Vigil

Web · Windows · Mac · Linux · Self-hosted · API

Freedom report

Three barsScore 6.6

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely4 of 6 device platforms
  • DocumentedPlans, terms and facts published

Vigil collects endpoint events, evaluates Sigma detections in real time and returns structured JSON for AI agents. It is open source, self-hosted and does not require a cloud account. Its included library contains 41 Sigma rules across 10 MITRE ATT&CK tactics, while HQL can search event history by aggregations, timelines, endpoint filters, time ranges and field values. A single binary gathers Windows Event Logs or Linux journald and sends batches every five seconds; short-lived enrollment tokens support secure agent onboarding. Vigil Connect currently supports Wazuh and Elastic, with Splunk and Microsoft Sentinel listed as coming soon. For destructive actions, the CLI waits for explicit human approval. The Claude Code integration is installed with npx @vigil/skill and needs no MCP server or running process. The Open Source plan is free and includes unlimited events, multi-endpoint support, forensic collection and JSON output. Cloud is listed as coming soon; Enterprise pricing requires contacting the provider.

Who it is for

Vigil suits teams seeking self-hosted endpoint event detection and threat hunting, including workflows that return JSON to AI agents. It also fits users who need human approval before destructive actions.

What is good

  • Free Open Source plan includes unlimited events.
  • Includes 41 Sigma rules across 10 tactics.
  • HQL searches event history with filters and timelines.
  • Destructive actions require explicit human approval.

What to know first

  • Splunk and Microsoft Sentinel integrations are coming soon.
  • Cloud plan is listed as coming soon.
  • Enterprise pricing requires contacting the provider.

Freedom251 review

Vigil: the full review

Vigil combines real-time Sigma detections, searchable event history and structured output in a self-hosted package. Its currently listed SIEM integrations are Wazuh and Elastic, while other named integrations are not yet available.

Vigil is a self-hosted security event platform that turns endpoint events into Sigma detections and structured output for AI agents. It suits security teams and developers who want to run that workflow on infrastructure they control. Its free open-source core is substantial; teams seeking managed hosting must wait for Cloud.

Overview

Vigil collects Windows Event Logs or Linux journald with a single binary that sends batches every five seconds. Short-lived enrollment tokens support secure agent onboarding, and deployment requires no cloud account. Apache 2.0 licensing gives teams room to operate and adapt the software, but self-hosting also means taking responsibility for its infrastructure.

The shipped detection library contains 41 Sigma rules across 10 MITRE ATT&CK tactics. This is a useful starting set, not comprehensive coverage for every environment; custom detection rules let teams extend it. Vigil also supports real-time alerting.

Key features

Hunting and response

HQL can search full event history using aggregations, timelines, endpoint filters, time ranges, and field values. That makes it useful for investigating patterns beyond an initial alert, though it favors analysts comfortable querying events rather than relying solely on a dashboard.

Vigil returns structured JSON for AI agents. Destructive actions require explicit human approval: the CLI blocks and polls until someone responds. That safeguard is valuable for teams automating response, but it also means destructive workflows cannot proceed unattended.

SIEM connections and AI workflow

Vigil Connect currently supports Wazuh and Elastic. It extracts four fields—id, severity, source_siem, and the untouched raw alert JSON—so teams can preserve the original alert while passing a defined set of metadata onward. Splunk and Microsoft Sentinel connections are coming soon, not current options.

The Claude Code integration is deployed with npx @vigil/skill and requires neither an MCP server nor a running process. This keeps that setup lightweight for Claude Code users, but does not replace the need to operate Vigil itself.

Pricing

Open Source: 0.00 USD per free. It includes unlimited events (ClickHouse), Sigma detection rules, HQL threat hunting, multi-endpoint support, Windows and Linux agents, forensic collection, and JSON output for AI agents. This is the natural fit for teams able to self-host; the trade-off is that they run the service themselves.

Cloud: custom pricing; billed Coming soon. The planned managed ClickHouse and Postgres service adds automatic updates, a 99.9% uptime SLA, web dashboard, email and Slack alerts, API key management, SSO / SAML, and dedicated infrastructure. It is aimed at teams wanting managed operations, but is not yet an option.

Enterprise: custom pricing; billed Contact us. It includes dedicated infrastructure, SSO / SAML, custom SLA, on-premise deployment, custom detection development, a dedicated Slack channel, annual invoicing, a SOC 2 report, and custom integrations. This fits organizations needing tailored deployment or support; the price requires direct contact.

Platforms

Vigil supports API, Linux, macOS, self-hosted, web, and Windows. The collection details specifically cover Windows Event Logs and Linux journald.

Who it's for

Vigil is best for security teams and developers who want Sigma-based endpoint detection, historical event hunting, and AI-agent output while retaining control of deployment. It is less suitable for teams that need a managed service today, broad SIEM integrations beyond Wazuh and Elastic, or destructive response without a human approval step.

Pros and cons

  • Pros: The free core combines unlimited events, HQL hunting, multi-endpoint support, and AI-ready JSON without a cloud account.
  • Pros: Human approval gates destructive actions, a practical control for AI-assisted response workflows.
  • Cons: Self-hosting puts infrastructure operation on the user, and the managed Cloud plan is still coming soon.
  • Cons: Current Vigil Connect integrations are limited to Wazuh and Elastic; Splunk and Microsoft Sentinel are not ready yet.

Alternatives

Consider Wazuh if you want a free, self-hosted open-source option with a paid Small plan starting at 571.00 USD per month. Elastic Security is another freemium option with a free plan and paid Security Analytics Essentials pricing at 0.09 USD per m.

Sumo Logic may suit readers seeking a hosted web option with a free tier capped at 20 daily credits and 7-day log retention for up to 3 users. nano SIEM is another freemium, self-hostable option; its nano engine is open source under AGPL-3.0 and can run without an account or bill.

Seceon Open Threat Management is an alternative with freemium pricing and self-hosted and web platforms. Devo Analytics Cloud is a paid, web-based alternative. CrowdStrike Falcon Surface is paid, has no free plan, and offers a free trial. FortiSIEM is a paid web-based alternative. Browse more options in SIEM Software.

Verdict

Choose Vigil if you want a free, self-hosted foundation for real-time Sigma detection, HQL event hunting, and AI-agent workflows with human approval for destructive actions. Its strongest reason to choose is the breadth of that open-source core; its main reason to look elsewhere is the need for managed service or SIEM connections beyond Wazuh and Elastic today.

Vigil plans and pricing

All plans
Open Source Free Free Unlimited events (ClickHouse) · Sigma detection rules · Threat hunting (HQL) · Multi-endpoint support · Windows & Linux agents · Forensic collection · JSON output for AI agents vigil-siem.com · 2 Oct 2026
Cloud Not published Coming soon Managed ClickHouse + Postgres · Automatic updates · 99.9% uptime SLA · Web dashboard · Email + Slack alerts · API key management · SSO / SAML · Dedicated infra vigil-siem.com · 2 Oct 2026
Enterprise Not published Contact us Dedicated infrastructure · SSO / SAML · Custom SLA · On-premise deployment · Custom detection development · Dedicated Slack channel · Annual invoicing · SOC 2 report · Custom integrations vigil-siem.com · 2 Oct 2026

Compared on SIEM software

Free plan
Yes
Custom detection rules
Yes
Real-time alerting
Yes
Deployment
self-hosted
Query language
HQL

Best Vigil alternatives

See all 12