Logpoint

European SIEM with licensing you can predict - European alternative based in Denmark

Quick Overview

Company Logpoint
Category SIEM & Security Monitoring
Headquarters Copenhagen, Denmark
EU/European Yes - Denmark
GDPR Compliant Yes
Main Features SIEM with SOAR & UEBA, Predictable node licensing, EU-only deployment
Pricing Per node or per device licence
Best For European enterprises and public bodies replacing Splunk or QRadar
Replaces Splunk, Microsoft Sentinel, IBM QRadar

Detailed Review

Pros and Cons

Pros

  • Node-based licensing, not per gigabyte
  • SIEM, UEBA and SOAR in one platform
  • EU-only deployment options
  • Compliance reporting for NIS2 and ISO 27001
  • Danish company with EU certifications
  • Software, appliance or SaaS

Cons

  • Smaller detection content library than SEKOIA
  • Node counting needs care on large estates
  • Less third-party tooling than Splunk
  • Enterprise sales cycle

Alternatives to Logpoint

Looking for other European security monitoring platforms? Here are the alternatives worth comparing:

Frequently Asked Questions

Logpoint is based in Denmark and operates under European data-protection rules including the GDPR. Security logs contain personal data — usernames, IP addresses, access times — so this is a processing question as well as a security one.

Logpoint is based in Denmark. Security telemetry describes an organisation's defences and its failures, which is why the vendor's jurisdiction carries unusual weight here.

Log collection and normalisation across infrastructure and applications, correlation rules and threat detection, user and entity behaviour analytics, SOAR playbooks for automated response, and compliance reporting for NIS2, GDPR and ISO 27001.

Licensed per node or per device rather than per gigabyte ingested, which is the difference that decides most Splunk replacements. Available as software, appliance or SaaS.

Logpoint is a European alternative to Splunk, Microsoft Sentinel, IBM QRadar, generally with a cost model that does not scale directly with log volume.

Detection and logging are foundational to the NIS2 obligations around incident handling and reporting, and this category is where most of that capability sits. No product delivers compliance on its own — the directive covers governance, supply chain and reporting timelines too — but you cannot report an incident within the deadline if nothing detected it.

Who worked on this review

Three people touch every tool page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's own documentation.

Sebastiaan Smits
Written by

Sebastiaan Smits

Founder & Editor · Netherlands

Selects the tools, writes the reviews, and checks where each company is actually established.

Daniel Brandt
Edited by

Daniel Brandt

Privacy & Compliance Researcher · Berlin, Germany

Checks the compliance claims: where the company is established, where the data sits, and what the DPA actually says.

Marta Kowalczyk
Fact-checked by

Marta Kowalczyk

Senior Analyst, Infrastructure & Developer Tools · Warsaw, Poland

Covers hosting, developer tooling and the practical side of moving workloads to European providers.

Read our editorial process for how we source, verify and update these pages — and how we keep affiliate income separate from what we recommend.

Go to Logpoint