Two genuinely free detection labs compared — which SIEM stack, setup path, and learning curve fits your team
Choose Splunk Attack Range if your team already lives in Splunk and you want detection engineering practice that maps directly to your production workflow. Choose Security Onion if you want to learn blue-team detection from first principles, build a full network monitoring stack, and are comfortable with Linux administration.
I have deployed both for different teams. Splunk Attack Range is a force multiplier for Splunk shops — it makes your existing investment more valuable. Security Onion is an education platform disguised as a tool — the learning is in building it, not just using it.
| Factor | Splunk Attack Range | Security Onion |
|---|---|---|
| License cost | $0 (Apache 2.0) | $0 (GPL) |
| Hosting cost | $50–200/mo (AWS/Azure) | $50–150/mo (cloud) or $500–1,500 (hardware) |
| SIEM stack | Splunk Enterprise | Elasticsearch + Kibana + HELK |
| Setup time | 2–4 hours (Terraform-experienced) | 15–25 hours (Linux-comfortable) |
| Network detection | Basic (via Splunk add-ons) | Enterprise-grade (Zeek + Suricata) |
| Attack scenarios | Atomic Red Team included | None (bring your own) |
| Endpoint visibility | Limited (Sysmon via forwarder) | Full (Osquery + Wazuh + Sysmon) |
| Maintenance | 2–4 hrs/month | 4–8 hrs/month |
| Skill transfer | Splunk-specific | General detection engineering |
Splunk Attack Range is purpose-built for one job: generating realistic attack telemetry that feeds into Splunk. It is not a general-purpose SOC lab — it is a Splunk-specific training environment. If your production SOC runs on Splunk, the skills your analysts build here transfer immediately.
Security Onion is a complete Linux distribution for network security monitoring. It bundles Zeek (network metadata), Suricata (IDS), Osquery (endpoint visibility), Wazuh (host intrusion detection), and Elasticsearch/Kibana (log management) into a single installable platform. When paired with HELK, it becomes a threat hunting and detection engineering powerhouse.
First-year cost reality: Both are "free" software but not free to operate. Splunk Attack Range costs ~$6,000–8,000/year (AWS + labor). Security Onion costs ~$10,000–15,000/year (hardware/cloud + labor). Compare to RangeForce at $6,000–12,000/year with zero maintenance. The "free" option is only cheaper when you have surplus engineering time.
Advanced teams often use both: Security Onion for network detection and threat hunting practice, Splunk Attack Range for Splunk-specific detection rule testing. The two stacks complement each other — Security Onion gives you the full network picture, while Splunk Attack Range gives you the SIEM-specific workflow. Total cost: ~$12,000–20,000/year in hosting and labor — still cheaper than most commercial platforms, but only if you have the staff to maintain both.
I help teams map their existing tools, technical capacity, and training goals to the right free or low-cost lab infrastructure.
Work With Todd →