EasySIEM โ€” a self-hosted SIEM built on SigmaHQ, OpenSearch & Grafana

2,600+ community detection rules, a lightweight Go ingestion pipeline, and dashboards that actually load fast โ€” installed as real services (Windows service / Scheduled Task, or systemd on Linux), not a pile of scripts you have to remember to restart.

Windows 11 ยท Windows Server ยท agents for Windows & Linux endpoints
EasySIEM's Overview dashboard in Grafana: Alerts (24h) and Critical/High Alerts gauges both showing high counts in red, an Active Agents gauge in green, and an Alerts Over Time by Severity chart below
What this is

Detection rules you didn't have to write, running on infrastructure you actually control

EasySIEM wires together the pieces of a real SIEM โ€” log collection, storage, detection, and visualization โ€” using SigmaHQ's open, vendor-neutral rule set instead of a proprietary rules language, and OpenSearch/Grafana instead of a SaaS bill.

Custom Go agents on Windows and Linux endpoints ship Event Log, Sysmon, journald, and auditd data over HTTPS to a small ingestion API, which authenticates each agent by its own API key and writes into OpenSearch. A detection engine converts SigmaHQ rules into OpenSearch queries with pySigma and runs them on a schedule, so hits show up as alerts โ€” not just raw logs โ€” in Grafana.

Everything server-side installs as a proper Windows service/Scheduled Task or a systemd unit on Linux, not a console window you have to keep open. And every component โ€” the agents, the ingestion API, the TLS cert generator โ€” is a plain Go binary calling documented OS APIs, which is also why it doesn't trip Windows Defender's heuristics the way a packed, obfuscated tool would. More on that below.

How it fits together

Architecture

One ingestion path in, three consumers out: real-time detection, dashboards, and live log search.

Windows agent Event Log ยท Sysmon Linux agent journald ยท auditd Suricata network IDS (optional) ingest-api Go ยท HTTPS ยท API keys OpenSearch events-* ยท alerts-* detect-engine Sigma โ†’ OpenSearch DSL Grafana dashboards Loki raw logs ยท LogQL (optional) HTTPS eve.json
Why it's built this way

What you get

๐Ÿงฉ

2,600+ SigmaHQ rules

Windows and Linux detection rules converted to real OpenSearch queries via pySigma โ€” no hand-written detections to maintain.

๐Ÿ›ก๏ธ

Defender-friendly by design

Plain Go binaries calling documented OS APIs โ€” no packing, no obfuscation, no process injection. Official signed tools (Sysmon, OpenSearch, Grafana) everywhere else.

โš™๏ธ

Real services, not scripts

ingest-api installs as a native Windows service (or systemd unit on Linux); the detect-engine runs as a Scheduled Task (or its own systemd unit). Nothing depends on a console window staying open.

๐Ÿ“Š

Dashboards that load

An Overview dashboard with KPI gauges, plus dedicated Events, Alerts, and Agent Health views โ€” provisioned automatically, not built by hand.

๐Ÿ”‘

Per-agent authentication

Every agent gets its own bearer API key over TLS. One compromised agent can't spoof another's identity โ€” ingest-api stamps identity server-side.

๐Ÿง

Windows + Linux agents

One small Go codebase, cross-compiled for both platforms, shipping to the same ingestion pipeline with a shared event schema.

๐Ÿ”

Live log search (optional)

Add Loki and ingest-api dual-writes every event there as a raw log line โ€” live-tail and LogQL-search in Grafana's Explore view, right alongside the dashboards.

๐Ÿ“ก

Network detection (optional)

Add Suricata and it runs Snort/Emerging-Threats-syntax rules against live traffic itself โ€” its alerts land in the same Grafana Alerts dashboard as Sigma's host-based detections.

Get running

Installation

Two ways to get the server running โ€” pick one.

Download EasySiemSetup.exe

Grab it from the Download section below.

Run it as Administrator

It needs admin rights to register the ingest-api Windows service and the detect-engine's Scheduled Task.

Pick your optional components

  • OpenSearch โ€” downloads ~450 MB from opensearch.org, skipped if already installed
  • Grafana โ€” installs with the provisioned dashboards already wired up; you'll be asked for an admin password instead of the default
  • Loki โ€” optional, for live log search/LogQL in Grafana's Explore view alongside the dashboards
  • Sysmon โ€” only if this same box is also a monitored endpoint
  • Suricata โ€” network IDS, runs Snort/ET-syntax rules against live traffic; only if this box is also a monitored endpoint. Needs one manual click-through for Npcap (its free edition has no silent installer) โ€” a setup window will appear

Grab your API key

The installer generates a TLS cert and a starter API key automatically, and writes both โ€” plus next steps โ€” to GETTING-STARTED.txt in the install directory.

Open Grafana

http://localhost:3000 on the server itself โ€” it opens straight to the Overview dashboard.

Prerequisites

winget install -e --id GoLang.Go
winget install -e --id Python.Python.3.12

Install OpenSearch and Grafana

.\scripts\install-opensearch.ps1
.\scripts\apply-index-templates.ps1
# from an elevated prompt:
.\scripts\install-grafana.ps1

Build and run ingest-api

go build -o bin\ingest-api.exe .\server\ingest
go build -o bin\gencert.exe .\tools\gencert
.\bin\gencert.exe -out-cert server\ingest\certs\server.crt -out-key server\ingest\certs\server.key -hosts localhost,127.0.0.1
# copy config.json.example to config.json, add an API key, then:
.\bin\ingest-api.exe -config server\ingest\config.json

Convert Sigma rules and run detections

git clone --depth 1 https://github.com/SigmaHQ/sigma.git rules\sigma
cd server\detect
python -m venv venv
.\venv\Scripts\pip install sigma-cli pysigma-backend-opensearch pysigma-pipeline-sysmon requests
.\venv\Scripts\python convert_rules.py
.\venv\Scripts\python run_detections.py

Build and deploy an agent

go build -o bin\windows-agent.exe .\agents\windows
# or, for a Linux endpoint:
$env:GOOS="linux"; go build -o bin\linux-agent .\agents\linux

Full walkthrough โ€” including Sysmon setup and agent config โ€” is in docs/SETUP.md in the source download.

A note on Windows Defender: a brand-new, unsigned .exe โ€” ours included โ€” will sometimes trigger a first-run SmartScreen prompt or a brief scan delay. That's normal, and not something this project tries to evade: every component is a plain binary calling documented APIs. See docs/DEFENDER.md in the source download for exclusion commands and code-signing notes if you want to remove the prompt entirely.
For Linux hosts

Linux Server

Prefer to run the backend on Linux instead of Windows? A .deb installs ingest-api and the detect-engine as systemd services, running as a dedicated unprivileged account rather than root. It does not include OpenSearch, Grafana, or Loki โ€” all three already have official Debian/Ubuntu packages, so this doesn't try to duplicate them.

Install OpenSearch and Grafana first

From their own official packages: OpenSearch for Debian and Grafana for Debian.

Download and install the server package

wget https://easysiem.com/downloads/easysiem-server_1.0.0_amd64.deb
sudo apt install ./easysiem-server_1.0.0_amd64.deb

Generates a TLS cert and a starter API key, writes a working config, and starts both services automatically โ€” the key is printed at the end of the install (and saved in /etc/easysiem-server/ingest-config.json).

Apply the OpenSearch index templates

sudo /usr/share/easysiem-server/apply-index-templates.sh

Wire up Grafana

sudo grafana-cli plugins install grafana-opensearch-datasource
sudo cp /etc/easysiem-server/grafana-provisioning/datasources/opensearch.yml \
    /etc/grafana/provisioning/datasources/
sudo cp -r /etc/easysiem-server/grafana-provisioning/dashboards/* \
    /etc/grafana/provisioning/dashboards/
sudo systemctl restart grafana-server

Connect an agent

Give it the printed API key, a copy of /var/lib/easysiem-server/certs/server.crt, and server_url: https://<this-host>:8443. See Linux Agent below, or build the Windows agent from source.

Runs as a dedicated unprivileged easysiem-server account, not root โ€” unlike the agent, neither service needs any special system access. sudo apt remove easysiem-server keeps your config and data; apt purge removes those and the dedicated account too. Full docs, including how to add more agent keys: /usr/share/doc/easysiem-server/README.md.
Want live log search too? Install Loki (bind it to 127.0.0.1 only โ€” it has no built-in auth), copy /etc/easysiem-server/grafana-provisioning/datasources/loki.yml into Grafana's provisioning, and add "loki_url": "http://localhost:3100" to ingest-config.json. Full steps in the README.
For endpoints

Linux Agent

A .deb package for Debian/Ubuntu boxes you want monitored. Ships journald and auditd events to an EasySIEM server that's already running โ€” see Install above if you haven't set that up yet.

Download and install the package

wget https://easysiem.com/downloads/easysiem-agent_1.0.0_amd64.deb
sudo apt install ./easysiem-agent_1.0.0_amd64.deb

Registers the systemd unit automatically. The agent does not start yet โ€” it needs a real config first.

Configure it

sudo cp /etc/easysiem/agent.json.example /etc/easysiem/agent.json
sudo nano /etc/easysiem/agent.json

Set server_url to your server's https://host:8443, and api_key to a key generated on the server (scripts\gen-api-key.ps1, or the starter key from its GETTING-STARTED.txt).

Copy the server's TLS certificate

Grab server.crt from C:\Program Files\EasySIEM\server\ingest\certs\ on the server (however's convenient โ€” SFTP, a shared drive, pasting its contents) and place it at /etc/easysiem/server.crt on this box, matching the ca_cert_path already set in agent.json.example.

Enable and start it

sudo systemctl enable --now easysiem-agent
journalctl -u easysiem-agent -f

The second command tails its logs, so you can confirm it's actually shipping events.

Runs as root by default โ€” it needs read access to /var/log/audit/audit.log (usually root:adm 0640) and the full journald stream. The systemd unit has a commented-out User=/Group= for running it as a dedicated account instead (needs adm + systemd-journal group membership) โ€” see SECURITY.md in the package's /usr/share/doc/easysiem-agent/. sudo apt remove easysiem-agent keeps your config; apt purge removes it too.
Want network detection too? Install Suricata from its official Ubuntu PPA/Debian package (ppa:oisf/suricata-stable on Ubuntu), point it at your interface, run suricata-update for the free ET Open ruleset, then set "suricata_eve_path": "/var/log/suricata/eve.json" in agent.json โ€” its alerts land in the same Grafana Alerts dashboard as Sigma's. Full steps in the README.
Get it

Download

๐ŸชŸ

EasySiemSetup.exe

Windows installer ยท ~11 MB

Installs ingest-api as a Windows service and the detect-engine as a Scheduled Task, with optional OpenSearch, Grafana, and Sysmon components. Requires Administrator.

โฌ‡ Download installer
๐Ÿง

easysiem-server.deb

Debian/Ubuntu ยท amd64

ingest-api + the detect-engine as systemd services (not OpenSearch/Grafana โ€” see Linux Server above). Runs as a dedicated unprivileged account.

โฌ‡ Download .deb
๐Ÿง

easysiem-agent.deb

Debian/Ubuntu ยท amd64

The Linux agent as a systemd service โ€” ships journald and auditd events to an EasySIEM server. See Linux Agent above for setup.

โฌ‡ Download .deb
๐Ÿ“ฆ

Source code

.zip ยท full repo

Agents, ingest-api, the detect-engine, install scripts, and full docs (SETUP.md, DEFENDER.md, SECURITY.md) โ€” for building agents yourself or customizing the server.

โฌ‡ Download source