cisagov/LME
Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting, helping small to medium-sized organizations secure their infrastructure. LME Docs can be found at https://cisagov.github.io/lme-docs/docs/ observed · 2026-08-28
Health v2 · maintenance only
10/100
- Activity 83
- Release rhythm 72
- Longevity 75
Flags: archived no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 65.5
- age_days: 1062
- days_rel: 110
- days_push: 103
- n_releases_24m: 9
Adoption not part of the score
1441 stars · 159 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
CISA's Logging Made Easy (LME) is a free, open-source log management and threat detection platform that bundles Elasticsearch, Kibana, Wazuh, and ElastAlert to centralize log collection and provide real-time alerting. It is designed for small to medium-sized organizations without an existing SOC or SIEM, deployed via Ansible and Podman containers.
Use cases
- set up a free siem for a small business
- centralize windows sysmon and network logs
- get real-time alerts for malicious activity on my network
- deploy log management without a security operations center
- monitor endpoints for threats on a limited budget
- build custom security dashboards with kibana
- replace paid siem with open source logging
When to choose
- you are a small or medium organization with no existing SIEM or SOC
- you need a no-cost, self-hosted log management and threat detection stack
- you want pre-integrated Elasticsearch, Wazuh, and ElastAlert with automated Ansible deployment
- you need locally run logging where no third party can access your data
When to avoid
- you need actively maintained software - CISA retired support effective May 22, 2026
- you already run a full SIEM or SOC with mature tooling
- you need large-enterprise scale log ingestion beyond a small/medium deployment
- you require vendor support or SLAs
Facets
application · maturity maintenance
logging monitoring alerting security data-visualization deployment security monitoring self-hosted self-hosted cli siem elk-stack wazuh elastalert kibana zeek sysmon threat-detection log-management cisa podman ansible small-business-security devops linux docker
10 sources
- readme: https://github.com/cisagov/LME · fetched 2026-08-28 · 3e54be08e623
- homepage: https://www.cisa.gov/resources-tools/services/logging-made-easy · fetched 2026-08-29 · 6abe16686403
- site_page: https://www.cisa.gov/about · fetched 2026-08-29 · 46b39cd497d8
- site_page: https://www.cisa.gov/about/divisions-offices · fetched 2026-08-29 · e90d4b26e2a4
- site_page: https://www.cisa.gov/about/regions · fetched 2026-08-29 · b5723310e002
- site_page: https://www.cisa.gov/about/leadership · fetched 2026-08-29 · ae28fd113963
- site_page: https://www.cisa.gov/about/doing-business-cisa · fetched 2026-08-29 · 582c57d633b2
- site_page: https://www.cisa.gov/about/cisa-central · fetched 2026-08-29 · 167294190ec7
- site_page: https://www.cisa.gov/about/contact-us · fetched 2026-08-29 · cc8295ea668a
- site_page: https://www.cisa.gov/about/contact-us/subscribe-updates-cisa · fetched 2026-08-29 · 44890ece1e2d
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| cisagov/LME | main | 10 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem