HomeThe Stash

Which SIEM Should You Learn? A Free-to-Lab Comparison

ReferenceSeptember 19, 2026

Reference9 platformsLast verified Sep 2026Free-to-lab flagged

A SIEM is the tool a SOC analyst lives in all day — it collects logs, runs detections, and raises the alerts you investigate. “Which one should I learn?” is the question behind most cybersecurity home labs. This page answers it two ways: which SIEM is worth your time for the job market, and which you can actually run for free at home — they are not always the same tool.

Short version: learn Splunk (and its language, SPL) for employability, and run Wazuh at home because it is free and complete. Everything else fills in around those two.

Every major SIEM, side by side

SIEM Vendor What it is Run it free? Best for learning
Splunk Splunk (Cisco) The market-leading SIEM; Enterprise Security is the paid premium app. SPL is its query language. Yes — free Docker image with a 60-day Enterprise trial, then Splunk Free (500 MB/day). The most in-demand SIEM skill. Learn SPL first.
Microsoft Sentinel Microsoft Cloud-native SIEM built on Azure Log Analytics; queried with KQL. Trial — 31-day free trial (up to 10 GB/day), pay-as-you-go after. Needs an Azure account. Microsoft and enterprise shops. KQL transfers to Defender.
Elastic Security Elastic SIEM on the Elastic (ELK) Stack. Detections, hunting, ES|QL / KQL-style search. Yes — free and open when self-hosted (Basic licence). Elastic Cloud has a 14-day trial. Open-source SIEM skills you can run for $0 forever.
Wazuh Wazuh (open source) Free, open-source SIEM + XDR. Agents, file-integrity, detection rules, dashboards. Yes — 100% free, self-host with Docker. No licence, no account. The best zero-cost home lab. Start here. → our lab.
Security Onion Security Onion Solutions Free Linux distro for network security monitoring & hunting. Bundles Elastic, Suricata, Zeek. Yes — free ISO, run in a VM. Paid appliances and support exist. Network defence and threat hunting, not just logs.
Graylog Graylog Log management with SIEM features. Graylog Open is free; Graylog Security is paid. Yes — Graylog Open is free, self-host with Docker. Log-centric SOCs; lighter to run than full ELK.
CrowdStrike Falcon CrowdStrike EDR/XDR platform with Falcon Next-Gen SIEM (LogScale). Cloud-only. No self-host — SaaS only. Falcon Go has a ~15-day trial; no free home-lab build. Knowing the market leader in EDR. Hard to lab at home.
Cortex XSIAM Palo Alto Networks AI-driven SOC / next-gen SIEM platform. Cloud-only. (Palo Alto also now owns the former QRadar SaaS.) No — enterprise SaaS, trial via sales only. No free tier. Awareness of where enterprise SOCs are heading.
IBM QRadar IBM Long-standing enterprise SIEM. IBM sold the SaaS business to Palo Alto in 2024; on-prem continues. Limited — a resource-capped Community Edition VM has been the learning option. Shops that still run QRadar. A declining priority.

Start here if you have no budget

These run on your own machine, free, with no sales call and no expiring trial. This is where a home lab should begin:

  • Wazuh — the most complete free SIEM/XDR. Agents, rules, dashboards, all open source. We have a step-by-step Wazuh Docker lab.
  • Splunk (free / Docker) — not open source, but the Docker image gives you a 60-day Enterprise trial so you can learn SPL hands-on. See the Splunk Docker lab.
  • Elastic Security — free and open when self-hosted; the same stack behind many commercial products.
  • Security Onion — a whole hunting distro in one VM if you want network monitoring too.
  • Graylog Open — a lighter, log-first option that is quick to stand up.

Learn these for the job market

  • Splunk is on more SOC job listings than any other SIEM. Time spent on SPL pays back directly — start with our SPL cheat sheet.
  • Microsoft Sentinel is everywhere Microsoft is, and its language KQL also drives Defender and Azure — two skills for one.
  • CrowdStrike Falcon and Cortex XSIAM are cloud-only, so you can rarely lab them at home. Know what they are and how they fit; get hands-on time through a job or an employer’s tenant.

How to get each one (and the account you’ll need)

Several of these ask you to create an account. Here is exactly what each one requires — and where you can skip the sign-up:

Platform How to get it
Splunk No account needed if you use the Docker image (splunk/splunk on Docker Hub). For the direct download or Splunkbase apps, a free splunk.com account is required.
Microsoft Sentinel Create a free Azure account (a card is used for identity verification; the free tier and trial won’t charge you). Enable Sentinel on a Log Analytics workspace, then watch your daily ingestion to stay inside the free trial.
Elastic Security No account to run it locally — pull the Docker images and go. For managed Elastic Cloud, sign up with an email for the 14-day trial.
Wazuh No account at all. Clone the repo and run Docker Compose — see our lab.
Security Onion No account. Download the ISO from the project site and install it in a VM.
Graylog No account. Pull Graylog Open with Docker Compose (it ships with MongoDB and a data store).
CrowdStrike / Palo Alto Not self-serve. Request a trial or demo through the vendor; access usually comes via an employer or a partner.
IBM QRadar An IBM account has been needed to download the Community Edition VM; treat it as legacy and prioritise the others.

A learning path that actually works

  • Week 1–2: stand up Wazuh, generate some alerts, and read how detections fire.
  • Week 3–4: run the Splunk lab and drill SPL with the cheat sheet until searching feels natural.
  • Then: map what you see to attacker behaviour with the Cyber Kill Chain, and try Elastic or Sentinel to feel the differences between query languages.

Comparison last verified Sep 2026. Free tiers, trial lengths and ownership (QRadar’s SaaS moved to Palo Alto in 2024) change — spotted something out of date? Tell me and I’ll fix it.