Best European Splunk Alternatives (2026)

A European Splunk alternative is a SIEM or security monitoring platform operated by a company established in Europe whose licensing does not scale with log volume, so the decision to collect a log source is an engineering choice rather than a budget one.

How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect the order tools appear in. It never buys a listing: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

European Purpose may be paid for placements on this page and may earn a commission through links on it. Paid placement can affect the order in which tools appear; it never affects whether a tool is listed or what our review says. Editorial policy

Key takeaways

  • Logpoint is the strongest European Splunk replacement, because node-based licensing removes the running cost of each additional log source.
  • Volume pricing changes what you monitor: teams stop ingesting noisy sources, which are frequently the ones an intrusion appears in first.
  • SEKOIA.IO solves the harder half — detection content maintained continuously against tracked threat actors, rather than an empty correlation engine.
  • Graylog is the cheapest entry point through its open-source core, with the caveat that the company is not purely European.
  • For NIS2-scope organisations, where the security platform itself sits is increasingly part of the supply chain assessment rather than a preference.

Organisations leave Splunk over the bill, and specifically over what the bill does to their coverage. This ranking judges five European platforms on the licensing model, on who maintains the detection content, and on where security telemetry that describes your defences is processed.

5 European SIEM & security monitoring tools compared

European SIEM & security monitoring tools compared on position, country, entry price and best use
PositionToolEstablishedEntry priceBest for
#1 Logpoint Denmark Per node or per device licence Replacing Splunk without volume pricing
#2 SEKOIA.IO France SaaS subscription Detection content you do not have to write
#3 Graylog Germany Open source + enterprise licence Starting for nothing and growing into SIEM
#4 TEHTRIS France Enterprise pricing on request Detection from agents rather than log ingest
#5 CrowdSec France Free and open source / paid plans for the threat feed Blocking hostile behaviour at the edge, free

The 5 tools reviewed

#1 Logpoint

Copenhagen, Denmark Per node or per device licence Demo on request

Best for: Replacing Splunk without volume pricing

Logpoint licenses by node rather than by gigabyte ingested, which removes the calculation that quietly shrinks Splunk coverage over time. SIEM, user behaviour analytics and SOAR playbooks sit in one platform, available as software, appliance or SaaS with EU-only deployment options.

What Logpoint does well

  • Node-based licensing
  • SIEM, UEBA and SOAR together
  • EU-only deployment available

Where Logpoint falls short

  • Smaller content library than SEKOIA
  • Node counting needs care on large estates

Standout feature. Collecting one more log source is never a budget decision.

#2 SEKOIA.IO

Paris, France SaaS subscription Demo on request

Best for: Detection content you do not have to write

SEKOIA.IO ships continuously updated detection rules informed by its own threat intelligence team tracking active adversaries, mapped to MITRE ATT&CK. That addresses where SIEM deployments actually fail — not collection, which is solved, but content nobody has time to maintain.

What SEKOIA.IO does well

  • Detection maintained against tracked actors
  • Integrated threat intelligence
  • French sovereign hosting

Where SEKOIA.IO falls short

  • SaaS only
  • Newer than the established vendors

Standout feature. Somebody else writes and updates the detection rules, continuously.

#3 Graylog

Hamburg, Germany (with US operations in Houston) Open source + enterprise licence Demo on request

Best for: Starting for nothing and growing into SIEM

Graylog’s open-source core solves log centralisation on your own hardware at no licence cost, with security detection available later on data you are already collecting. It is the pragmatic entry point when there is no budget round yet.

Note the caveat: substantial US operations in Houston alongside the Hamburg roots, so confirm the contracting entity — or self-host, where the question does not arise.

What Graylog does well

  • Open-source core, free to self-host
  • Strong log search at scale
  • Detection on the same data later

Where Graylog falls short

  • Not purely European
  • Enterprise features licensed by volume

Standout feature. The only option here you can start with for nothing.

#4 TEHTRIS

Paris, France Founded 2010 Enterprise pricing on request Demo on request

Best for: Detection from agents rather than log ingest

TEHTRIS approaches the problem from the endpoint: XDR across endpoints, mobile and network with automated neutralisation, on sovereign French hosting. For organisations whose estate is well covered by agents, that can deliver detection faster than a log-ingest project.

What TEHTRIS does well

  • XDR with automated response
  • Sovereign French hosting
  • Deception capabilities

Where TEHTRIS falls short

  • Not general log management
  • Agent coverage rather than universal ingest

Standout feature. Detection and neutralisation without a log ingestion programme first.

#5 CrowdSec

Montrouge, France Founded 2020 Free and open source / paid plans for the threat feed Demo on request

Best for: Blocking hostile behaviour at the edge, free

CrowdSec detects hostile behaviour in logs and shares signals across its user base, so an IP attacking one participant is blocked by all of them. It is narrower than a SIEM by design, and for a team currently running fail2ban it is a considerable step up at no licence cost.

What CrowdSec does well

  • Open source and free at the base tier
  • Crowdsourced threat signal
  • Lightweight agent

Where CrowdSec falls short

  • Not a SIEM — no enterprise correlation
  • Requires parsers per application

Standout feature. A threat feed generated by its own users rather than bought.

Why does volume-based licensing hurt so much?

Because it converts a security decision into a finance decision, repeatedly. Every candidate log source — DNS, proxy, endpoint telemetry, authentication at scale — arrives with a running cost attached, and the noisy sources cost the most.

The noisy sources are frequently where an intrusion first becomes visible. Over a few budget cycles the platform quietly becomes blind in exactly the places that matter, while still passing a compliance review because the important-sounding sources are present.

Node-based licensing removes the trade-off, and self-hosting an open core removes it differently: the marginal cost of another source becomes storage rather than licence.

Where do SIEM deployments actually fail?

Almost never at collection. Getting logs into a platform is a solved problem and every vendor does it.

They fail at content. A correlation engine with no detection rules produces nothing, and writing and maintaining rules against evolving attacker behaviour is a full-time job most organisations do not staff. That is SEKOIA.IO’s entire argument, and why Logpoint ships content and playbooks rather than a blank platform.

Ask who writes the rules, how often they are updated, and what happens to your customisations when they are. The answer predicts whether the deployment is still useful in two years better than any feature comparison.

What does NIS2 mean for this choice?

NIS2 brings incident handling and reporting on defined timelines, plus risk management measures that include logging and detection. You cannot report an incident within the deadline if nothing detected it, which makes this category foundational rather than optional for in-scope organisations.

It also brings supply chain obligations, which is where vendor jurisdiction enters the assessment formally rather than as a preference. For public bodies in particular that is now a procurement question.

No product delivers compliance on its own — governance and accountability sit outside the tooling. This is a summary, not legal advice.

How we selected and ranked these 5 tools

Every tool on this page is in the European Purpose directory, which means the operating company is established in Europe and we have verified that from the company register or the vendor's own legal notice rather than from a marketing page. Tools headquartered outside Europe are not eligible, however good they are.

  1. Feature verification (weight: 40%). We check each capability against the vendor's own documentation and product pages, and record what the tool does rather than what the category is assumed to include.
  2. Ease of adoption (weight: 30%). Integrations, published API access, trial availability and how much configuration stands between signing and a usable result.
  3. Value and transparency (weight: 30%). Published pricing counts in a vendor's favour; quote-only pricing is recorded as quote-only rather than estimated. We weigh what a buyer gets for the entry price, not the headline feature count.
  4. Editorial review. Three people touch every page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's documentation. The three weights above decide the order; a position is a ranking against the other European tools in this category, not an absolute score.

Vendor-reported outcomes — ROI figures, margin uplift, time saved — are labelled as vendor claims wherever they appear on this page. We have not audited them, and neither has anyone else who quotes them. Read our full editorial process for how pages are re-verified.

Frequently asked questions

Logpoint for most European enterprises and public bodies: SIEM, behaviour analytics and automated response with node-based licensing rather than volume pricing, which is usually the reason organisations are leaving Splunk. SEKOIA.IO is the stronger pick if maintained detection content matters more than licensing.

Graylog’s open-source core is free to self-host and solves log centralisation, with security detection available on the same data later. CrowdSec is free and open source too but narrower — crowdsourced behavioural blocking rather than SIEM correlation. Both are credible starting points without a budget round.

Because it decouples cost from log volume. Under volume pricing every additional source has a running cost, so teams stop collecting the noisy ones — which are frequently where an intrusion appears first. Node licensing ties cost to how many systems you monitor rather than how chatty they are.

It is foundational rather than sufficient. NIS2 requires incident handling and reporting within defined timelines, and you cannot report what nothing detected. Vendor jurisdiction also enters the supply chain assessment for in-scope organisations. This is a summary, not legal advice.

Partly. Its engineering roots and a substantial part of the company are in Hamburg, with US operations in Houston, so unlike the others here it is not purely European and the contracting entity is worth confirming. Self-hosting the open-source core sidesteps the question, since the data never leaves your infrastructure.