nano SIEM is a security information and event management platform for teams handling detection, alerting, investigation, and response. It stores security logs, OpenTelemetry traces, and metrics together for queries in nPL, its query language. The maker says searches can return in under a second across billions of events using ClickHouse. Its pivt assistant can create parsers, queries, detection rules, and investigation summaries from natural-language requests. Detection rules include MITRE ATT&CK mapping, entity risk scoring, and tracking rare or first-seen indicators. Data can be ingested through HTTP, Syslog, HEC, or Vector, and listed parsers cover tools including Palo Alto, CrowdStrike, Okta, AWS CloudTrail, Microsoft Defender, and Zeek. Deployment options include a managed service and BYOC; Enterprise lists cloud, on-premises, or air-gapped deployment. The nano engine is open source under AGPL-3.0 and can be self-hosted without an account or bill. Hobby includes 2 GB/day of ingest, 10 data sources, 300 AI requests per month, and three team members.
Who it is for
nano SIEM is for security teams that need to search logs and coordinate detection, alerting, investigation, and response. Its self-hosted engine may suit teams that want to run open-source software without an account or bill.
What is good
- Stores logs, traces, and metrics together
- Natural-language assistant generates queries and detection rules
- Detection rules include MITRE ATT&CK mapping
- Engine can be self-hosted without an account or bill
What to know first
- Hobby allows 2 GB/day of ingest
- Hobby includes 10 data sources and three team members
- Hobby limits AI requests to 300 per month
Verdict
nano SIEM combines event search and detection features with several deployment choices, including a self-hosted open-source engine. Hobby has specific ingest, source, AI request, and team limits; paid plans are listed from $29/mo.
nano SIEM plans and pricing
All plansCompared on SIEM software
- Free plan
- Yes
- Paid from
- $29/mo
- Data retention
- 365 days
- Custom detection rules
- Yes
- Real-time alerting
- Yes
- Deployment
- hybrid
- Query language
- nPL (nano Pipe Language)



