European SIEM & Security Monitoring

Looking for a European alternative to Splunk or Microsoft Sentinel? These European SIEM and security monitoring platforms keep your security telemetry under EU jurisdiction, and most price by node rather than by gigabyte — the difference that decides whether you can afford to watch everything. Led by Logpoint from Denmark.

How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect the order tools appear in. It never buys a listing: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

European Purpose may be paid for placements on this page and may earn a commission through links on it. Paid placement can affect the order in which tools appear; it never affects whether a tool is listed or what our review says. Editorial policy

8 European SIEM & Security Platforms

Logpoint

European SIEM with licensing you can predict

#1 of 8 in this category
Denmark Per node or per device licence
SIEM with SOAR & UEBAPredictable node licensingEU-only deployment

SEKOIA.IO

French SOC platform with threat intelligence built in

#2 of 8 in this category
France SaaS subscription
SOC platform with CTIDetection-as-codeFrench sovereign hosting

Graylog

Open-source log management that grew into SIEM

#3 of 8 in this category
Germany Open source + enterprise licence
Open source coreLog management & SIEMSelf-hostable

TEHTRIS

French XDR platform with sovereign hosting

#4 of 8 in this category
France Per endpoint subscription
XDR platformEDR, MTD and deceptionSovereign French hosting

HarfangLab

French endpoint detection, certified by ANSSI

#5 of 8 in this category
France Per endpoint, per year
ANSSI-certified EDROn-premises or SecNumCloudOpen detection rules

CrowdSec

Open-source crowdsourced intrusion detection

#6 of 8 in this category
France Free open source + paid tiers
Crowdsourced threat intelOpen source agentBehaviour-based blocking

LogSentinel

Bulgarian SIEM with a cryptographically sealed audit trail

#7 of 8 in this category
Bulgaria Per data volume or per asset
Tamper-evident audit trailSIEM for mid-sized teamsCompliance reporting

Logmanager

Log management and SIEM without the operating overhead

#8 of 8 in this category
Czech Republic Appliance licence by volume
Deliberately simple to operateAppliance modelCentral European support

Key takeaways

  • Logpoint ranks #1 among the European security platforms in this directory, because Logpoint licenses by node rather than by data volume, which is the single most common reason organisations leave Splunk.
  • Volume-based pricing changes what you monitor: when every log source has a running cost, teams quietly stop collecting the noisy ones, which are frequently where an intrusion appears first.
  • Security telemetry describes an organisation's defences, blind spots and incidents — the last data set most European public bodies want under foreign jurisdiction, and increasingly part of the NIS2 supply chain assessment.
  • Detection content is where most SIEM deployments fail rather than collection, which is why SEKOIA.IO ships continuously maintained rules tied to tracked adversary behaviour instead of an empty correlation engine.
  • Graylog is the exception on jurisdiction: substantial US operations in Houston alongside its Hamburg roots, so self-hosting the open-source core is the way to keep the data inside your own infrastructure.

European SIEM and security monitoring platforms collect, correlate and act on security telemetry, built by companies established in Europe, where the logs describing an organisation's defences and incidents stay under EU jurisdiction — and where licensing generally does not scale with the volume of logs you dare to collect.

European SIEM & security monitoring compared

European SIEM & security monitoring tools compared on position, country, entry price and best use
PositionToolEstablishedEntry priceBest for
#1 Logpoint Denmark Per node or per device licence European enterprises and public bodies replacing Splunk or QRadar
#2 SEKOIA.IO France SaaS subscription SOC teams and MSSPs wanting detection content maintained for them
#3 Graylog Germany Open source + enterprise licence Teams that want to self-host log management and add security on top
#4 TEHTRIS France Enterprise pricing on request Organisations wanting XDR and sovereign hosting from one French vendor
#5 HarfangLab France Per endpoint, per year Organisations that need endpoint telemetry under French or EU control
#6 CrowdSec France Free and open source / paid plans for the threat feed Teams wanting crowdsourced behavioural blocking, free and open source
#7 LogSentinel Bulgaria Per data volume or per asset Regulated mid-market organisations that must prove log integrity
#8 Logmanager Czech Republic Appliance licence by volume IT teams running a SIEM without a dedicated SOC

Every European SIEM & security monitoring tool reviewed

#1 Logpoint

Copenhagen, Denmark Per node or per device licence Demo on request

Best for: European enterprises and public bodies replacing Splunk or QRadar

Logpoint is a Danish SIEM vendor built for European organisations that need security monitoring without an American platform underneath it. The suite covers log collection and correlation, user and entity behaviour analytics and automated response in one product.

Its most quoted advantage is commercial: licensing by node rather than by data volume. SIEM projects fail on cost when the answer to whether to ingest a log source becomes a budget question, and volume pricing makes it one every time. Node licensing removes that decision.

Logpoint is headquartered in Copenhagen with European deployment options and EU security certifications, available as software, appliance or SaaS, with compliance reporting for NIS2, the GDPR and ISO 27001. Security logs are the most sensitive telemetry an organisation produces, which for public bodies makes vendor jurisdiction a national security question.

What Logpoint does well

  • Node-based licensing, not per gigabyte
  • SIEM, UEBA and SOAR in one platform
  • EU-only deployment options
  • Compliance reporting for NIS2 and ISO 27001
  • Danish company with EU certifications
  • Software, appliance or SaaS

Where Logpoint falls short

  • Smaller detection content library than SEKOIA
  • Node counting needs care on large estates
  • Less third-party tooling than Splunk
  • Enterprise sales cycle

Standout feature. Licensing by node, so collecting one more log source is never a budget decision.

#2 SEKOIA.IO

Paris, France SaaS subscription Demo on request

Best for: SOC teams and MSSPs wanting detection content maintained for them

SEKOIA.IO is a Paris-based SOC platform combining SIEM-style detection with its own cyber threat intelligence: the detection rules are informed by the intelligence team's tracking of active threat actors rather than written from scratch by each customer.

That addresses where SIEM deployments actually fail. Collection is solved; content is not, and nobody has time to write and maintain detection rules against evolving attacker behaviour. SEKOIA ships continuously updated detection mapped to MITRE ATT&CK, and publishes much of it openly.

SEKOIA.IO is headquartered in Paris and hosts in France, positioning itself explicitly as a sovereign alternative for European SOCs. For organisations in scope of NIS2, the origin of both the platform and the intelligence increasingly forms part of the assessment.

What SEKOIA.IO does well

  • Detection content maintained continuously
  • Integrated threat intelligence with actor tracking
  • Rules mapped to MITRE ATT&CK
  • French sovereign hosting
  • Case management and automated response
  • MSSP-friendly multi-tenancy

Where SEKOIA.IO falls short

  • SaaS only
  • Newer than the established SIEM vendors
  • Pricing by assets or events needs modelling
  • Strongest in the French market

Standout feature. Detection rules maintained against tracked adversaries, instead of an empty correlation engine.

#3 Graylog

Hamburg, Germany (with US operations in Houston) Open source + enterprise licence Demo on request

Best for: Teams that want to self-host log management and add security on top

Graylog began in Hamburg as an open-source log management project and has grown into a security platform: centralised log collection and search, with SIEM detection and anomaly analytics layered on the same data.

It is the practical entry point to this category. The open-source core solves log centralisation on your own hardware for nothing, and security detection can be added later on data you are already collecting — rather than requiring a platform decision and a budget round before the first log arrives.

One thing to be precise about: Graylog's engineering roots and a substantial part of the company are in Hamburg, but it has substantial US operations in Houston, so unlike the rest of this list it is not purely European and the contracting entity is worth confirming. Self-hosting the open-source core sidesteps the question, since the data never leaves your infrastructure.

What Graylog does well

  • Open-source core, free to self-host
  • Strong log search and dashboards at scale
  • SIEM detection on the same data
  • API-driven architecture
  • Free enterprise tier for small deployments

Where Graylog falls short

  • Not purely European — US operations in Houston
  • Enterprise features licensed by data volume
  • Self-hosting is real operational work
  • Detection content thinner than SEKOIA's

Standout feature. Start with free self-hosted log centralisation, add security detection to the same data later.

#4 TEHTRIS

Paris, France Founded 2010 Enterprise pricing on request Demo on request

Best for: Organisations wanting XDR and sovereign hosting from one French vendor

TEHTRIS is a French XDR platform combining endpoint detection and response, mobile threat defence, deception and automated response, sold with sovereign French hosting.

It approaches the same problem from the opposite end to a SIEM: rather than collecting logs from everything and correlating, it starts from the telemetry its own agents produce across endpoints and mobile devices and detects there, with automated neutralisation built in.

TEHTRIS is headquartered in Bordeaux and appears here cross-listed from Endpoint Protection, where its page lives. The categories are converging, and for many European organisations the practical question is which combination of XDR and SIEM covers their estate rather than which acronym to buy.

What TEHTRIS does well

  • XDR across endpoint, mobile and network
  • Automated response and neutralisation
  • Deception capabilities included
  • Sovereign French hosting
  • French company with public sector track record

Where TEHTRIS falls short

  • Not a general log management platform
  • Agent-based coverage rather than universal ingest
  • Per-endpoint pricing on large estates
  • Strongest in the French market

Standout feature. XDR with automated neutralisation, hosted sovereignly in France.

#5 HarfangLab

Paris, France Per endpoint, per year Demo on request

Best for: Organisations that need endpoint telemetry under French or EU control

HarfangLab is a Paris endpoint detection and response vendor and one of the few EDR products certified by ANSSI, the French national cybersecurity agency — a qualification the American incumbents do not hold.

EDR is the most invasive software an organisation installs: an agent with kernel access on every machine, streaming process telemetry to the vendor. HarfangLab can be deployed entirely on-premises with detection rules you can read and modify, in YARA and Sigma rather than in a closed engine, which changes that relationship from trust to inspection.

The product runs on-premises or on SecNumCloud-qualified infrastructure, and integrates into SIEM and SOC tooling rather than trying to replace it. For an operator of essential services under NIS2, that combination is frequently the requirement rather than the preference.

What HarfangLab does well

  • ANSSI-certified, which the US incumbents are not
  • Deployable fully on-premises or on SecNumCloud
  • Detection rules in YARA and Sigma you can read and edit
  • Windows, Linux and macOS agents
  • Integrates into existing SIEM and SOC tooling

Where HarfangLab falls short

  • EDR rather than a SIEM — it feeds one
  • On-premises deployment needs someone to run it
  • Smaller threat intelligence footprint than CrowdStrike
  • Priced per endpoint, so large estates add up

Standout feature. Endpoint telemetry that never has to leave your infrastructure, with rules you can audit.

#6 CrowdSec

Montrouge, France Founded 2020 Free and open source / paid plans for the threat feed Demo on request

Best for: Teams wanting crowdsourced behavioural blocking, free and open source

CrowdSec is a French open-source security engine that detects hostile behaviour in logs and shares the resulting signals across its user base, so an IP attacking one participant can be blocked by all of them.

It is narrower than a SIEM and should be understood that way: behavioural detection and blocking at the edge rather than correlation across an enterprise estate. What it offers instead is a threat signal derived from a large community rather than purchased as a reputation feed.

CrowdSec is based in Paris, with the agent open source and free and paid tiers above it, and appears here cross-listed from Endpoint Protection where its page lives. For a team currently running fail2ban, it is a considerable step up at no licence cost.

What CrowdSec does well

  • Open source and free at the base tier
  • Crowdsourced threat signal from the user base
  • Behaviour-based rather than signature-based
  • Lightweight agent, easy to deploy
  • French company, EU jurisdiction

Where CrowdSec falls short

  • Not a SIEM — no enterprise correlation
  • Community signal quality varies by scenario
  • Requires log parsers per application
  • Paid tiers needed for enterprise features

Standout feature. A threat feed generated by its own users rather than bought from a vendor.

#7 LogSentinel

Sofia, Bulgaria Per data volume or per asset Demo on request

Best for: Regulated mid-market organisations that must prove log integrity

LogSentinel is a Sofia-based SIEM whose distinguishing feature is integrity: log entries are hashed into a tamper-evident chain, so an organisation can prove that its audit trail has not been edited after the fact.

Detection is what a SIEM sells; provable integrity is what an auditor asks for. Once logs are cryptographically sealed, an insider with database access cannot quietly remove their own trail — the scenario a compliance framework is written against and that most SIEMs answer with a policy rather than with mathematics. Collection, correlation, behavioural detection and incident workflow sit around it.

LogSentinel is based in Sofia with EU hosting, and its reporting is mapped to GDPR, ISO 27001, PCI DSS and NIS2. A SIEM ingests the complete record of what happens inside an organisation, which makes it one of the systems where the vendor's jurisdiction is least negotiable.

What LogSentinel does well

  • Tamper-evident, cryptographically sealed audit trail
  • Compliance reporting mapped to GDPR, ISO 27001 and NIS2
  • Priced for mid-sized organisations
  • Behavioural detection alongside correlation rules
  • Bulgarian company, EU hosting

Where LogSentinel falls short

  • Smaller integration catalogue than the enterprise SIEMs
  • Less third-party threat intelligence
  • Smaller vendor than the incumbents it replaces
  • Detection content needs tuning to your estate

Standout feature. An audit trail whose integrity is proven rather than promised.

#8 Logmanager

Prague, Czech Republic Appliance licence by volume Demo on request

Best for: IT teams running a SIEM without a dedicated SOC

Logmanager is a Czech log management and SIEM appliance built on a premise most of this category ignores: that the organisation deploying it does not have a security operations centre to run it.

Simplicity is the product decision. Parsing, dashboards and detection arrive configured for the systems most organisations actually run, so a two-person IT team gets useful alerts in days rather than standing up a query-writing practice — which is why an unstaffed enterprise SIEM so often decays into an expensive log archive. Collection, search, correlation and compliance reporting are all in the appliance.

Logmanager is based in Prague with a team in Brno, serving mostly Central European customers, and became part of the European Guardsix group in 2026. The appliance runs on your own infrastructure, virtual or physical, so the logs never leave it.

What Logmanager does well

  • Usable by an IT team without a SOC
  • Appliance runs on your own infrastructure
  • Parsing and dashboards preconfigured for common systems
  • Licensed on volume, with no per-user or per-query metering
  • Czech company, Central European support

Where Logmanager falls short

  • Less depth than an enterprise SIEM at the top end
  • Appliance model means capacity planning is yours
  • Smaller ecosystem outside Central Europe
  • Volume licensing punishes very chatty log sources

Standout feature. A SIEM that produces useful alerts without a team hired to operate it.

Why does the SIEM licensing model matter so much?

Because it decides what you can afford to see. Volume-based pricing turns every additional log source into a running cost, and the predictable consequence is that teams stop ingesting the noisy sources — DNS, endpoint telemetry, proxy logs, authentication events at scale.

Those are frequently the sources an intrusion shows up in first. A SIEM that is blind in exactly the places attackers operate is an expensive compliance artefact rather than a detection capability.

Node-based licensing, which Logpoint uses, removes that trade-off: the cost is tied to how many systems you monitor rather than how chatty they are. It is the most common practical reason for a European SIEM migration, ahead of jurisdiction.

Graylog's open-source core takes the same problem from the other side: self-hosted, the marginal cost of another log source is storage rather than licence.

What does NIS2 actually change?

NIS2 widens the set of organisations subject to EU cybersecurity obligations — energy, transport, health, digital infrastructure, public administration, manufacturing and more — and raises the requirements on those already in scope.

The parts that touch this category are incident handling and reporting on defined timelines, and risk management measures that include logging and detection. You cannot report an incident within the deadline if nothing detected it, which makes this tooling foundational rather than optional.

The other relevant part is supply chain. In-scope organisations have to consider the security of their suppliers, and where a security platform itself sits is increasingly part of that assessment — which is why the sovereignty argument in this category is being made by procurement rather than by marketing.

No product delivers compliance on its own: the directive covers governance and accountability too, and this is a summary rather than legal advice.

Collection, correlation or content — where do deployments fail?

Almost never collection. Getting logs into a platform is a solved problem, and every vendor here does it.

Correlation is where the effort goes and content is where deployments die. A correlation engine with no detection rules produces nothing, and writing and maintaining rules against evolving attacker behaviour is a full-time job most organisations do not staff.

That is SEKOIA.IO's argument: detection content maintained continuously against tracked threat actors, mapped to MITRE ATT&CK, rather than a platform you populate yourself. Logpoint ships detection content and SOAR playbooks for the same reason.

Before choosing, ask who writes and updates the rules, how often, and what happens to your customisations when they do. That answer predicts whether the deployment will still be useful in two years better than any feature comparison.

How we selected and ranked these 8 tools

Every tool on this page is in the European Purpose directory, which means the operating company is established in Europe and we have verified that from the company register or the vendor's own legal notice rather than from a marketing page. Tools headquartered outside Europe are not eligible, however good they are.

  1. Feature verification (weight: 40%). We check each capability against the vendor's own documentation and product pages, and record what the tool does rather than what the category is assumed to include.
  2. Ease of adoption (weight: 30%). Integrations, published API access, trial availability and how much configuration stands between signing and a usable result.
  3. Value and transparency (weight: 30%). Published pricing counts in a vendor's favour; quote-only pricing is recorded as quote-only rather than estimated. We weigh what a buyer gets for the entry price, not the headline feature count.
  4. Editorial review. Three people touch every page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's documentation. The three weights above decide the order; a position is a ranking against the other European tools in this category, not an absolute score.

Vendor-reported outcomes — ROI figures, margin uplift, time saved — are labelled as vendor claims wherever they appear on this page. We have not audited them, and neither has anyone else who quotes them. Read our full editorial process for how pages are re-verified.

Frequently asked questions

Logpoint, for most European enterprises and public bodies. The Danish platform covers SIEM, user behaviour analytics and automated response, and licenses by node rather than by data volume — which is usually the reason organisations are leaving Splunk in the first place. SEKOIA.IO is the stronger pick if you want maintained detection content and threat intelligence.

Because it changes what you monitor. When every additional log source has a running cost, teams quietly stop collecting the noisy ones — which are frequently where an intrusion appears first. Node-based licensing removes that trade-off, and it is the most common practical driver of a European SIEM migration, ahead of jurisdiction.

It is foundational rather than sufficient. NIS2 brings incident handling, reporting deadlines, risk management and supply chain obligations, and you cannot report an incident in time if nothing detected it. Where the vendor sits also increasingly forms part of the supply chain assessment. No tool delivers compliance alone, and this is a summary rather than legal advice.

Graylog's core is open source and self-hostable, which makes it the usual starting point for teams wanting log centralisation now and security detection later. CrowdSec is open source too but solves a narrower problem: crowdsourced behavioural blocking rather than full SIEM correlation.

Partly, and the detail matters. Its engineering roots and a substantial part of the company are in Hamburg, with US operations in Houston — so unlike the others here it is not purely European, and the entity you contract with is worth confirming. Self-hosting the open-source core sidesteps the question entirely, since the data never leaves your infrastructure.

SIEM collects and correlates logs from everything; XDR starts from endpoint and network telemetry the vendor's own agents produce and adds detection on top. In practice the categories are converging, which is why TEHTRIS appears here alongside the SIEM platforms — and why the useful question is what you need to detect rather than which acronym the vendor uses.