OpenFrame SIEM logo

OpenFrame SIEM

Security Information and Event Mgmt. (SIEM)

OpenFrame Selected
Self-hosted
OpenMSP Score
0
5
Reddit Impact Score
Github Score
341K
60Stars
18Forks
2KCommits
OtherLicense
Jun 8, 2026Last commit
OpenFrame SIEM is the security event and log management layer of the OpenFrame platform. It centralizes events from across the MSP stack into a single normalized event store, giving security teams one place to search, correlate, and investigate activity instead of moving between tool-specific consoles. The platform Logs screen aggregates data from every integrated OpenFrame tool in a normalized format, so events from RMM, endpoint telemetry, identity, and remote access share a common schema. Fleet and osquery queries are a primary source of high-fidelity endpoint data feeding the store. Core capabilities today center on high-volume event ingestion, normalization across heterogeneous sources, retention, and fast search and filtering across the unified log view, with multi-tenant separation so an MSP can manage many clients from one deployment. An AI-powered anomaly detection engine is on the roadmap, layering automated baselining and outlier detection on top of the aggregated data. It is not yet generally available, so today the product is best understood as a normalized aggregation and search layer rather than a full detection-and-response SIEM. OpenFrame SIEM runs as part of the self-hostable OpenFrame core and shares the single OpenFrame data fabric, so log and event data sits alongside RMM, PSA, and remote access rather than in a siloed tool, with no per-seat licensing.

Key Features

Unified Event Store

Aggregates events from every integrated tool into one normalized, searchable database.

Normalized Log Aggregation

Events from RMM, endpoints, identity, and remote access share a common schema in the Logs screen.

Fleet and osquery Telemetry

High-fidelity endpoint data from Fleet and osquery queries feeds the event store.

Centralized Logs Screen

One place to search, filter, and investigate activity across the whole stack.

High-Volume Ingestion and Retention

Collects and retains large volumes of event data for investigation and compliance.

Multi-Tenant Monitoring

Client isolation so MSPs can monitor many tenants from a single deployment.

Pros and Cons

Pros

Single Normalized Event Store

Aggregates and normalizes data from all integrated tools, removing console-hopping.

Strong Endpoint Data Source

Fleet and osquery queries provide rich, structured endpoint telemetry.

Self-Hosted, No Per-Seat Fees

Runs in the OpenFrame core with full control over security data.

Unified With the Wider Platform

Shares a data fabric with RMM, PSA, and remote access instead of a siloed SIEM tool.

Multi-Tenant by Design

Manage many clients from one deployment.

Cons

Anomaly Detection Not Yet Available

AI-based detection is on the roadmap; today the focus is aggregation and search.

Fewer Built-In Detections

Lacks the large prebuilt rule and correlation libraries of mature SIEMs.

Newer Product

Less battle-tested than established SIEM platforms, with fewer references.

Requires the OpenFrame Platform

Most value comes when used inside the broader OpenFrame stack.

Self-Hosting Overhead

Self-hosted deployments need infrastructure and storage planning for event volume.

Feature Comparison

Comments

No Comments Yet

Be the first to share your experience with OpenFrame SIEM.