This is built upon OSSec[1]. While it works ok, with Elastic underneath it's far too much maintenance for my 30 servers.
[1] - https://www.ossec.net/
[1] - https://www.ossec.net/
I run an in-house deployment using the Docker conf they supply. It requires a couple of hours per month and mainly a lot of disparate skills.
The real thing that takes time is the installation and configuration of the rules and agents. That’s something that you have to do for any SIEM really, irrespective of open source / paid: you have to understand your nominal feed and that takes time.