Kibana and Graylog on top of elastic/opensearch. Even the commerical licenses on those are usually a tiny fraction of splunk's costs, and Graylog does enough for free that it's a much easier path to stand that up and then buy the correlation functionality if you really need it.
For some organizations what Splunk does well is important but for most of them they really only need much more basic log aggregation and analysis tools.