European Alternatives to Splunk

Looking for a European alternative to Splunk? Splunk is a Cisco company, and its General Terms are a contract with Splunk LLC, a Delaware company in San Jose, governed by California law with disputes brought exclusively in the federal or state courts of the Northern District of California.

Eleven European options cover log management and security monitoring, from Danish, Czech, French and British SIEM vendors to managed log and OpenSearch services and a German security data pipeline, from companies in Denmark, the Czech Republic, France, the United Kingdom, Finland, Switzerland, Germany and the Netherlands.

11 Alternatives
100% GDPR Compliant
How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect which tools appear here and the order they appear in. It never buys a good review: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect which tools appear here and the order they appear in. Editorial policy

11 European Alternatives to Splunk

Logmanager

Prague log management and light SIEM with a free 100 GB self-hosted tier and pricing by stored gigabyte

#1 for replacing Splunk
Czech Republic

Logpoint (Guardsix)

Copenhagen SIEM, NDR and SOAR sold as Guardsix, priced by nodes and entities under Danish law

#2 for replacing Splunk
Denmark

OVHcloud Logs Data Platform

Managed log platform on OpenSearch with Graylog and Grafana access, 14 days to 1 year retention

#3 for replacing Splunk
France

Scaleway Cockpit

Paris logs, metrics and traces on Grafana and Loki, EUR 0.35 per GB ingested for custom logs

#4 for replacing Splunk
France

Tenzir

Hamburg security data pipeline and lake with a free Community edition, aimed at SIEM cost and migration

#5 for replacing Splunk
Germany

SEKOIA.IO

Rennes SOC platform combining SIEM, threat intelligence and automated response, quoted on request

#6 for replacing Splunk
France

Aiven for OpenSearch

Managed OpenSearch with Dashboards and security analytics, Finnish law, with a free sandbox tier

#7 for replacing Splunk
Finland

Exoscale OpenSearch

Lausanne managed OpenSearch with Dashboards in every plan, billed by the second in European zones

#8 for replacing Splunk
Switzerland

TeskaLabs LogMan.io

Prague-built log management and AI SIEM from a UK company with a Czech branch, on-premises or managed

#9 for replacing Splunk
United Kingdom

Elastic

Dutch-incorporated Elasticsearch, Kibana and Elastic Security, with the contracting entity set on the order form

#10 for replacing Splunk
Netherlands

ITrust Reveelium

Labege XDR and SIEM platform with UEBA and threat intelligence engines, plus a managed SOC, quoted on request

#11 for replacing Splunk
France

Key takeaways

  • Splunk's General Terms are with Splunk LLC, a Delaware company in San Jose, under California law with exclusive venue in the Northern District of California.
  • Splunk Cloud, Enterprise and Security are priced "Get a quote" on the activity, workload or ingest model; only Observability Cloud publishes figures, from $15 per host per month.
  • All eleven European options on this page are run by companies registered in Denmark, the Czech Republic, France, the United Kingdom, Finland, Switzerland, Germany or the Netherlands, though the Elastic contracting entity is only named on the order form.
  • Five of the eleven let you try them without a sales call: Logmanager (free tier and trial), Tenzir (free Community edition), Aiven (free sandbox), Exoscale (free credit) and Scaleway Cockpit, which is on by default in every Scaleway project.
  • Nothing here speaks SPL, so every saved search, alert and dashboard has to be rewritten, and that rebuild is the real cost of leaving.

Why people leave Splunk

Splunk is a good product, and the case against it is mostly about the contract and the meter. Its General Terms, last updated in May 2026, are an agreement with Splunk LLC, a Delaware company in San Jose, California.

Section 23 puts the agreement under California law and sends any legal action to the federal or state courts of the Northern District of California. Splunk now describes itself as "a Cisco Company", so the party that holds your logs sits inside a large American group.

Logs are where personal data hides: usernames, IP addresses, email addresses in query strings, session identifiers. A log platform is also the system you will ask for evidence during an incident. If your auditor or your NIS2 programme asks who can compel access to that evidence, an answer that starts with a California court is a harder conversation than one that starts in Copenhagen, Prague, Paris or Hamburg.

The other reason is the shape of the bill. Splunk Cloud Platform and Splunk Enterprise are sold on activity, workload or ingest models, and the pricing page offers a quote rather than a rate.

Only Splunk Observability Cloud shows numbers, starting at $15 per host per month for infrastructure and $75 for the end-to-end tier. A price you cannot see before talking to sales is also a price you cannot compare, which is the first thing a European buyer on a tight procurement cycle wants to do.

  • The contract is American and so are the courts The General Terms are with Splunk LLC, 3098 Olsen Drive, San Jose, a Delaware limited liability company. They are governed by the laws of California, with exclusive venue in the Northern District of California. If you buy through a Splunk Affiliate Distributor instead, each order becomes a separate contract with that distributor, still subject to the General Terms. That is workable for a multinational with a US legal team. For a Dutch hospital or a Danish utility it is a clause you have to explain to your own board.
  • You cannot see the main price before you ask On Splunk's own pricing page, Cloud Platform, Enterprise and Security all read "Get a quote", with the choice of activity-based, workload or ingest pricing. Observability Cloud is the exception, from $15 per host per month billed annually. That makes a like-for-like comparison with a European tool a negotiation exercise rather than a spreadsheet. Several tools on this page publish a rate, or at least the unit they price on, so you can work out an order of magnitude before you book a demo.
  • Capacity is something Splunk can ask you to prove Section 11 of the terms lets Splunk request a signed certification that your use stays within the licensed Capacity, and for on-premises products to ask for reasonable access to the installation, including one hosted by your own third-party provider, to verify it. That is standard enterprise software practice, and it still means a vendor in California holds an audit right over a log platform you run inside your own network.
  • Your log platform is now a line in someone else's portfolio The pricing page sells Splunk Cloud, Enterprise, Security, Observability and AppDynamics as one portfolio, with "built-in value" for Cisco telemetry at a 0.5x weighted ingest rate. If you run Cisco networking, that is a discount. If you do not, it is a sign of where the roadmap is pulled. A smaller European vendor whose only product is the log platform has less reason to bend it toward a parent company's hardware.

What you have to replace, not just match

Splunk is a log search engine, a data platform, a SIEM and an observability suite in one brand, and no single European tool replaces all four. The useful split is by job rather than by logo.

If your Splunk is mainly a SIEM, the closest matches are Logpoint (sold as Guardsix), SEKOIA.IO, ITrust Reveelium, TeskaLabs and Logmanager, which bring correlation, detection content and incident handling.

If it is mainly log search and retention, a managed OpenSearch service from OVHcloud, Aiven or Exoscale, or Scaleway Cockpit, covers the search and dashboards part for far less ceremony. If your actual problem is ingest cost, Tenzir sits in front of any of them and lets you filter, enrich and route data before you pay to store it.

Three things Splunk does that nothing here replicates one for one: SPL, the query language your analysts and years of saved searches are written in; the app marketplace with thousands of ready-made add-ons; and the sheer size of the Splunk Enterprise Security content ecosystem. Plan for rebuilding saved searches and dashboards in a different query language.

The alternatives compared

European Splunk alternatives, in the order this page ranks them, compared on headquarters, pricing and jurisdiction
PositionToolHeadquartersPricingJurisdiction
#1 Logmanager Prague, Czech Republic Appliance licence by volume EU (Czech Republic)
#2 Logpoint (Guardsix) Copenhagen, Denmark Per node or per device licence EU (Denmark)
#3 OVHcloud Logs Data Platform Roubaix, France PostgreSQL essential from about €0.16/hour (2 vCPU / 8GB RAM); MySQL, MongoDB, Kafka, Cassandra, OpenSearch, M3DB and Valkey priced separately by engine and tier EU (France)
#4 Scaleway Cockpit Paris, France From about €0.0025/hour (DEV1-S) EU (France)
#6 SEKOIA.IO Paris, France SaaS subscription EU (France)
#7 Aiven for OpenSearch Helsinki, Finland Free tier for small services / from about $20/month, usage-based EU (Finland)
#8 Exoscale OpenSearch Lausanne, Switzerland From about CHF 5.50/month (Compute) Switzerland (adequacy decision, outside the EEA)
#10 Elastic Amsterdam, Netherlands Free tier / custom pricing EU (Netherlands)
#11 ITrust Reveelium Toulouse, France Custom quote (devis); on-premise or SaaS licensing, no published price list EU (France)

How each alternative compares to Splunk

#1

Logmanager

the one to try first if you want logs and a light SIEM without a procurement project

Prague, Czech RepublicAppliance licence by volume#8 in SIEM & Security Monitoring

  • Which law reaches it. EU (Czech Republic). Splunk is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Source code. Closed source, as Splunk is.

Best for: Small and mid-sized security teams that need log retention and compliance reporting

Logmanager a.s. is registered in Prague (company ID 04667115, Municipal Court in Prague, file B 21247), and the registry at ares.gov.cz confirms the entity. It describes itself as a log management and lightweight SIEM with more than 140 log sources, deployable as a virtual appliance on VMware, Hyper-V or Proxmox, or as a managed cloud service.

The pricing model is the reason it leads. The page says you pay for the log data you store each month, with no limits on daily data volume and unlimited users, and a free plan with 100 GB of storage is listed for the self-hosted version. That removes the daily ingest meter that makes Splunk sizing exercises painful. The page showed dollar amounts when fetched, so this page quotes no figure; check the price in your own currency.

It is positioned against ELK and Graylog on simplicity, with a claimed 30-minute virtual appliance deployment and a 7-day free trial without a credit card. It is a lightweight SIEM, not a full detection-engineering platform, so heavy correlation and SOAR work will need something else alongside it.

What Logmanager does better than Splunk

  • A free 100 GB tier listed on the pricing page, where Splunk Cloud and Enterprise core pricing is quote only
  • Pricing on stored gigabytes with no daily ingest cap, instead of the activity, workload or ingest models Splunk quotes
  • Unlimited users listed on the plans
  • Czech company in a public register, against a contract with Splunk LLC in California
  • Self-hosted or managed, with a deployment time measured in minutes rather than a project

Where Logmanager is a step down from Splunk

  • Lightweight SIEM only, with far less detection content than Splunk Enterprise Security
  • No equivalent of SPL or the Splunk app marketplace
  • The pricing page showed dollar amounts, so the price in your currency has to be confirmed
  • Hosting location of the managed cloud service is not stated on the pages checked

Standout against Splunk. It is the only option here that pairs a published free tier with pricing on stored data rather than on ingest.

logmanager.com Visit Logmanager
#2

Logpoint (Guardsix)

the closest like-for-like SIEM, from a Danish company

Copenhagen, DenmarkPer node or per device licence#1 in SIEM & Security Monitoring

  • Which law reaches it. EU (Denmark). Splunk is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Source code. Closed source, as Splunk is.

Best for: Security teams that want a full SIEM with NDR and SOAR under European law

Logpoint now trades as Guardsix. The old logpoint.com legal page redirects to guardsix.com/legal, where the entity is Guardsix A/S, registration DK-26301939, at Valkendorfsgade 13A in Copenhagen. Its website terms are governed by the laws of Denmark with exclusive jurisdiction for the Danish courts. This page did not check the separate customer agreement.

The product range maps onto the Splunk security stack more directly than anything else here: Guardsix SIEM, NDR, SOAR, Fleet and Governance. The pricing page sets out four tiers named Govern, Detect, Defend and Respond, and says pricing depends on the number of nodes, devices or entities, the products you choose and your service level. There is no price, only "Get a quote".

The node and entity basis is the interesting point against Splunk. It does not charge for a noisy log source, so adding a firewall or a chatty application does not change the invoice the way ingest pricing does. The flip side is that large estates with many small devices can add up, and you will want to count entities carefully before you sign.

What Logpoint (Guardsix) does better than Splunk

  • Pricing by nodes, devices or entities rather than by data volume, so a noisy source does not raise the bill
  • SIEM, NDR and SOAR products under one Danish company and one pricing model
  • Contract terms on the website under Danish law and Danish courts, instead of California
  • Positions on-premises deployment and data sovereignty as selling points rather than add-ons

Where Logpoint (Guardsix) is a step down from Splunk

  • No published price, only a quote
  • Smaller content and integration ecosystem than Splunk Enterprise Security
  • Rebranded from Logpoint to Guardsix, so older documentation and integrations may use the earlier name
  • Entity counts need care on large estates

Standout against Splunk. It is the only option here that sells a SIEM, a network detection product and SOAR from one European vendor on a flat node basis.

#3

OVHcloud Logs Data Platform

the managed log store for teams that want OpenSearch without running it

Roubaix, FrancePostgreSQL essential from about €0.16/hour (2 vCPU / 8GB RAM); MySQL, MongoDB, Kafka, Cassandra, OpenSearch, M3DB and Valkey priced separately by engine and tier#8 in Databases & Backends

  • Which law reaches it. EU (France). Splunk is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. 30+ data centres, majority in Europe.
  • Source code. Closed source, as Splunk is.
  • Independently checked. SecNumCloud (ANSSI), GAIA-X founding member.

Best for: Operations and platform teams searching application and infrastructure logs at moderate scale

Logs Data Platform is OVHcloud's managed log service, built on the OpenSearch ecosystem. It accepts GELF, syslog, Cap'n Proto, LTSV and RFC 5425, offers OpenSearch Dashboards, Graylog and Grafana access, supports retention from 14 days to a year with cold storage options, and includes alerting. The contracting company behind the site is OVH SAS, and the French business register lists OVHCLOUD at 2 rue Kellermann, Roubaix, SIREN 424761419.

It is a log store and search tool, not a SIEM. There is no built-in detection content, so if you used Splunk mainly for operations searches and dashboards it fits well, and if your security team lived in Enterprise Security it does not.

The page states ISO 27001, 27017 and 27701 certification and a pay-as-you-go model with a standard and an enterprise plan. Prices on the page depend on the storefront country, so none is quoted here, and the hosting regions were not itemised on the page we read.

What OVHcloud Logs Data Platform does better than Splunk

  • Standard OpenSearch, Graylog and Grafana interfaces, so your tooling is portable
  • Pay-as-you-go with a published enterprise option, against Splunk's quote-only core products
  • French company with ISO 27001, 27017 and 27701 stated on the product page
  • Retention from 14 days to a year, plus cold storage options

Where OVHcloud Logs Data Platform is a step down from Splunk

  • No SIEM content, correlation rules or case management
  • Not SPL, so saved searches must be rewritten
  • Price shown varies by country, so a budget needs a quote from your own storefront
  • Region details and sub-processors were not checked on the page

Standout against Splunk. It is the only log service here that hands you Graylog and OpenSearch Dashboards as ordinary front ends on a managed store.

#4

Scaleway Cockpit

the cheapest way to get logs, metrics and traces if you already run on Scaleway

Paris, FranceFrom about €0.0025/hour (DEV1-S)#6 in Cloud Computing

  • Which law reaches it. EU (France). Splunk is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Paris, Amsterdam, Warsaw — EU only.
  • Source code. Closed source, as Splunk is.

Best for: Teams hosting on Scaleway, or developers who want a published euro rate for custom logs

Cockpit is Scaleway's observability service, built on Grafana for dashboards, Loki for logs, Mimir for metrics and Tempo for traces. The footer names Scaleway SAS and the business register lists SCALEWAY at 8 rue de la Ville l'Eveque in Paris, SIREN 433115904.

The pricing is stated plainly on the page. Metrics and logs from Scaleway resources are collected at no extra cost. Custom data from your own applications, including those running elsewhere, is billed at EUR 0.35 per GB for logs and traces and EUR 0.15 per million samples for metrics. Default retention is 31 days for metrics and 7 days for logs and traces, extendable up to five years, with charges only beyond the default.

It is a Grafana-and-Loki stack, so it handles operational log search well and security detection poorly. There is no SIEM layer, and its strongest case is for workloads that already run on Scaleway. If you search logs from a wide on-premises estate, the other managed stores here may fit better.

What Scaleway Cockpit does better than Splunk

  • Published euro rates for custom logs and metrics, where Splunk's core pricing is a quote
  • Collection from Scaleway resources at no extra cost
  • Open components, Grafana, Loki, Mimir and Tempo, so queries and dashboards are portable
  • Retention you can extend to five years without changing product

Where Scaleway Cockpit is a step down from Splunk

  • Seven days of log retention by default, shorter than many compliance needs
  • No detection rules, correlation or SIEM features
  • LogQL rather than SPL, so every saved search has to be rewritten
  • Value depends largely on already running workloads on Scaleway

Standout against Splunk. It is the only option here where the log rate, EUR 0.35 per GB, is printed on the product page next to the retention limits.

scaleway.com Visit Scaleway Cockpit
#5

Tenzir

the one that attacks the ingest bill instead of replacing the console

Best for: Teams whose main Splunk pain is the cost and noise of what they send into it

Tenzir GmbH is registered in Hamburg (Handelsregister Hamburg HRB 148081, Lilienstrasse 11, 20095 Hamburg), and its terms are governed by German law. The product is a pipeline engine and security data lake: it collects, normalises, enriches and routes data, with solution pages for SIEM migration, cost optimisation and a security data lake.

The pricing page lists a free Community edition with 1 TB per day of ingress and 1 TB of edge storage, an Enterprise edition and a Sovereign edition, the last two on request. That is a generous free entry point and a straightforward way to test whether filtering data before it reaches Splunk, or a replacement, would change your costs.

It is not a drop-in replacement for the Splunk search and dashboard experience. Think of it as the layer in front of a store or SIEM, which can also reduce what you pay a vendor like Splunk while you migrate piece by piece.

What Tenzir does better than Splunk

  • Free Community edition with 1 TB per day ingress and a published edition list, against quote-based core Splunk pricing
  • Normalises, enriches and routes data before storage, which cuts volume for any downstream tool
  • German GmbH in a public register with German-law terms
  • Useful during migration, since it can feed Splunk and a new platform at once

Where Tenzir is a step down from Splunk

  • Not a full search and dashboard product, so you still need a store or SIEM behind it
  • Younger and smaller than Splunk, with a far smaller community and content library
  • Enterprise and Sovereign pricing is not published
  • Needs engineers comfortable building pipelines

Standout against Splunk. It is the only option here that is explicitly designed to sit in front of Splunk and shrink what you send it.

#6

SEKOIA.IO

the one with detection content and threat intelligence included

Paris, FranceSaaS subscription#2 in SIEM & Security Monitoring

  • Which law reaches it. EU (France). Splunk is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Source code. Closed source, as Splunk is.

Best for: Teams without the capacity to write and maintain correlation rules themselves

Sekoia.io SAS is registered in Rennes (RCS 913 174 744, 28 boulevard du Colombier), with the legal notice updated 22 June 2026 and the registry listing SEKOIA.IO at the same address. The platform pairs a SIEM (Defend) with threat intelligence, an asset layer (Reveal) and an automation layer (Elevate), and the site has a dedicated "SIEM replacement" use case.

The pitch against Splunk is that detection content and threat intelligence are part of the platform rather than something you build and tune yourself on top of a search engine. Its security page states ISO 27001, SOC 2, PCI-DSS and Spain's ENS level Alta.

The homepage shows no price or free trial and directs you to a demo. It does not state where data is hosted on the pages read, so confirm region and sub-processors in the contract. Sekoia is a SaaS security platform, so it is not the right shape for teams that want a raw log search tool to query freely.

What SEKOIA.IO does better than Splunk

  • Detection content and threat intelligence come with the platform instead of being a build project
  • A French SAS in the commercial register, against a California contract
  • Markets a SIEM replacement path with SIEM, intelligence and automation in one product
  • Stated ISO 27001, SOC 2, PCI-DSS and ENS Alta compliance

Where SEKOIA.IO is a step down from Splunk

  • No published price and no free trial on the homepage
  • Data hosting regions not stated on the pages read
  • Less flexible for ad hoc log exploration than a general search platform
  • Smaller ecosystem of integrations and community content than Splunk

Standout against Splunk. It is the only option here that bundles an in-house threat intelligence function into the SIEM itself.

sekoia.io Visit SEKOIA.IO
#7

Aiven for OpenSearch

the managed OpenSearch to choose if you want a Finnish-law contract and a free sandbox

Helsinki, FinlandFree tier for small services / from about $20/month, usage-based#1 in Databases & Backends

  • Which law reaches it. EU (Finland). Splunk is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Your chosen region, including EU-only.
  • Source code. Closed source, as Splunk is.
  • Independently checked. Services are open source.

Best for: Engineering teams that want OpenSearch with security analytics and no cluster to run

Aiven's OpenSearch page lists log analytics as a main use case, with OpenSearch Dashboards, full-text search, real-time queries and a security analytics plugin. The terms are governed by Finnish law with arbitration in Helsinki under the Finland Chamber of Commerce rules, and the Finnish registry lists Aiven Oy under business ID 2795743-5. The terms themselves name the provider only as "Aiven", so confirm the entity on your order form.

There is a free sandbox tier, a developer plan, a startup plan and a business plan, all shown in dollars when fetched, with networking and data transfer bundled and a 99.99 percent SLA stated. We quote no price here.

The caveat that matters for this page is that Aiven runs "on any cloud". You choose a region on a provider that may be a US hyperscaler, so the European contract does not by itself mean the data stays on European-owned infrastructure. Choose the cloud as well as the region.

What Aiven for OpenSearch does better than Splunk

  • A free sandbox tier for testing without a quote
  • Finnish-law terms with arbitration in Helsinki
  • Bundled networking and data transfer in the plan price, which avoids a surprise line
  • Same open OpenSearch API and Dashboards, so your queries are portable

Where Aiven for OpenSearch is a step down from Splunk

  • Runs on third-party clouds, including US hyperscalers, so hosting is your choice to make
  • Contracting entity not named in the terms we read
  • No SIEM content of its own beyond the OpenSearch security analytics plugin
  • Not SPL, and not a log-first product like Logmanager

Standout against Splunk. It is the only OpenSearch service here that lets you pick the underlying cloud, which is both its strength and the thing to check.

#8

Exoscale OpenSearch

the managed OpenSearch from a Swiss supplier with dashboards in every plan

Lausanne, SwitzerlandFrom about CHF 5.50/month (Compute)#4 in Cloud Computing

  • Which law reaches it. Switzerland (adequacy decision, outside the EEA). Splunk is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Switzerland, Germany, Austria, Bulgaria.
  • Source code. Closed source, as Splunk is.

Best for: Teams wanting a simple, per-second-billed OpenSearch cluster in European zones

Exoscale's terms define the Supplier as Akenes SA, Boulevard de Grancy 19A, 1006 Lausanne, Switzerland. That is the contracting company, and Switzerland sits outside the EU but inside this directory's scope. The page describes managed OpenSearch with OpenSearch Dashboards included in every plan, automated lifecycle management, daily backups, TLS in transit and encryption at rest.

It states that data is hosted in European zones and bills by the second, with four plan families, from a Hobbyist plan to Business and Premium clusters. New accounts receive free credit. The page shows euro prices per hour, but we quote none because plan tables change.

This is a search and dashboard service. It is a good fit for log search and operations analytics and has no detection content, correlation engine or case management. If your use of Splunk was security heavy, pair it with a SIEM.

What Exoscale OpenSearch does better than Splunk

  • Published hourly rates in euro and per-second billing, against Splunk quotes
  • OpenSearch Dashboards included in every plan
  • A Swiss supplier named in the terms, with European zones stated
  • Free credit on registration to test with real logs

Where Exoscale OpenSearch is a step down from Splunk

  • No SIEM or detection content, only search and dashboards
  • Retention and ingest are your own design, with no log-specific features such as tiered archives
  • Smaller managed OpenSearch offering than Aiven in plugins and clouds
  • Not SPL, so saved searches must be rewritten

Standout against Splunk. It is the only option here billed by the second, with dashboards bundled into every plan.

#9

TeskaLabs LogMan.io

the one that scales from a compliance log archive up to an AI SIEM

Best for: Organisations that start with NIS2-driven log archiving and want a path to a SIEM

TeskaLabs' privacy policy names TeskaLabs Ltd, 124 City Road, London, acting through a branch office in Prague. Companies House lists TESKALABS LTD, number 08893495, incorporated on 13 February 2014. So the contracting company is British, and the company says its engineering, support and operations are in the Czech Republic.

The product ladder is unusual: LogMan.io Lite for tamper-proof, signed log archiving, which it says a certified court expert verified as NIS2 compliant, LogMan.io for large-scale collection and analysis, LogMan.io PLUS for correlation and alerting, and the LogMan.io AI SIEM. It runs on-premises, air-gapped or as a managed service, with a data centre in the Czech Republic.

There is no price list on the pages read, only an EPS calculator, so costs need a conversation. It is a smaller vendor than Splunk with a smaller partner ecosystem, but the stepwise approach suits teams that do not need a full SIEM on day one.

What TeskaLabs LogMan.io does better than Splunk

  • A tiered path from log archive to AI SIEM, rather than buying the whole suite at once
  • On-premises and air-gapped deployment, which Splunk Enterprise also supports, plus a managed option
  • Tamper-proof, signed log archiving as an entry product for compliance
  • Companies House registration in a public register, against a California contract

Where TeskaLabs LogMan.io is a step down from Splunk

  • No published prices, only an EPS calculator
  • Contracting entity is a UK company with a Czech branch, so check which entity signs your order
  • Small vendor with a small integration and community ecosystem
  • Claims on AI SIEM capability are vendor statements we could not test

Standout against Splunk. It is the only option here that starts at a signed, tamper-proof log archive and grows into a SIEM.

#10

Elastic

the nearest functional match to Splunk, with a contracting entity you have to check

Amsterdam, NetherlandsFree tier / custom pricing#1 in Monitoring & Observability

  • Which law reaches it. EU (Netherlands). Splunk is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Self-hosted, or Elastic Cloud in EU regions.
  • Source code. Open source, where Splunk is not: you can read what it does rather than take the description on trust.
  • Independently checked. GDPR.

Best for: Teams with engineers who want a search engine, SIEM and observability on one open stack

Elastic is the most direct functional alternative to Splunk on this page: Elasticsearch for search, Kibana for dashboards, and Elastic Security for detection. The privacy statement is issued by Elastic N.V. and its subsidiaries, and the website terms by Elasticsearch B.V. You can run the software yourself or buy Elastic Cloud.

It sits last in the ranking for one reason. The Elastic Cloud subscription agreement defines "Elastic" as the entity named on your order form, and the governing law follows your location: England and Wales, France, Germany or California where those apply, and the Netherlands (Amsterdam courts) for the rest of the world. So the contracting company, and in some places the law, is not fixed until you order. Read the order form before treating it as a European contract.

Elastic is also the one here that most resembles Splunk's operational weight. A self-managed cluster needs capacity planning and upgrades, and a hosted deployment needs a quote for serious volumes. Its pricing page was not checked for amounts.

What Elastic does better than Splunk

  • Self-managed option, so no vendor holds the data at all
  • Search, SIEM and observability on one engine, closest to Splunk's breadth
  • Dutch-incorporated parent, and Dutch law as the default outside listed countries
  • Large community and content ecosystem, the nearest thing to Splunk's

Where Elastic is a step down from Splunk

  • Contracting entity set on the order form, so not verifiable in advance
  • California law and courts apply to customers located in the United States
  • Operating a cluster well is real work, like Splunk Enterprise
  • KQL and ES|QL rather than SPL, so saved searches must be rewritten

Standout against Splunk. It is the only option here you can run entirely yourself with a content ecosystem approaching Splunk's.

elastic.co/observability/application-performance-monitoring Visit Elastic
#11

ITrust Reveelium

the French XDR and SIEM with a managed SOC behind it

Toulouse, FranceCustom quote (devis); on-premise or SaaS licensing, no published price list#11 in SIEM & Security Monitoring

  • Which law reaches it. EU (France). Splunk is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Source code. Closed source, as Splunk is.

Best for: Organisations that want a platform and an outsourced SOC from the same French vendor

ITRUST SA is registered in Toulouse (RCS Toulouse, Siret 493 754 204 000 52, share capital 620,596.50 euros), with its registered office at 1000 L'Occitane, 31670 Labege. The French business register lists the same company and address.

Reveelium Defend is described as an advanced XDR technology combined with a SIEM, using four integrated detection engines: SIEM rules, UEBA, threat intelligence, and correlation and supervision. ITrust also sells managed SOC services, which matters for teams without round-the-clock analysts.

No prices appear on the pages read, and ITrust positions itself as "French and sovereign" without us checking hosting or sub-processors. It is the smallest and least documented of the SIEM vendors here, and the English-language material is thinner than for Guardsix or SEKOIA.

What ITrust Reveelium does better than Splunk

  • Managed SOC option from the same vendor as the platform
  • SIEM rules and UEBA described as built-in detection engines of one product
  • French SA in a public register at a stated address
  • Four detection engines described on the product page

Where ITrust Reveelium is a step down from Splunk

  • No published price list or free tier
  • Much smaller than Splunk, with a small ecosystem of integrations
  • Hosting location and sub-processors not verified here
  • Less English documentation than the larger vendors

Standout against Splunk. It is the only option here that pairs a SIEM and UEBA product with the vendor's own managed SOC service.

What actually breaks when you switch

The query language comes first. Every saved search, scheduled alert, dashboard panel and correlation search in Splunk is written in SPL, and none of the tools here run SPL. Start with an inventory, rank what was opened or fired in the last quarter, and rebuild only those; the rest is usually dead weight you were paying to index.

Then the data path. Splunk forwarders and HEC feeds can be redirected to syslog or a standard shipper, but parsing and field names differ between products, so a detection that worked on Splunk's field names will not match unless you normalise first. A pipeline layer such as Tenzir exists for exactly this, but it is one more component to run.

Finally, the overlap. Splunk contracts are usually annual or multi-year commitments, so you may be paying for capacity while you build the replacement. Check the term and renewal date before you plan a cut-over, and keep Splunk running in parallel until the new detections have fired correctly on real events.

Is Splunk only a SIEM, or can a log platform replace it?

It depends on what your team actually does inside it. Many Splunk estates started as a log search tool for operations and gradually gained a security app. If you mostly search logs and build dashboards, an OpenSearch-based service plus Grafana or OpenSearch Dashboards does the job and costs a fraction of a licence. The tools on this page built on OpenSearch are OVHcloud Logs Data Platform, Aiven for OpenSearch and Exoscale OpenSearch.

If your security team lives in correlation rules, notable events and case handling, you want an actual SIEM. Logpoint under its Guardsix brand, SEKOIA.IO, ITrust Reveelium and TeskaLabs LogMan.io are built for that.

The honest middle case is a team that does both. Then the realistic answer is two layers: a cheap, long-retention log store and a SIEM on the data that matters for detection. That is also the architecture Tenzir is designed to make easy.

What is the real jurisdiction risk with a US log platform?

Not a prohibition, and not a guarantee. The facts are specific: your contract is with Splunk LLC, governed by California law, with disputes in California courts, and Splunk is part of Cisco. Where the data physically sits is a separate question, and one this page did not check, because the Splunk Cloud region list and DPA text were not retrievable.

Whether this matters depends on what is in your logs and who asks. A public-sector body, a regulated utility or a hospital will usually be asked about it. A web agency with application logs and no personal data in them may be fine. The question to put to any vendor, European or not, is which legal entity you are contracting with and which courts it names.

A European entity is not a magic fix either. Several tools here run on public clouds or have international parents, and the contract you sign is the thing that counts.

How hard is the migration, really?

The ingest side is the easy part. Splunk forwarders, syslog and HEC feeds can usually be redirected, and most tools here accept syslog and standard shippers. Tenzir and the OpenSearch ecosystem exist partly to normalise and route data without re-instrumenting every source.

The hard part is everything built on SPL: saved searches, scheduled alerts, dashboards, lookups, correlation searches and the playbooks hanging off them. None of them port automatically. Budget for an inventory first, and decide which ones people actually use before rebuilding anything; in most estates the answer is a small fraction.

Run both side by side for a quarter. A SIEM you switch off before the detections are proven is how a migration turns into an incident.

Will a European tool be cheaper than Splunk?

Often, but check the unit before the number. Logmanager charges by stored gigabyte rather than daily ingest, Guardsix by nodes, devices or entities, Scaleway Cockpit by gigabytes ingested at EUR 0.35 for custom logs, and OpenSearch services by instance size and storage. Each shifts risk differently: node pricing is predictable but punishes large device counts, and stored-GB pricing rewards filtering at the edge.

Several vendors, notably Sekoia, ITrust, TeskaLabs and Elastic above its free options, publish no list price, so any comparison there requires a quote. Treat savings claims, including those on vendor pages, as hypotheses until you have your own volume numbers in an estimate.

Which one to pick

If your Splunk is mainly a SIEM and you want a European contract with a comparable product shape, start with Logpoint under its Guardsix name, and look at SEKOIA.IO if you would rather buy detection content than write it.

If the real use is log search, retention and compliance, Logmanager is the lightest route and lists a free tier, and the managed OpenSearch services from OVHcloud, Aiven and Exoscale give you open interfaces without the ceremony. Choose Scaleway Cockpit if you already run on Scaleway.

If the pain is the bill rather than the console, try Tenzir first: filtering and routing data before it is stored can change the economics whichever product sits behind it.

And if you depend on SPL, the app marketplace and years of Enterprise Security content, accept that no tool on this page replaces them. The honest case for moving is a clearer contract jurisdiction and a price you can see, and that case is strongest where the logs contain personal data or the buyer is a public body.

Frequently Asked Questions

Splunk's General Terms, last updated in May 2026, are between Splunk LLC, a Delaware limited liability company with its principal place of business at 3098 Olsen Drive, San Jose, California, and the customer. They are governed by California law, with exclusive venue in the federal or state courts of the Northern District of California. If you order through a Splunk Affiliate Distributor, the order is a separate contract with that distributor under the same General Terms.

Only partly. For Splunk Cloud Platform, Splunk Enterprise and Splunk Security the pricing page offers a quote, with activity-based, workload or ingest models. Splunk Observability Cloud lists starting prices of $15 per host per month for infrastructure, $60 for App and Infra and $75 for End-to-End, billed annually, and AppDynamics starts at $6 per vCPU per month. The core log and security products are therefore not comparable from the page alone.

Logpoint, now sold as Guardsix, is the most direct: a Danish SIEM with NDR and SOAR products and node-based pricing. SEKOIA.IO is the pick if you want maintained detection content and threat intelligence bundled, ITrust Reveelium suits teams that also want a managed SOC, and TeskaLabs LogMan.io is a log platform that adds an AI SIEM. None of them has Splunk's content ecosystem.

Yes, several. Logmanager lists a free plan with 100 GB of storage and a 7-day trial for its virtual appliance. Tenzir has a free Community edition with 1 TB per day of ingress. Aiven offers a free sandbox tier for OpenSearch, Exoscale gives free credit at registration, and Scaleway Cockpit is enabled by default in every Scaleway project. The SIEM vendors, Guardsix, SEKOIA.IO, ITrust and TeskaLabs, work through demos and quotes.

Yes. The logpoint.com legal page redirects permanently to guardsix.com/legal, where the contracting entity is Guardsix A/S, registration DK-26301939, Valkendorfsgade 13A, Copenhagen. Its terms are governed by Danish law with the Danish courts. The product line now includes Guardsix SIEM, NDR, SOAR, Fleet and Governance, which is why this page lists it as Logpoint (Guardsix).

With a caveat. Elastic N.V. is the parent named in the privacy statement, and the website terms are from Elasticsearch B.V.

The Elastic Cloud subscription agreement defines "Elastic" as the entity named on your order form, so the contracting company is not fixed in advance, and the governing law depends on where you are: England and Wales, France, Germany, California or, for the rest of the world, the Netherlands. Check the order form before you treat it as a European contract, which is why it sits last in the ranking.

Its privacy policy names TeskaLabs Ltd, 124 City Road, London, acting through a branch office in Prague, and Companies House lists TESKALABS LTD, number 08893495, incorporated on 13 February 2014. The company describes its engineering and a data centre as being in the Czech Republic. The contracting entity is therefore British, which counts for this directory, but check which entity signs your order.

It varies and you have to ask. OVHcloud and Scaleway run their own infrastructure, Exoscale describes European zones, and TeskaLabs describes a data centre in the Czech Republic. Aiven for OpenSearch runs "on any cloud", which includes the large US hyperscalers, so the region and cloud you choose decides where your data sits. A European contracting entity does not by itself answer where the data physically is.

Splunk has SPL, a very large marketplace of add-ons and apps, and a mature Enterprise Security content ecosystem, plus one platform spanning logs, security and observability. None of the European tools replicates all three. In exchange you get a clearer contract jurisdiction, and in several cases a free tier and a published unit price.

Yes, several. Logmanager is available as a self-hosted virtual appliance on VMware, Hyper-V and Proxmox. TeskaLabs deploys on-premises or air-gapped, and Guardsix offers on-premises deployment. Elastic can run self-managed too. OVHcloud, Scaleway, Aiven, Exoscale and SEKOIA.IO are services, which suits teams that do not want to operate the platform themselves.

Who worked on this review

Three people touch every comparison page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's own documentation.

Daniel Brandt
Written by

Daniel Brandt

Privacy & Compliance Researcher · Berlin, Germany

Checks the compliance claims: where the company is established, where the data sits, and what the DPA actually says.

Sebastiaan Smits
Edited by

Sebastiaan Smits

Founder & Editor · Netherlands

Selects the tools, writes the reviews, and checks where each company is actually established.

Marta Kowalczyk
Fact-checked by

Marta Kowalczyk

Senior Analyst, Infrastructure & Developer Tools · Warsaw, Poland

Covers hosting, developer tooling and the practical side of moving workloads to European providers.

Read our editorial process for how we source, verify and update these pages — and how we keep affiliate income separate from what we recommend.

Explore More European Alternatives

Discover privacy-focused European alternatives to other popular US tech services.

More SIEM & Security Monitoring Browse All Categories