Skip to content

Logging & SIEM

Forwarders and dashboards are fully offline. The multi-GB SIEM servers ship as compose files you pull once, by design — see limitations.

Fluent Bit

service

Lightweight log/metrics forwarder — the workhorse shipping side.

Grafana

service

Dashboards for anything with a datasource — Loki included.

Vector

system

Observability data pipeline — route logs/metrics between anything.

Loki

binary

Grafana's log-aggregation backend, indexed by label not full text.

Splunk Universal Forwarder

manual

Requires a splunk.com login, so it can't be fetched during the build.

Elastic + Kibana

compose

Not pre-pulled (multi-GB images) — a ready compose file is staged instead.

OpenSearch + Dashboards

compose

Same policy as Elastic — staged compose, pulled on demand.

Wazuh

compose

Open-source XDR/SIEM. Upstream's own compose changes per release, so it's fetched fresh rather than pinned stale.

Graylog

compose

Log management on Mongo + OpenSearch — staged compose, pulled on demand.

Arkime

compose

Full packet-capture search-and-analysis system.