The best open source alternative to Logstash is SigNoz. If that doesn't suit you, we've compiled a ranked list of other open source Logstash alternatives to help you find a suitable replacement. Other interesting open source alternatives to Logstash are: OpenObserve, HyperDX, GreptimeDB, and Maple.
Logstash alternatives are mainly Log Management Tools but may also be Performance Monitoring (APM) Tools or Infrastructure Monitoring Tools. Browse these if you want a narrower list of alternatives or looking for a specific functionality of Logstash.
Comprehensive monitoring and troubleshooting solution for microservices architectures, offering metrics, traces, and logs in a single pane.

SigNoz is a powerful, open-source observability platform designed for modern, cloud-native applications. It provides a unified solution for monitoring, troubleshooting, and optimizing your microservices architecture.
Key benefits of SigNoz include:
All-in-One Observability: Combine metrics, traces, and logs in a single platform, eliminating the need for multiple tools and reducing context-switching.
Cost-Effective: As an open-source solution, SigNoz offers significant cost savings compared to proprietary alternatives, especially for high-volume data ingestion.
Easy Setup: Get started quickly with a simple installation process and intuitive UI, making it accessible for teams of all sizes.
Customizable Dashboards: Create tailored views of your system's performance with flexible, drag-and-drop dashboard builders.
Distributed Tracing: Gain deep insights into request flows across your microservices, helping you identify bottlenecks and optimize performance.
Anomaly Detection: Leverage built-in anomaly detection capabilities to proactively identify issues before they impact your users.
Scalability: Designed to handle high-volume data ingestion, SigNoz scales effortlessly with your growing infrastructure.
Open Standards: Built on OpenTelemetry, ensuring compatibility with a wide range of technologies and future-proofing your observability stack.
By choosing SigNoz, you're not just adopting a monitoring tool; you're embracing a comprehensive observability solution that grows with your needs and empowers your team to maintain high-performing, reliable applications.
Monitor logs, metrics, and traces with an open-source observability platform. Achieve petabyte scale with 140x lower storage costs and high performance.

OpenObserve is a comprehensive, open-source observability platform designed for logs, metrics, and traces. It offers a modern, scalable architecture built for high performance and significant cost savings. The platform's primary advantage is its efficiency, providing up to 140x lower storage costs when compared to alternatives like Elasticsearch. This is achieved through high data compression and a columnar storage format.
Key features include:
Open source observability platform unifying session replays, logs, traces, metrics and errors. Fast search, automatic clustering, $0.40/GB pricing.

Open source observability platform that unifies session replays, logs, traces, metrics and errors into a single view - all without the expensive Datadog price tag. Recently acquired by ClickHouse to accelerate open source observability innovation.
Key capabilities include:
Developer-friendly features:
Transparent pricing at $0.40 per GB with no per-user or per-host fees makes enterprise-grade observability accessible to teams of all sizes. Trusted by high-velocity engineering teams for resolving production issues fast.
Cloud-native observability database unifying metrics, logs, and traces with sub-second queries, 50x cost reduction, and seamless OpenTelemetry integration.

GreptimeDB is a cloud-native, real-time observability database that revolutionizes how organizations handle metrics, logs, and traces. Built for OpenTelemetry and modern cloud environments, it delivers sub-second query performance at petabyte scale while dramatically reducing operational complexity.
Key benefits include:
Trusted by companies like Li Auto (reduced traffic costs by 50%, storage costs by 98%), SGCC (2x write performance, 5x query performance), and others who have migrated from InfluxDB, Loki, and Thanos to achieve superior performance and simplified operations.
Observability platform built on OpenTelemetry and ClickHouse. Collect, visualize, and query distributed traces, logs, and metrics, with an MCP server for AI agent diagnostics.

Maple is an observability platform for distributed systems, built on OpenTelemetry and backed by ClickHouse for sub-second queries across billions of rows. It handles traces, logs, and metrics in one place, with correlated data across all three signals tied to a single trace ID. No stitching between tools, no second search in a second product.
The incident workflow is its sharpest edge. An alert arrives carrying the service, the broken threshold, and sample traces. From there you open the failing span tree, jump to correlated logs on the same trace ID, and see exactly what happened. Retry exhaustion, a full connection pool, three Stripe timeouts at 1.75 seconds each – all visible without switching tabs.
Key capabilities:
Compared to tools like HyperDX or Uptrace, Maple's first-class MCP surface is a genuine differentiator. The agent doesn't just read dashboards – it pulls the source file behind a failing span, so the fix it proposes cites your actual code. It can also write back: claim an issue, set severity, attach a fix.
The local mode runs as a single compiled binary with an embedded ClickHouse, OTLP ingest, query API, and dashboard – all on localhost, no account required. For production, you can self-host against your own ClickHouse or use the hosted plan at $39/month for 100 GB per signal, then $0.30/GB flat. No per-host fees. No per-seat fees.
The source is on GitHub under FSL-1.1, which converts to Apache 2.0 two years after each release. OpenTelemetry in means no proprietary agent and no re-instrumentation if you switch.
Unified platform for logs, metrics, traces and profiles with native compatibility for popular tools like OpenTelemetry, Prometheus, and Loki. No data silos, no usage limits.

A powerful observability platform that brings together logs, metrics, traces and profiles in one unified solution. Built on high-performance OLAP engines ClickHouse and DuckDB with NVMe storage, Gigapipe delivers exceptional speed and reliability.
Key advantages:
Perfect for engineering teams and DevOps professionals who need comprehensive observability without the complexity of managing multiple tools or worrying about data volume costs. Gigapipe's polyglot approach ensures you can work with your data your way, while the unified platform enables quick correlation between different data types for faster troubleshooting and deeper insights.
Open-source cookie banner, built for control and lightening fast modern web apps.
Get Started in 30 seconds