Splunk is the dominant SIEM platform. It’s powerful, ubiquitous in enterprise, and offers a free tier.
Splunk’s core: ingest data, parse it, search it. You upload logs, Splunk indexes them, and you search with SPL (Splunk Processing Language).
The free version can ingest up to 500MB per day, which is enough to learn on.
Part of the free Intro to Cyber course by Cover6 Solutions.