Every European SIEM & security monitoring tool reviewed
Copenhagen, Denmark
Per node or per device licence
Demo on request
Best for: European enterprises and public bodies replacing Splunk or QRadar
Logpoint is a Danish SIEM vendor built for European organisations that need security monitoring without an American platform underneath it. The suite covers log collection and correlation, user and entity behaviour analytics and automated response in one product.
Its most quoted advantage is commercial: licensing by node rather than by data volume. SIEM projects fail on cost when the answer to whether to ingest a log source becomes a budget question, and volume pricing makes it one every time. Node licensing removes that decision.
Logpoint is headquartered in Copenhagen with European deployment options and EU security certifications, available as software, appliance or SaaS, with compliance reporting for NIS2, the GDPR and ISO 27001. Security logs are the most sensitive telemetry an organisation produces, which for public bodies makes vendor jurisdiction a national security question.
What Logpoint does well
- Node-based licensing, not per gigabyte
- SIEM, UEBA and SOAR in one platform
- EU-only deployment options
- Compliance reporting for NIS2 and ISO 27001
- Danish company with EU certifications
- Software, appliance or SaaS
Where Logpoint falls short
- Smaller detection content library than SEKOIA
- Node counting needs care on large estates
- Less third-party tooling than Splunk
- Enterprise sales cycle
Standout feature. Licensing by node, so collecting one more log source is never a budget decision.
Paris, France
SaaS subscription
Demo on request
Best for: SOC teams and MSSPs wanting detection content maintained for them
SEKOIA.IO is a Paris-based SOC platform combining SIEM-style detection with its own cyber threat intelligence: the detection rules are informed by the intelligence team's tracking of active threat actors rather than written from scratch by each customer.
That addresses where SIEM deployments actually fail. Collection is solved; content is not, and nobody has time to write and maintain detection rules against evolving attacker behaviour. SEKOIA ships continuously updated detection mapped to MITRE ATT&CK, and publishes much of it openly.
SEKOIA.IO is headquartered in Paris and hosts in France, positioning itself explicitly as a sovereign alternative for European SOCs. For organisations in scope of NIS2, the origin of both the platform and the intelligence increasingly forms part of the assessment.
What SEKOIA.IO does well
- Detection content maintained continuously
- Integrated threat intelligence with actor tracking
- Rules mapped to MITRE ATT&CK
- French sovereign hosting
- Case management and automated response
- MSSP-friendly multi-tenancy
Where SEKOIA.IO falls short
- SaaS only
- Newer than the established SIEM vendors
- Pricing by assets or events needs modelling
- Strongest in the French market
Standout feature. Detection rules maintained against tracked adversaries, instead of an empty correlation engine.
Hamburg, Germany (with US operations in Houston)
Open source + enterprise licence
Demo on request
Best for: Teams that want to self-host log management and add security on top
Graylog began in Hamburg as an open-source log management project and has grown into a security platform: centralised log collection and search, with SIEM detection and anomaly analytics layered on the same data.
It is the practical entry point to this category. The open-source core solves log centralisation on your own hardware for nothing, and security detection can be added later on data you are already collecting — rather than requiring a platform decision and a budget round before the first log arrives.
One thing to be precise about: Graylog's engineering roots and a substantial part of the company are in Hamburg, but it has substantial US operations in Houston, so unlike the rest of this list it is not purely European and the contracting entity is worth confirming. Self-hosting the open-source core sidesteps the question, since the data never leaves your infrastructure.
What Graylog does well
- Open-source core, free to self-host
- Strong log search and dashboards at scale
- SIEM detection on the same data
- API-driven architecture
- Free enterprise tier for small deployments
Where Graylog falls short
- Not purely European — US operations in Houston
- Enterprise features licensed by data volume
- Self-hosting is real operational work
- Detection content thinner than SEKOIA's
Standout feature. Start with free self-hosted log centralisation, add security detection to the same data later.
Paris, France
Founded 2010
Enterprise pricing on request
Demo on request
Best for: Organisations wanting XDR and sovereign hosting from one French vendor
TEHTRIS is a French XDR platform combining endpoint detection and response, mobile threat defence, deception and automated response, sold with sovereign French hosting.
It approaches the same problem from the opposite end to a SIEM: rather than collecting logs from everything and correlating, it starts from the telemetry its own agents produce across endpoints and mobile devices and detects there, with automated neutralisation built in.
TEHTRIS is headquartered in Bordeaux and appears here cross-listed from Endpoint Protection, where its page lives. The categories are converging, and for many European organisations the practical question is which combination of XDR and SIEM covers their estate rather than which acronym to buy.
What TEHTRIS does well
- XDR across endpoint, mobile and network
- Automated response and neutralisation
- Deception capabilities included
- Sovereign French hosting
- French company with public sector track record
Where TEHTRIS falls short
- Not a general log management platform
- Agent-based coverage rather than universal ingest
- Per-endpoint pricing on large estates
- Strongest in the French market
Standout feature. XDR with automated neutralisation, hosted sovereignly in France.
Paris, France
Per endpoint, per year
Demo on request
Best for: Organisations that need endpoint telemetry under French or EU control
HarfangLab is a Paris endpoint detection and response vendor and one of the few EDR products certified by ANSSI, the French national cybersecurity agency — a qualification the American incumbents do not hold.
EDR is the most invasive software an organisation installs: an agent with kernel access on every machine, streaming process telemetry to the vendor. HarfangLab can be deployed entirely on-premises with detection rules you can read and modify, in YARA and Sigma rather than in a closed engine, which changes that relationship from trust to inspection.
The product runs on-premises or on SecNumCloud-qualified infrastructure, and integrates into SIEM and SOC tooling rather than trying to replace it. For an operator of essential services under NIS2, that combination is frequently the requirement rather than the preference.
What HarfangLab does well
- ANSSI-certified, which the US incumbents are not
- Deployable fully on-premises or on SecNumCloud
- Detection rules in YARA and Sigma you can read and edit
- Windows, Linux and macOS agents
- Integrates into existing SIEM and SOC tooling
Where HarfangLab falls short
- EDR rather than a SIEM — it feeds one
- On-premises deployment needs someone to run it
- Smaller threat intelligence footprint than CrowdStrike
- Priced per endpoint, so large estates add up
Standout feature. Endpoint telemetry that never has to leave your infrastructure, with rules you can audit.
Montrouge, France
Founded 2020
Free and open source / paid plans for the threat feed
Demo on request
Best for: Teams wanting crowdsourced behavioural blocking, free and open source
CrowdSec is a French open-source security engine that detects hostile behaviour in logs and shares the resulting signals across its user base, so an IP attacking one participant can be blocked by all of them.
It is narrower than a SIEM and should be understood that way: behavioural detection and blocking at the edge rather than correlation across an enterprise estate. What it offers instead is a threat signal derived from a large community rather than purchased as a reputation feed.
CrowdSec is based in Paris, with the agent open source and free and paid tiers above it, and appears here cross-listed from Endpoint Protection where its page lives. For a team currently running fail2ban, it is a considerable step up at no licence cost.
What CrowdSec does well
- Open source and free at the base tier
- Crowdsourced threat signal from the user base
- Behaviour-based rather than signature-based
- Lightweight agent, easy to deploy
- French company, EU jurisdiction
Where CrowdSec falls short
- Not a SIEM — no enterprise correlation
- Community signal quality varies by scenario
- Requires log parsers per application
- Paid tiers needed for enterprise features
Standout feature. A threat feed generated by its own users rather than bought from a vendor.
Sofia, Bulgaria
Per data volume or per asset
Demo on request
Best for: Regulated mid-market organisations that must prove log integrity
LogSentinel is a Sofia-based SIEM whose distinguishing feature is integrity: log entries are hashed into a tamper-evident chain, so an organisation can prove that its audit trail has not been edited after the fact.
Detection is what a SIEM sells; provable integrity is what an auditor asks for. Once logs are cryptographically sealed, an insider with database access cannot quietly remove their own trail — the scenario a compliance framework is written against and that most SIEMs answer with a policy rather than with mathematics. Collection, correlation, behavioural detection and incident workflow sit around it.
LogSentinel is based in Sofia with EU hosting, and its reporting is mapped to GDPR, ISO 27001, PCI DSS and NIS2. A SIEM ingests the complete record of what happens inside an organisation, which makes it one of the systems where the vendor's jurisdiction is least negotiable.
What LogSentinel does well
- Tamper-evident, cryptographically sealed audit trail
- Compliance reporting mapped to GDPR, ISO 27001 and NIS2
- Priced for mid-sized organisations
- Behavioural detection alongside correlation rules
- Bulgarian company, EU hosting
Where LogSentinel falls short
- Smaller integration catalogue than the enterprise SIEMs
- Less third-party threat intelligence
- Smaller vendor than the incumbents it replaces
- Detection content needs tuning to your estate
Standout feature. An audit trail whose integrity is proven rather than promised.
Prague, Czech Republic
Appliance licence by volume
Demo on request
Best for: IT teams running a SIEM without a dedicated SOC
Logmanager is a Czech log management and SIEM appliance built on a premise most of this category ignores: that the organisation deploying it does not have a security operations centre to run it.
Simplicity is the product decision. Parsing, dashboards and detection arrive configured for the systems most organisations actually run, so a two-person IT team gets useful alerts in days rather than standing up a query-writing practice — which is why an unstaffed enterprise SIEM so often decays into an expensive log archive. Collection, search, correlation and compliance reporting are all in the appliance.
Logmanager is based in Prague with a team in Brno, serving mostly Central European customers, and became part of the European Guardsix group in 2026. The appliance runs on your own infrastructure, virtual or physical, so the logs never leave it.
What Logmanager does well
- Usable by an IT team without a SOC
- Appliance runs on your own infrastructure
- Parsing and dashboards preconfigured for common systems
- Licensed on volume, with no per-user or per-query metering
- Czech company, Central European support
Where Logmanager falls short
- Less depth than an enterprise SIEM at the top end
- Appliance model means capacity planning is yours
- Smaller ecosystem outside Central Europe
- Volume licensing punishes very chatty log sources
Standout feature. A SIEM that produces useful alerts without a team hired to operate it.