoiding a usage cap for self-hosted teams.
- Pros: HQL covers full-history searches with timelines and aggregations, while human approval gates destructive actions in CLI workflows.
- Pros: Apache 2.0 licensing and deployment without a cloud account give operators control over hosting.
- Cons: Self-hosting puts service operation on the team; the managed Cloud plan is still coming soon.
- Cons: Vigil Connect currently supports only Wazuh and Elastic, limiting teams that depend on other SIEM integrations.
- Cons: The included 41 rules across 10 tactics are a starting library, so teams may need custom detections for their own coverage.
Alternatives
For a wider SIEM shortlist, browse SIEM Software. Choose Wazuh instead if you want a freemium, free and open-source self-hosted option with a paid Small plan starting at 571.00 USD per month. Elastic Security is another freemium alternative with a free plan and a Security Analytics Essentials tier priced at 0.09 USD per m.
nano SIEM is worth considering for a self-hosted, account-free open-source engine under AGPL-3.0; its Hobby plan is 26.00 USD per month. Sumo Logic suits readers seeking a web-based option whose Free plan has 20 daily credits, seven-day log retention, and up to three users.
CrowdStrike Falcon Surface is a paid alternative with a free trial. ManageEngine Log360 is a paid option with a free trial. Rapid7 Surface Command is a paid option with a free trial. UTMStack is a freemium alternative with a free trial and a listed advanced plan for an average of 300 devices and 750 GB of hot storage.
Verdict
Choose Vigil if you want a free, self-hosted foundation for endpoint event collection, Sigma detection, HQL hunting, and AI-assisted workflows with a human gate on destructive actions. Look elsewhere if managed hosting or integrations beyond Wazuh and Elastic are essential now.
Vigil plans and pricing
All plansCompared on SIEM software
- Free plan
- Yesvigil-siem.com
- Custom detection rules
- Yesvigil-siem.com
- Real-time alerting
- Yesvigil-siem.com
- Deployment
- self-hostedvigil-siem.com
- Query language
- HQLvigil-siem.com
Facts
- Product purpose
- Vigil ingests endpoint events, evaluates Sigma detections in real time, and returns structured JSON for AI agents.vigil-siem.com · 2 Oct 2026
- License
- Vigil is released under the Apache 2.0 license.vigil-siem.com · 2 Oct 2026
- Detection library
- Vigil ships with 41 Sigma rules across 10 MITRE ATT&CK tactics.vigil-siem.com · 2 Oct 2026
- Event hunting
- HQL can query full event history with aggregations, timelines, endpoint filters, time ranges, and field values.vigil-siem.com · 2 Oct 2026
- Human approval
- Destructive actions require explicit human approval, with the CLI blocking and polling until a response.vigil-siem.com · 2 Oct 2026
- Agent collection
- The single binary collects Windows Event Logs or Linux journald and ships batches every five seconds.vigil-siem.com · 2 Oct 2026
- Platforms
- The agent is a dependency-free single binary for Windows, Linux, and macOS, and Vigil includes a web dashboard.vigil-siem.com · 2 Oct 2026
- Security onboarding
- Vigil supports secure agent onboarding through short-lived enrollment tokens.vigil-siem.com · 2 Oct 2026
- SIEM integrations
- Vigil Connect supports Wazuh and Elastic now, while Splunk and Microsoft Sentinel integrations are listed as coming soon.vigil-siem.com · 2 Oct 2026
- Raw alert handling
- Vigil Connect extracts only id, severity, source_siem, and the untouched raw alert JSON.vigil-siem.com · 2 Oct 2026
- Claude Code
- The Claude Code integration is deployed with npx @vigil/skill and requires no MCP server or running process.vigil-siem.com · 2 Oct 2026
- Support
- Enterprise includes a dedicated Slack channel, custom integrations, custom SLAs, and a SOC 2 report.vigil-siem.com · 2 Oct 2026
Best Vigil alternatives
See all 20Where it ranks on Everything Xiaomi
- Best SIEM Software in 2026#2 of 26
Is Vigil yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- vigil-siem.com· checked 2 Oct 2026
- vigil-siem.com/siem· checked 2 Oct 2026
- vigil-siem.com/connect· checked 2 Oct 2026
- vigil-siem.com/pricing· checked 2 Oct 2026




