UTMStack

The open source SIEM priced by device, not by data volume

UTMStack checks every log the moment it arrives, cuts the noise, responds automatically and gives your auditor evidence from your own logs. Run it in our cloud or on your own servers.

Prefer your own servers? Install the free open source edition or ask for a license quote

organizations run UTMStack, open source and paid
4,000+
organizations run UTMStack, open source and paid
building UTMStack, since 2018
8 years
building UTMStack, since 2018
detection rules mapped to MITRE ATT&CK
600+
detection rules mapped to MITRE ATT&CK
compliance frameworks scored continuously
9
compliance frameworks scored continuously
built-in integrations, plus any syslog or API source
30+
built-in integrations, plus any syslog or API source

Trusted by government, public safety, education, finance and technology teams in 26 countries

  • Steinway & Sons, Germany
  • Ministerio de Hacienda, Chile
  • Wolters Kluwer, Hungary
  • Eastern National Bank, United States
  • Konica Minolta, France
  • Bomberos de Quito, Ecuador
  • Kyocera, United States
  • Comfandi, Colombia
  • THQ Nordic, Austria
  • Duoc UC, Chile
  • Cluj International Airport, Romania
  • Universidad Católica Silva Henríquez, Chile
  • NCBA Bank, Kenya
  • SERCOTEC, Chile
  • Gwinnett County, United States
  • Bayport, South Africa
  • TIME dotCom, Malaysia
  • ISSPOL, Ecuador
  • U.S. Department of State, United States
  • Afriland First Bank, Cameroon
  • BMKG, Indonesia
  • Conn-Selmer, United States
  • Ministry of Finance of Mongolia, Mongolia
  • Azzorti, Colombia
  • Mohammed V University, Morocco
  • OneDome, United Kingdom
  • Scan Computers, United Kingdom
  • City of Dunedin, United States
  • SOLCA, Ecuador
  • Alivi, United States
  • Lungarotti, Italy
  • Veritas Data Research, United Kingdom
  • Seven-Up Bottling Company, Nigeria
  • IDscan, United States
  • Citrus County Clerk of Court, United States
  • UCFB, United Kingdom
  • Theraskin, Brazil
  • Uganda Christian University, Uganda
  • O2Nexus, Malaysia
  • Western Nebraska Community College, United States
  • BorneoCR, Costa Rica
  • Onicorn, Turkey
  • Q Management, Bulgaria
  • Sefti Mimarlık, Turkey
  • Adventure India, India
  • GEAR, Colombia
  • SIA Banga, Latvia
  • Pro Vape, Latvia

This is the real UTMStack console

Running on sample data from a fictional company. Click the tabs, the sidebar, or ask the assistant a question.

UTMStack · Overview
UTMStack
3MR

Want the whole product? The live demo opens every screen in a full browser window, with sample data and no sign-up.

What each screen shows
  • Overview: Alert, incident and playbook counters, event volume per data source, top MITRE ATT&CK techniques, most targeted assets, compliance scores and system health, with a question box for the AI assistant.
  • Threats: Alerts with severity, status, MITRE technique, source and target, filtered by status and severity.
  • Multi-tenancy: One card per customer with users, data sources, open alerts and AI usage, for service providers running many customers from one server.
  • Response flows: The SOAR flows list with each flow’s activity and on/off switch, and the canvas a flow opens on, where an alert match runs enrichment, endpoint commands, HTTP calls, notifications and incident creation.
  • AI assistant: The SOC-AI chat, answering questions about alerts and incidents with tool steps, tables and diagrams.
  • Log search: Log Explorer with free-text and SQL search over hot and cold data.
  • Compliance: Compliance frameworks with their scores; each opens a report with control status and evidence.
  • Threat intel: Indicator lookups, threat actors and feed matches from ThreatWinds threat intelligence, plus a research workspace that investigates an indicator and gives a verdict.

One platform and one price for the whole job

UTMStack replaces the log tool, the response tool, the compliance tool and the threat intelligence feed you would otherwise buy and connect separately. Each screen below is the real product; try it.

Predictable pricing

Turn on every log source. Your bill stays the same.

Most security monitoring tools charge for the data you send them, so teams switch off noisy sources to stay on budget and lose sight of attacks. UTMStack is priced by the number of devices you watch, so a busy week, an incident or a chatty firewall does not change what you pay.

  • Priced by device, never by gigabyte. A firewall that sends millions of events a day counts as one device.
  • Correlation, response flows, threat intelligence, the AI assistant and compliance reports come in every cloud plan.
  • Run it in our cloud as a subscription or on your own servers with a license, both priced by device. Or start free with the open source edition.

Log volume, events per hour

1,204,880

Your monthly price

Fixed

Log volume during an incident

Up to 3 times higher

Change to your bill

No change

An illustration: hourly log volume rises and falls, and triples during an incident, while the price, set by the number of devices you monitor, stays the same.

Less alert noise

Fewer alerts, and the ones left are real

UTMStack checks each event against 600+ detection rules the moment it arrives, before it is stored. Alerts show up in seconds, already deduplicated, scored and tagged with the MITRE ATT&CK technique and the assets involved, and the AI assistant takes the first look so a small team can keep up.

See threat detection: Fewer alerts, and the ones left are real
  • Tagging rules mark known false positives so analysts only see what matters
  • Rule flood guard switches off a noisy rule and tells you why
  • The SOC-AI assistant triages an alert, explains it and suggests the next step
UTMStack · Alerts
The Alerts screen: alerts with status, MITRE ATT&CK technique, source, adversary and severity. Opening one shows the parties involved, the raw events, an AI assessment and the actions an analyst can take.

Threat intelligence

Know who is behind an alert before you respond

Every event is checked against ThreatWinds threat intelligence as it arrives. Look up any IP address, domain, URL, file hash or CVE, or hand an indicator to the research workspace: it gathers reputation, related infrastructure and past sightings, then gives a verdict with the evidence behind it.

Explore threat intelligence: Know who is behind an alert before you respond
  • Reputation, accuracy, tags and first and last sightings for every indicator
  • A relationship graph of linked addresses, domains and file hashes
  • Threat actor profiles and matches against your own data
UTMStack · Threat Intelligence
The Threat Intelligence screen: indicator lookups, threat actors, feed matches, and a research workspace that investigates an indicator and returns a verdict with its dossier and relationship graph.

Built-in response

Response is built in, not a second purchase

Draw response flows on a canvas. Start from an alert, enrich it with threat intelligence or an AI step, run a command through the endpoint agent, call any API, open an incident and notify the team. Every run is recorded in the execution history.

See automated response: Response is built in, not a second purchase
  • Isolate a host, kill a process, log a user off or block an IP in seconds
  • An interactive console to run commands on any agent
  • Edit flows on the canvas or as code
UTMStack · SOAR Flows
A response flow on the canvas: a VPN brute-force alert triggers an AI check of the source address, a firewall ban and a notification to the team, with success and error paths. Close it to see every flow in a list with its on/off switch.

Audit evidence

Give auditors evidence, not screenshots

UTMStack works out on its own whether you meet each control. It already reads your logs, so it can see whether sign-ins use multi-factor authentication, whether disks and connections are encrypted, whether audit logging is on and who holds privileged access, and it marks each control compliant or not for every regulation that asks for it.

  • More than 600 controls are checked automatically, from multi-factor sign-ins and encryption to audit logging, privileged access and antivirus changes.
  • Controls are built on the NIST SP 800-53 library, so one check answers that control in every framework that requires it, from HIPAA and PCI DSS to CMMC and GDPR.
  • Reviewers can confirm or override any result with a reason, and the report exports as PDF for your auditor.
HIPAAPCI DSS 4.0CMMC 2.0GDPR

HIPAA

64 of 68 requirements met

Checked from your own logs

  • Multi-factor authentication§164.312(d)

    All 312 console sign-ins used MFA

    Compliant
  • Disk encryption§164.312(a)(2)(iv)

    BitLocker on, no setting changes on 48 hosts

    Compliant
  • Encrypted connections§164.312(e)(1)

    TLS handshake errors from 2 clients on api-prod-01

    At risk
  • Audit logging§164.312(b)

    Event log service running on every host

    Compliant

HIPAA report

Every control, its status and the logs that decided it

Download PDF
An illustration: UTMStack reads the logs behind each control, such as MFA on sign-ins or disk encryption, decides whether the control is met under each regulation's own clause, and updates the score and the report.

Switching

Switching from another SIEM?

You do not have to rebuild everything. Keep sending logs the way you do today, start with detection rules, response flows and compliance reports that work on day one, and move each source at your own pace.

  • Ready on day one: 600+ detection rules, response flows and compliance reports, installed in about 30 minutes
  • 33 built-in integrations, plus syslog (CEF and LEEF), the UTMStack agent and an HTTP intake for anything else
  • Open source under AGPL-3.0, so you are never locked in
UTMStackAlerts in secondsAutomated responseAudit evidence
Agents, syslog and cloud connectors bring in the logs you already collect; UTMStack correlates them as they arrive and turns them into alerts, response and audit evidence.

Run it the way your team works

Same platform, three ways to run it. Move between them as you grow.

Built to grow with you

  • Add nodes as you grow

    Every node runs the whole platform: storage, correlation and the console. Add a node and capacity grows on its own.

  • Proven at 12,000 devices

    Our largest single deployment watches 12,000 devices.

  • More logs, same price

    Plans grow with the number of devices. More logs from the same devices never raise your cloud bill.

  • A year of searchable logs

    Cloud plans keep about a month of logs in fast storage and a year in a searchable archive, with longer retention on request.

Your data, protected

  • A dedicated instance

    Each cloud customer gets an instance of their own, never a slice of a shared one.

  • Hosted on OVHcloud

    In data centers certified to ISO/IEC 27001, 27017 and 27018.

  • Your choice of region

    Run in the United States, Canada, the United Kingdom, France or Poland.

  • Locked-down access

    Every connection is encrypted, and our engineers reach production only through a VPN with multi-factor sign-in.

Recognized and open

8 years building UTMStack, an open source platform anyone can read, run and audit.

Linux Foundation silver memberBBB Accredited Business, A+ rating. Open the BBB profile.
“HancoCyber powered by UTMStack transformed how we approach cybersecurity. Their expertise ensures our clients’ intellectual property remains protected at all times.”
HancoCyber, Managed security partner

In the news

Questions buyers ask

How much does UTMStack cost?

The open source edition is free. UTMStack Cloud subscriptions and self-hosted Enterprise licenses are both priced by the number of devices you monitor, never by log volume. Tell us how many devices you have and how you want to run UTMStack, and we will send a quote within one business day, directly or through a partner near you.

Do you charge for log volume?

No. Plans are sized by number of devices, not by gigabytes ingested, so a busy week or an incident does not change your bill. A device is any individual log source, such as a server, a workstation agent, a firewall or a cloud account; a console that collects from many machines, such as Microsoft 365 or an antivirus console, counts as one.

How long is data kept, and can I search old logs?

Cloud plans keep about one month of logs in fast storage and archive older logs for a year. Archived logs stay searchable in Log Explorer without a restore. Longer retention is available on request, and on your own servers you choose the retention.

Where does my data live, and how is it protected?

UTMStack Cloud runs on OVHcloud. Each customer gets a dedicated instance in the region they choose: the United States, Canada, the United Kingdom, France or Poland. OVHcloud data centers are certified to ISO/IEC 27001, 27017 and 27018. Every connection is encrypted, and our engineers reach production systems only through a VPN with multi-factor sign-in. If you run UTMStack on your own servers, your logs never leave your network.

How does UTMStack scale?

UTMStack scales out. Every node runs the whole platform (storage, correlation and the console), and adding nodes to a cluster adds capacity on its own. Our largest single deployment watches 12,000 devices. Book a call and our engineers will size the nodes for your log volume.

How long does it take to get running?

A self-hosted install takes about 30 minutes on Ubuntu or a Red Hat compatible server. Detection rules, response flows and compliance reports work from the first day, and agents, syslog and cloud connectors start sending logs within minutes of setup.

Can I switch from my current SIEM without losing coverage?

Yes. Most teams point their existing log sources at UTMStack (agents, syslog with CEF or LEEF, cloud connectors or the HTTP intake) and run both tools side by side until they are confident. Book a call and our engineers will help you plan the move source by source.

What support do I get?

Cloud and Enterprise customers get support by ticket and chat from the engineers who build UTMStack, with round-the-clock options. Open source users get help from the community on GitHub, and anyone can add our analysts through the SOC extension service.

Protect your organization this week, not next quarter

Talk to an engineer today, or start using UTMStack in minutes.

Need to extend your SOC team?

Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.

Want to try UTMStack?

Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.