Every European observability and log management tool reviewed
Linz, AustriaFounded 2005Consumption-based, published ratesNo free tier stated
Best for: Large estates that need automatic dependency mapping across a stack nobody fully documented
Dynatrace was founded in Linz in 2005 and, despite listing on the New York Stock Exchange, still develops and headquarters its core engineering there — the same convention this site applies to other NYSE-listed European-headquartered vendors.
A single OneAgent per host builds an automatic dependency map of a stack rather than requiring every service to be manually wired into a dashboard, and Grail, its unified data lakehouse, stores logs, metrics, traces and business events in one queryable place instead of three separate products.
The trade-off is independence: the strongest features assume Dynatrace's own agent rather than a plain OpenTelemetry collector, consumption pricing across hosts and ingest resists forecasting before a trial, and the product is sold and implemented in a way that expects a procurement process rather than a card. For an estate too large to map by hand, that cost buys genuine automatic discovery few competitors match.
What Dynatrace does well
- Automatic dependency mapping from a single agent per host, including services nobody remembered
- Grail unifies logs, metrics, traces and business events in one data lakehouse rather than three products
- Genuinely Austrian engineering and headquarters despite the NYSE listing
- Root-cause suggestions that are ahead of the market average for automatic estates
Where Dynatrace falls short
- Consumption pricing across hosts, ingest and retention is difficult to forecast before running it
- The strongest features assume the OneAgent, not a plain OpenTelemetry collector
- Sold and implemented in a way that expects a procurement process rather than self-serve signup
Standout feature. Grail, a single data lakehouse that keeps logs, metrics, traces and business events queryable together instead of scattered across separate products.
Amsterdam, NetherlandsElastic N.V., founded 2012Consumption-based, published ratesFree self-managed tier
Best for: Teams that want a self-hostable, search-based store for logs, metrics and traces together
Elastic Observability grew directly out of the ELK stack — Elasticsearch, Logstash and Kibana — which makes it the one platform on this page built log-first rather than metrics-first. Logs, traces and metrics land in one searchable index, which removes the correlation step that costs the most time during an incident, and the product can be self-hosted in full, so the exit genuinely exists.
A caveat matters here: Elastic N.V. remains incorporated in Amsterdam and files a Dutch registered office, but its executive team, largest office and NYSE listing are heavily weighted toward the United States, so treat the jurisdiction question as more open than a purely EU-run vendor.
Operationally, a buyer is running a search cluster — shard counts, index lifecycle and retention tiers decide both performance and cost — and Elastic's licence direction has changed twice in five years (away from Apache 2.0 in 2021, back to AGPL in 2024), which is worth remembering when planning five years out.
What Elastic Observability does well
- Logs, traces and metrics in one searchable index, removing a correlation step other tools leave to the buyer
- Genuinely self-hostable, including the full open source core, for a real exit from the vendor
- Amsterdam-incorporated N.V. with a real Dutch registered office
Where Elastic Observability falls short
- Executive leadership and the largest office are US-based, despite the Dutch incorporation
- Cluster tuning — shards, index lifecycle, retention — is a specialism most teams do not already have
- Licensing has changed direction twice in five years
Standout feature. The only platform on this page built log-first from the ELK stack, with a genuine self-hosted option for the full open source core.
Copenhagen, DenmarkFounded 2001/2004 as LogPointNode-based licensing, quotedNo free tier stated
Best for: Security teams needing SIEM-grade log retention with a named EU-sovereignty story
LogPoint rebranded to Guardsix in March 2026, framed by the company as closer alignment with managed security service providers and regulated organisations navigating growing regulatory demands. The product itself, contracts and support are unchanged: a converged SIEM, SOAR, UEBA and network detection and response platform, log-centric by design rather than a general infrastructure or application monitoring tool. Acquired outright in 2024, Danish NDR vendor Muninn now sits inside the same platform.
Licensing is node-based — by the number and type of infrastructure nodes reporting in — rather than pure data-volume billing, which the company markets as more predictable than the log-volume-based pricing common among SIEM competitors.
Summa Equity, its majority owner since 2023, is itself a Stockholm-headquartered investment firm, which keeps both the operating company and its controlling investor inside the EU. The trade-off is a genuinely steep learning curve: the platform's structured taxonomy and query language require real onboarding investment before a security team gets full value from it.
What Guardsix does well
- Node-based licensing avoids the bill-shock of pure log-volume pricing common in SIEM
- Self-hosted and air-gappable deployment for regulated and public-sector buyers
- Both the operating company (Denmark) and its majority owner, Summa Equity (Sweden), are EU-based
- Explicit EU-sovereignty positioning against US CLOUD Act and FISA 702 exposure
Where Guardsix falls short
- Steep learning curve — structured taxonomy and query language need real onboarding time
- Pricing is quoted rather than published as a self-serve number
- Narrower fit for general infrastructure or application observability outside security use cases
Standout feature. The only tool in this category built specifically for SIEM and security-log management, with an explicit, EU-owned sovereignty story.
Paris, FranceCentreon SASQuoted on request; free IT EditionFree self-hosted edition
Best for: IT operations teams wanting open-source monitoring that scales into full observability
Centreon started from Nagios-lineage infrastructure and network monitoring and has extended it toward full-stack observability: metrics, logs and business or SLA-level views for large hybrid estates, with a particular footprint in French public-sector, enterprise and telecom accounts. The free, open-source IT Edition is a genuine self-hosted product with a capped feature set, not a crippled demo, while the paid Business, MSP and Cloud editions are custom-quoted by host and device count.
Sixth Street Partners, a US investment firm, holds a growth-equity stake, but this is a minority financial investment rather than a controlling acquisition, and the company's registered office, management and majority ownership remain French. The trade-off for that maturity is pricing opacity above the free tier — there is no self-serve number, only a sales conversation — and reviewers still describe the interface as dated next to newer cloud-native tools.
What Centreon does well
- Free, open-source IT Edition is a genuine self-hosted product, not a crippled trial
- Deep, mature hybrid on-prem and cloud infrastructure monitoring heritage
- Registered office and majority ownership remain French; only a minority US growth investor
- Strong footprint in French public-sector and telecom accounts where data residency in France matters
Where Centreon falls short
- No self-serve pricing above the free tier — every paid edition is quote-only
- Interface still reads as dated next to newer cloud-native observability tools
- Weaker on modern distributed tracing than purpose-built APM specialists
Standout feature. A genuinely free, self-hosted open-source edition with no artificial feature cap disguised as a trial.
Riga, LatviaZabbix SIA, founded 2005Free, open source; support from $325Free at any scale
Best for: Infrastructure teams wanting zero licence cost at any scale
Zabbix has been developed in Riga since 2005 and remains owned by its founder, Alexei Vladishev, with no external investors and no acquisitions in twenty years. The software itself is entirely free with no host cap and no feature gate — unlike most "open core" competitors, there is no separate paid tier that unlocks functionality the free edition withholds. Paid subscriptions (Silver from $325, Gold from $825, Platinum custom) buy support, not more product.
It monitors metrics-first — hosts, services, network devices, cloud and containers — with log monitoring available through agent log items rather than as a dedicated log-search product, and no native distributed tracing.
Self-hosting means operating the database and tuning it yourself as the estate grows, and the templating and UI are dated next to the newest cloud-native tools, but for a team that wants monitoring with genuinely no licence line item, it is one of the most straightforward choices in this category.
What Zabbix does well
- 100% free and open source with zero feature gating, at any host count
- Founder-owned for twenty years, with no VC or acquisition to change the terms later
- Mature, large install base and a genuinely Latvian legal entity
Where Zabbix falls short
- No native distributed tracing or APM
- Log monitoring is agent-based, not a dedicated log-search product like Elastic or Guardsix
- Self-hosting means owning database tuning and scaling yourself
Standout feature. Genuinely free at any scale, with no feature withheld behind a paid tier — the paid subscriptions buy support, not product.
Nuremberg, GermanyIcinga GmbH, project forked 2009Free, open source; support via NetwaysFree at any scale
Best for: Teams that want monitoring configured as code with no feature-gated tier
Icinga is the Nagios-lineage successor most infrastructure teams outgrow Nagios into, forked in 2009 and now operated as Icinga GmbH within the Netways Group, a German open-source consultancy and hosting company. Every feature in the core is free and open source with no functionality withheld behind a paid tier — the only thing sold is support subscriptions, mainly for organisations that need packaged builds on RHEL, SLES or Amazon Linux.
Configuration is code-first rather than click-first, which suits a team that wants monitoring defined in version control alongside the infrastructure it watches, but means a steeper starting point than a hosted SaaS product. The plugin and integration ecosystem is smaller than the Nagios one it forked from, though Nagios plugins are largely compatible, and like Zabbix it monitors metrics and state first, with log and cloud coverage as an addition rather than the core product.
What Icinga does well
- Fully open source with no feature gating — paid tiers buy packaged OS support, not functionality
- Configuration as code, suited to teams that already manage infrastructure that way
- German-owned within the Netways Group, no external or non-EU investors
Where Icinga falls short
- Smaller plugin and integration ecosystem than the Nagios lineage it forked from
- Steeper starting point than a hosted SaaS product — self-hosting is the only option
- Metrics and state monitoring first; log and cloud coverage are additions, not the core
Standout feature. Configuration as code with every feature free at any scale — the paid subscription only buys packaged OS builds and support.
Amsterdam, NetherlandsFounded 2012Free from €0/month; paid from €219/yearPermanent free tier
Best for: Small Ruby, Elixir, Node, Python or PHP teams wanting logging bundled in
AppSignal covers error tracking, performance monitoring, host metrics and now logging across nine languages and frameworks, with a permanent free tier (30,000 requests and 1GB of logging a month) and a paid plan from €219 a year that keeps working past the limit rather than billing a surprise overage. Long-term log storage and a HIPAA Compliance add-on are both priced separately at €89 a month.
Full review, pricing detail and alternatives on the AppSignal tool page.
Bonn, GermanyTideways GmbHTiered by request volume, published14-day trial, no card
Best for: PHP shops running Symfony, Laravel or Shopware wanting continuous profiling
Tideways is a PHP-only profiler and APM with automatic instrumentation for Laravel, Symfony, Magento, Shopware, WordPress and Drupal at a stated 1-5% overhead, priced in tiers by monthly request volume with a stated no-surprise-invoice policy and a two-month grace period before an automatic tier upgrade.
Full review, pricing tiers and alternatives on the Tideways tool page.