Energy Logserver logo
Observability Monitoring · Privacy Security

Energy Logserver

Energy Logserver is an on-premise SIEM and log management platform built on Elasticsearch. It combines log collection, security correlation, network probing, SOAR automation and an AI assistant that can run entirely inside the customer's own infrastructure.

Active Contact Sales API available Verified by Guidaio
Overview

What is Energy Logserver?

Energy Logserver is a security and observability platform published by EMCA SOFTWARE Sp. z o.o. of Warsaw, and installed on the customer's own infrastructure rather than consumed as a hosted service. Its foundation is the Log Management Plan, an Elasticsearch-backed store for events from across the IT estate. The vendor's central commercial argument is the absence of ceilings: the site states there are no limits on the number of events, gigabytes per day or number of data sources, which positions it against SIEM products metered by ingested volume.

Around that base sit several licensed modules. The SIEM Plan adds hundreds of predefined correlation rules, vulnerability detection aligned to CIS benchmarks, File Integrity Monitoring, incident handling, risk assessment, MISP threat-intelligence feeds and mapping of detections onto MITRE ATT&CK. The Network Probe captures netflow and traffic copies, analyses layers 2 to 7, reports on DNS, DHCP, server response time and round-trip time, and uses behavioural analysis to flag zero-day activity. Energy SOAR contributes case management, playbooks, workflow automation, webhooks and multitenancy. Energy XDR is the commercial bundle combining SIEM, SOAR, Network Probe and the AI module.

The artificial intelligence is functional rather than decorative. The documented AI and Analytics module covers anomaly detection, advanced analytics, a model library and an AI Assistant, with an AI Agent available from the Discover tab. Log entries, prompts and uploaded PDF Knowledge Chapters are vectorised, and the agent queries those vector indices in a retrieval-augmented pattern. The model can interpret an event, flag a probable threat semantically, suggest alert rules, prioritise, classify and extract indicators of compromise. Customers choose the language model provider: a dedicated engine hosted by the vendor, the AI on Prem hardware appliance running models locally, or external services such as Ollama, OpenAI or Fireworks. An AI Store distributes preconfigured AI use cases. The AI work stems from a Polish National Centre for Research and Development project, POIR.01.01.01-00-0152/22. Documentation is public and currently at version 8.0.

What it does

  • Centralise logs and events from the whole IT estate with no cap on events, daily volume or number of sources
  • Detect threats using hundreds of predefined correlation rules and map them to MITRE ATT&CK tactics
  • Analyse network traffic and netflow from layers 2 to 7 with the Network Probe
  • Automate incident response through playbooks, workflows and case management in Energy SOAR
  • Query and interpret log data in natural language through the AI Assistant and AI Agent in Discover
  • Detect anomalies in event data using machine learning models from the Empowered AI module
  • Generate compliance reporting for GDPR, PCI-DSS, NIST 800-53, HIPAA, ISO 27001 and CIS
Audience

When to use Energy Logserver / When not to

A quick filter to help you decide if Energy Logserver is the right fit.

When to use Energy Logserver

  • Security operations centre teams that need a SIEM priced by licence rather than by daily data volume
  • CISOs and security architects in organisations where log data must never leave the corporate network
  • Public-sector IT departments procuring SIEM and SOAR capability under structured tender requirements
  • Compliance and audit teams that must evidence controls against GDPR, PCI-DSS, NIST 800-53, HIPAA, ISO 27001 and CIS
  • Managed security service providers needing multi-tenant source management through the dedicated MSSP licence

When not to use Energy Logserver

  • Buyers who need transparent public pricing, since no rate, currency or plan cost is published anywhere
  • Small teams looking for a self-service sign-up, as every route to the product runs through a sales conversation
  • Organisations wanting a permanent free tier, because each documented plan requires a licence file
  • Users expecting a mobile application, as no iOS or Android app is offered
  • Teams wanting to rely on public LLM providers in production, which the vendor itself advises against for sensitive data
Get started

How to use Energy Logserver

A typical end-to-end flow, from setup to results.

  1. Explore the linked public demonstration environment or request a guided presentation through the site form
  2. Contact the sales team, since there is no self-service purchase route and no published price
  3. Size the deployment, using the EPS calculator published in the site's resources section as a starting point
  4. Install the platform on your own servers following the Installation section of the knowledge base
  5. Place the two licence files, .license and .info, in the installation directory or load them through the GUI
  6. Add the modules you have licensed, such as SIEM Plan, Network Probe, Energy SOAR or the AI Assistant
  7. Connect data sources using SNMP, API, JDBC or WMI, and deploy agents such as Metricbeat or Filebeat
  8. Open the Empowered AI module and use the Assistant Wizard tabs for Prompts, Knowledge and Providers
  9. Register a language model provider, either the vendor's hosted engine, an AI on Prem appliance or an external endpoint
  10. Work from the Discover tab to search data and question the AI Assistant, verifying its output before acting
Quick read

Pros & Cons

Pros

  • No licensing ceiling on events, daily gigabytes or number of data sources on the base platform
  • Artificial intelligence can run entirely on customer premises through the AI on Prem appliance, with no data leaving the network
  • For vendor-operated providers, prompts are neither stored nor logged and traffic is encrypted
  • The language model provider is the customer's choice, including a fully self-hosted Ollama endpoint
  • Broad functional coverage in one platform: log management, SIEM, network probe, SOAR, XDR, UEBA and AI
  • Large published integration catalogue spanning roughly sixty technologies
  • Complete, versioned public documentation with a documented REST API

Cons

  • No public pricing whatsoever: no rate, no currency and no pricing page anywhere on the site
  • No terms and conditions, licence agreement or legal notice is published
  • The privacy policy covers cookies only, with no retention policy, subprocessor list or data processing agreement
  • The vendor's own documentation contradicts itself on whether the AI Assistant costs extra
  • No mobile application is offered
  • Site and documentation are available in English only, with no declared interface languages
  • Several pages are empty or simply re-serve the homepage, making the site hard to evaluate
Pricing

Pricing & Plans

No pricing is published. The site carries no pricing page, and probes of the usual paths returned the same not-found response as a deliberately invalid address, while the sitemap lists no tariff page. Commercially the product is sold through direct contact and a partner network. Licensing is file-based: each licence consists of a .license and .info pair carrying an expiry date, the enabled plans, the permitted number of cluster nodes and other limits. No permanent free plan is documented, and every plan described in the documentation requires a licence. Because no amount is public, and because the actual regime is a node-based licence that none of the available billing units describes, the starting price, currency and billing unit have deliberately been left empty together rather than populated with a misleading figure. The AI on Prem appliance is a separate hardware offering quoted on request. Prospective buyers should note one contradiction in the vendor's own documentation: the licensing page lists the AI Assistant as an add-on requiring an additional licence, while the AI Assistant page states it is available at no additional cost to customers holding an active support agreement.

Log Management Plan (LMP)
  • base platform for centralised log management and operational monitoring
Network Probe
  • add-on package for network traffic analysis
  • sold by configurable node count
  • requiring an additional licence
AI Assistant
  • add-on enabling language-model features in Discover
  • listed as requiring an additional licence
MSSP
  • mode for managed service providers enabling multi-tenant source management
  • requiring an additional licence
Energy XDR
  • commercial bundle presented as combining Logserver and SIEM
  • Energy SOAR
  • Network Probe and Empowered AI
Plan 7
  • No price is attached to any of these plans
Special offers — No promotional, student or reduced-rate offer is published on the site · The closest element is the AI Assistant, presented on the AI documentation page as carrying no additional cost for customers with an active support agreement, although the licensing page contradicts this
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Energy Logserver handles your data.

GDPR overview

GDPR appears in two distinct roles, which should not be confused. As a product capability, Energy Logserver ships dashboards and reports that help customers evidence compliance with GDPR alongside PCI-DSS, NIST 800-53, HIPAA, ISO 27001 and CIS. As a matter of the vendor's own compliance, disclosure is thin: the privacy policy covers cookies only and names the controller as EMCA SOFTWARE Sp. z o.o., ul. Wiejska 20, 00-490 Warszawa, with NIP 701-082-15-58, REGON 380162627 and KRS 0000730493. Form consent language references GDPR and mentions rights of access, rectification and objection. No data processing agreement, no subprocessor list and no retention policy is published. The publisher is established in Poland, so no Article 27 representative is required. The site never claims the product itself is GDPR compliant.

Who owns the data?

No terms and conditions, licence agreement or legal notice is published on the site, so ownership of customer data is not stated contractually anywhere in public. What can be established is architectural rather than legal: the platform is installed inside the customer's own infrastructure, so collected logs remain on customer-controlled systems. Where the AI on Prem appliance is used, the vendor states that all processing runs on your own infrastructure with no data leaving your network. The site's privacy policy addresses cookies only and names EMCA SOFTWARE Sp. z o.o. as data controller for the website itself. Prospects should expect ownership terms to be settled in the licence contract, not on the website.

Reuse rights

Because no public terms exist, there is no published clause granting or restricting reuse of data by the customer. In practice the deployment model leaves the data in the customer's hands. The documented AI behaviour is more precise: the AI Assistant does not send raw log content or prompt text to the language model. Log entries, prompts and uploaded Knowledge Chapters are converted into numerical vectors first, and the vendor states these vectors cannot be used to reconstruct the original text. Original documents are never re-sent to the model. For providers operated by the vendor, communication is encrypted and prompts are neither stored nor logged. If a customer configures a public provider such as OpenAI, Anthropic or Fireworks, the vendor warns those providers may analyse prompts and profile usage, and recommends restricting them to testing.

Data retention & training

Retention summary
No retention policy is published. A targeted search across the whole collected corpus, in both extracted text and archived HTML, returned no retention wording at all, and the site's privacy policy deals only with cookies. In practice retention is a customer configuration matter, since the platform runs on customer infrastructure and offers an archiving capability described as easy management of fast archives. On the AI side, the vendor states that prompts are neither stored nor logged for the providers it operates, while vectorised Knowledge Chapters are held in a dedicated index with no stated lifetime. Activity on the demonstration platform is recorded in audit files, again with no stated duration. Retention terms should therefore be expected to come from the contract rather than the website.
Trains on customer data
Configurable

Hosting summary

Hosting is primarily the customer's own responsibility, because the platform is installed on customer infrastructure rather than delivered as a hosted service. Collected logs therefore reside wherever the customer runs the cluster, and no vendor jurisdiction applies to them. Where the AI on Prem appliance is deployed, the vendor states that all processing runs on your own infrastructure with no data leaving your network. One vendor-side exception exists: the default language model provider is described as a dedicated engine fully hosted in the publisher's own data centre, with encrypted communication and no prompt storage or logging. No country or region is named for that data centre, so no hosting jurisdiction can be recorded. The publisher is established in Warsaw, Poland, but inferring a hosting location from that would go beyond what the site states. The marketing website itself sits behind Cloudflare, which reflects the website's delivery and not the platform's data hosting.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Energy Logserver.

  • No published contract: with no terms, licence agreement or legal notice online, data ownership and liability are undefined until negotiation
  • Automation bias: the vendor warns that model output is one input only and must be verified by an analyst before operational decisions
  • Choosing a public language model provider can expose sensitive security data, which the vendor advises against for production
  • The publisher's documentation contradicts itself on whether the AI Assistant requires an extra licence, so budgets may be misjudged
  • No published retention rules mean deletion and archiving behaviour depend entirely on local configuration and contract
  • Semantic detection may create false confidence: vectorised analysis is probabilistic, not deterministic rule matching
  • The site brands itself Energy Logserver while the contracting entity is EMCA SOFTWARE Sp. z o.o., a distinction to keep clear in procurement
Setup

Setup & Integrations

Technical difficulty

Setup is demanding and clearly aimed at technical teams rather than end users. The platform is installed on customer servers, runs as an Elasticsearch-based cluster, and is activated by placing two licence files in the installation directory or loading them through the interface, with command-line updates also documented. Data sources must be connected through SNMP, API, JDBC or WMI and agents deployed and managed centrally. Adding AI on Prem requires racking an appliance, assigning it an address and opening firewall rules to the interface node. The vendor argues that ready-made integrations and data standardisation shorten implementation, but system administration skills remain essential.

Deployment

Web appAPI

Integrations

ActiveMQ Ansible Amazon Web Services Microsoft Azure Apache Cassandra Catchpoint Check Point Cisco Elasticsearch F5 Filebeat Fireworks AI Forcepoint Fortinet Fudo Security GitHub GitLab Apache Hadoop Jira Juniper Networks Apache Kafka Kibana Logstash McAfee Metricbeat Microsoft Active Directory Microsoft IIS Microsoft SCOM Microsoft Teams MISP MITRE ATT&CK MongoDB Microsoft SQL Server MySQL Nagios Nginx Ollama Op5 Monitor OpenAI Oracle Palo Alto Networks Pmacct PostgreSQL Prometheus Qualys RabbitMQ Rapid7 ServiceNow Slack SolarWinds Apache Solr Apache Spark Suricata Tenable Apache Tomcat Uberagent VMware Wazuh Zabbix Zeek
Company

Behind Energy Logserver

Company name
EMCA SOFTWARE Sp. z o.o.
Founded
08/05/2018
Country of origin
🇵🇱 Poland
Headquarters
ul. Wiejska 20, 00-490 Warszawa, Poland
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇩🇩 Germany

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

Is Energy Logserver installed on our own servers or used as a cloud service?
It is deployed on the customer's own infrastructure. The platform is licensed through two files placed in the installation directory or loaded through the web interface, and it runs as a cluster whose permitted node count is set by the licence.
How much does Energy Logserver cost?
No price is published. There is no pricing page on the site and the sitemap lists none. The product is sold through direct contact with the vendor's sales team and through its partner network, so a quotation must be requested.
Is there a free plan or a free trial?
No permanent free plan is documented, and every plan in the licensing documentation requires a licence. A demonstration environment is linked from the homepage and a demo-account page exists, but a demonstration is not the same as a free trial and none is announced.
Does the AI send our logs to an external language model?
Not by default. Log entries and prompts are converted into numerical vectors before processing, and the vendor states these cannot be used to reconstruct the original text. The provider can also be entirely local through the AI on Prem appliance, in which case no data leaves your network.
Are our prompts stored or logged?
For the providers operated by the vendor, the documentation states that prompts are not stored or logged and that prompt logging is not implemented. Communication with those providers is encrypted.
Can we use OpenAI or Anthropic as the model provider?
Yes, external providers including Ollama, OpenAI, Fireworks and Anthropic are supported and configured with a URL and model name. The vendor explicitly advises against public providers for production security data, recommending them for testing and evaluation only.
Does the platform offer an API?
Yes. The knowledge base contains an API and Integrations section documenting a REST API alongside XLSX import.
Which compliance frameworks does it support?
The product provides dashboards and reports supporting GDPR, PCI-DSS, NIST 800-53, HIPAA, ISO 27001 and CIS. These are frameworks the product helps you report against; they are not certifications held by the publisher, and none is published.
Who publishes Energy Logserver?
EMCA SOFTWARE Sp. z o.o., based at ul. Wiejska 20 in Warsaw, Poland, registered in the National Court Register under KRS 0000730493. It is a wholly owned subsidiary of EMCA S.A.
Is there a mobile application?
No. The platform is used through its web interface and its REST API, and no iOS or Android application is offered anywhere on the site.
Conclusion

Should you pick Energy Logserver?

Energy Logserver is a broad, self-hosted security and observability platform rather than a narrow AI product. Its distinguishing commitment is architectural: the base platform is sold without ceilings on events, daily volume or data sources, and the artificial intelligence can be run entirely inside the customer's own network through the AI on Prem appliance. For organisations whose log data cannot legally or politically leave their premises, that combination is the reason to look at it. The AI is genuinely functional, covering anomaly detection, a model library, vectorised retrieval over uploaded documents and an assistant embedded in the search interface, and the vendor is unusually candid about its limits, stating that results should be treated as one input and verified by a security analyst.

The reservations are commercial and documentary rather than technical. Nothing about price is public: there is no pricing page, no amount and no currency, and the product is reachable only through a sales conversation. More unusually for an enterprise security vendor, the site publishes no terms and conditions, no licence agreement and no legal notice, and its privacy policy covers cookies alone, with no retention policy, subprocessor list or data processing agreement. The publisher's own documentation also contradicts itself on whether the AI Assistant carries an extra licence cost. Buyers should expect to settle data ownership, retention and processing terms in contract negotiation, since the website settles none of them. The publisher itself is verifiable and established: EMCA SOFTWARE Sp. z o.o. of Warsaw, registered in 2018 and wholly owned by EMCA S.A., which dates from 2001. The product is actively maintained, currently at version 8.0.