
Energy Logserver
Energy Logserver is an on-premise SIEM and log management platform built on Elasticsearch. It combines log collection, security correlation, network probing, SOAR automation and an AI assistant that can run entirely inside the customer's own infrastructure.
What is Energy Logserver?
Energy Logserver is a security and observability platform published by EMCA SOFTWARE Sp. z o.o. of Warsaw, and installed on the customer's own infrastructure rather than consumed as a hosted service. Its foundation is the Log Management Plan, an Elasticsearch-backed store for events from across the IT estate. The vendor's central commercial argument is the absence of ceilings: the site states there are no limits on the number of events, gigabytes per day or number of data sources, which positions it against SIEM products metered by ingested volume.
Around that base sit several licensed modules. The SIEM Plan adds hundreds of predefined correlation rules, vulnerability detection aligned to CIS benchmarks, File Integrity Monitoring, incident handling, risk assessment, MISP threat-intelligence feeds and mapping of detections onto MITRE ATT&CK. The Network Probe captures netflow and traffic copies, analyses layers 2 to 7, reports on DNS, DHCP, server response time and round-trip time, and uses behavioural analysis to flag zero-day activity. Energy SOAR contributes case management, playbooks, workflow automation, webhooks and multitenancy. Energy XDR is the commercial bundle combining SIEM, SOAR, Network Probe and the AI module.
The artificial intelligence is functional rather than decorative. The documented AI and Analytics module covers anomaly detection, advanced analytics, a model library and an AI Assistant, with an AI Agent available from the Discover tab. Log entries, prompts and uploaded PDF Knowledge Chapters are vectorised, and the agent queries those vector indices in a retrieval-augmented pattern. The model can interpret an event, flag a probable threat semantically, suggest alert rules, prioritise, classify and extract indicators of compromise. Customers choose the language model provider: a dedicated engine hosted by the vendor, the AI on Prem hardware appliance running models locally, or external services such as Ollama, OpenAI or Fireworks. An AI Store distributes preconfigured AI use cases. The AI work stems from a Polish National Centre for Research and Development project, POIR.01.01.01-00-0152/22. Documentation is public and currently at version 8.0.
What it does
- Centralise logs and events from the whole IT estate with no cap on events, daily volume or number of sources
- Detect threats using hundreds of predefined correlation rules and map them to MITRE ATT&CK tactics
- Analyse network traffic and netflow from layers 2 to 7 with the Network Probe
- Automate incident response through playbooks, workflows and case management in Energy SOAR
- Query and interpret log data in natural language through the AI Assistant and AI Agent in Discover
- Detect anomalies in event data using machine learning models from the Empowered AI module
- Generate compliance reporting for GDPR, PCI-DSS, NIST 800-53, HIPAA, ISO 27001 and CIS
When to use Energy Logserver / When not to
A quick filter to help you decide if Energy Logserver is the right fit.
When to use Energy Logserver
- Security operations centre teams that need a SIEM priced by licence rather than by daily data volume
- CISOs and security architects in organisations where log data must never leave the corporate network
- Public-sector IT departments procuring SIEM and SOAR capability under structured tender requirements
- Compliance and audit teams that must evidence controls against GDPR, PCI-DSS, NIST 800-53, HIPAA, ISO 27001 and CIS
- Managed security service providers needing multi-tenant source management through the dedicated MSSP licence
When not to use Energy Logserver
- Buyers who need transparent public pricing, since no rate, currency or plan cost is published anywhere
- Small teams looking for a self-service sign-up, as every route to the product runs through a sales conversation
- Organisations wanting a permanent free tier, because each documented plan requires a licence file
- Users expecting a mobile application, as no iOS or Android app is offered
- Teams wanting to rely on public LLM providers in production, which the vendor itself advises against for sensitive data
How to use Energy Logserver
A typical end-to-end flow, from setup to results.
- Explore the linked public demonstration environment or request a guided presentation through the site form
- Contact the sales team, since there is no self-service purchase route and no published price
- Size the deployment, using the EPS calculator published in the site's resources section as a starting point
- Install the platform on your own servers following the Installation section of the knowledge base
- Place the two licence files, .license and .info, in the installation directory or load them through the GUI
- Add the modules you have licensed, such as SIEM Plan, Network Probe, Energy SOAR or the AI Assistant
- Connect data sources using SNMP, API, JDBC or WMI, and deploy agents such as Metricbeat or Filebeat
- Open the Empowered AI module and use the Assistant Wizard tabs for Prompts, Knowledge and Providers
- Register a language model provider, either the vendor's hosted engine, an AI on Prem appliance or an external endpoint
- Work from the Discover tab to search data and question the AI Assistant, verifying its output before acting
Pros & Cons
Pros
- No licensing ceiling on events, daily gigabytes or number of data sources on the base platform
- Artificial intelligence can run entirely on customer premises through the AI on Prem appliance, with no data leaving the network
- For vendor-operated providers, prompts are neither stored nor logged and traffic is encrypted
- The language model provider is the customer's choice, including a fully self-hosted Ollama endpoint
- Broad functional coverage in one platform: log management, SIEM, network probe, SOAR, XDR, UEBA and AI
- Large published integration catalogue spanning roughly sixty technologies
- Complete, versioned public documentation with a documented REST API
Cons
- No public pricing whatsoever: no rate, no currency and no pricing page anywhere on the site
- No terms and conditions, licence agreement or legal notice is published
- The privacy policy covers cookies only, with no retention policy, subprocessor list or data processing agreement
- The vendor's own documentation contradicts itself on whether the AI Assistant costs extra
- No mobile application is offered
- Site and documentation are available in English only, with no declared interface languages
- Several pages are empty or simply re-serve the homepage, making the site hard to evaluate
Pricing & Plans
No pricing is published. The site carries no pricing page, and probes of the usual paths returned the same not-found response as a deliberately invalid address, while the sitemap lists no tariff page. Commercially the product is sold through direct contact and a partner network. Licensing is file-based: each licence consists of a .license and .info pair carrying an expiry date, the enabled plans, the permitted number of cluster nodes and other limits. No permanent free plan is documented, and every plan described in the documentation requires a licence. Because no amount is public, and because the actual regime is a node-based licence that none of the available billing units describes, the starting price, currency and billing unit have deliberately been left empty together rather than populated with a misleading figure. The AI on Prem appliance is a separate hardware offering quoted on request. Prospective buyers should note one contradiction in the vendor's own documentation: the licensing page lists the AI Assistant as an add-on requiring an additional licence, while the AI Assistant page states it is available at no additional cost to customers holding an active support agreement.
- base platform for centralised log management and operational monitoring
- add-on package extending the base platform with SIEM capabilities
- requiring an additional licence
- add-on package for network traffic analysis
- sold by configurable node count
- requiring an additional licence
- add-on enabling language-model features in Discover
- listed as requiring an additional licence
- mode for managed service providers enabling multi-tenant source management
- requiring an additional licence
- commercial bundle presented as combining Logserver and SIEM
- Energy SOAR
- Network Probe and Empowered AI
- No price is attached to any of these plans
Data, GDPR & hosting
A consolidated view of how Energy Logserver handles your data.
GDPR overview
GDPR appears in two distinct roles, which should not be confused. As a product capability, Energy Logserver ships dashboards and reports that help customers evidence compliance with GDPR alongside PCI-DSS, NIST 800-53, HIPAA, ISO 27001 and CIS. As a matter of the vendor's own compliance, disclosure is thin: the privacy policy covers cookies only and names the controller as EMCA SOFTWARE Sp. z o.o., ul. Wiejska 20, 00-490 Warszawa, with NIP 701-082-15-58, REGON 380162627 and KRS 0000730493. Form consent language references GDPR and mentions rights of access, rectification and objection. No data processing agreement, no subprocessor list and no retention policy is published. The publisher is established in Poland, so no Article 27 representative is required. The site never claims the product itself is GDPR compliant.
Who owns the data?
No terms and conditions, licence agreement or legal notice is published on the site, so ownership of customer data is not stated contractually anywhere in public. What can be established is architectural rather than legal: the platform is installed inside the customer's own infrastructure, so collected logs remain on customer-controlled systems. Where the AI on Prem appliance is used, the vendor states that all processing runs on your own infrastructure with no data leaving your network. The site's privacy policy addresses cookies only and names EMCA SOFTWARE Sp. z o.o. as data controller for the website itself. Prospects should expect ownership terms to be settled in the licence contract, not on the website.
Reuse rights
Because no public terms exist, there is no published clause granting or restricting reuse of data by the customer. In practice the deployment model leaves the data in the customer's hands. The documented AI behaviour is more precise: the AI Assistant does not send raw log content or prompt text to the language model. Log entries, prompts and uploaded Knowledge Chapters are converted into numerical vectors first, and the vendor states these vectors cannot be used to reconstruct the original text. Original documents are never re-sent to the model. For providers operated by the vendor, communication is encrypted and prompts are neither stored nor logged. If a customer configures a public provider such as OpenAI, Anthropic or Fireworks, the vendor warns those providers may analyse prompts and profile usage, and recommends restricting them to testing.
Data retention & training
Hosting summary
Hosting is primarily the customer's own responsibility, because the platform is installed on customer infrastructure rather than delivered as a hosted service. Collected logs therefore reside wherever the customer runs the cluster, and no vendor jurisdiction applies to them. Where the AI on Prem appliance is deployed, the vendor states that all processing runs on your own infrastructure with no data leaving your network. One vendor-side exception exists: the default language model provider is described as a dedicated engine fully hosted in the publisher's own data centre, with encrypted communication and no prompt storage or logging. No country or region is named for that data centre, so no hosting jurisdiction can be recorded. The publisher is established in Warsaw, Poland, but inferring a hosting location from that would go beyond what the site states. The marketing website itself sits behind Cloudflare, which reflects the website's delivery and not the platform's data hosting.
Things to keep in mind
Risks and trade-offs to weigh before adopting Energy Logserver.
- No published contract: with no terms, licence agreement or legal notice online, data ownership and liability are undefined until negotiation
- Automation bias: the vendor warns that model output is one input only and must be verified by an analyst before operational decisions
- Choosing a public language model provider can expose sensitive security data, which the vendor advises against for production
- The publisher's documentation contradicts itself on whether the AI Assistant requires an extra licence, so budgets may be misjudged
- No published retention rules mean deletion and archiving behaviour depend entirely on local configuration and contract
- Semantic detection may create false confidence: vectorised analysis is probabilistic, not deterministic rule matching
- The site brands itself Energy Logserver while the contracting entity is EMCA SOFTWARE Sp. z o.o., a distinction to keep clear in procurement
Setup & Integrations
Technical difficulty
Setup is demanding and clearly aimed at technical teams rather than end users. The platform is installed on customer servers, runs as an Elasticsearch-based cluster, and is activated by placing two licence files in the installation directory or loading them through the interface, with command-line updates also documented. Data sources must be connected through SNMP, API, JDBC or WMI and agents deployed and managed centrally. Adding AI on Prem requires racking an appliance, assigning it an address and opening firewall rules to the interface node. The vendor argues that ready-made integrations and data standardisation shorten implementation, but system administration skills remain essential.
Deployment
Integrations
Behind Energy Logserver
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Is Energy Logserver installed on our own servers or used as a cloud service?
How much does Energy Logserver cost?
Is there a free plan or a free trial?
Does the AI send our logs to an external language model?
Are our prompts stored or logged?
Can we use OpenAI or Anthropic as the model provider?
Does the platform offer an API?
Which compliance frameworks does it support?
Who publishes Energy Logserver?
Is there a mobile application?
Should you pick Energy Logserver?
Energy Logserver is a broad, self-hosted security and observability platform rather than a narrow AI product. Its distinguishing commitment is architectural: the base platform is sold without ceilings on events, daily volume or data sources, and the artificial intelligence can be run entirely inside the customer's own network through the AI on Prem appliance. For organisations whose log data cannot legally or politically leave their premises, that combination is the reason to look at it. The AI is genuinely functional, covering anomaly detection, a model library, vectorised retrieval over uploaded documents and an assistant embedded in the search interface, and the vendor is unusually candid about its limits, stating that results should be treated as one input and verified by a security analyst.
The reservations are commercial and documentary rather than technical. Nothing about price is public: there is no pricing page, no amount and no currency, and the product is reachable only through a sales conversation. More unusually for an enterprise security vendor, the site publishes no terms and conditions, no licence agreement and no legal notice, and its privacy policy covers cookies alone, with no retention policy, subprocessor list or data processing agreement. The publisher's own documentation also contradicts itself on whether the AI Assistant carries an extra licence cost. Buyers should expect to settle data ownership, retention and processing terms in contract negotiation, since the website settles none of them. The publisher itself is verifiable and established: EMCA SOFTWARE Sp. z o.o. of Warsaw, registered in 2018 and wholly owned by EMCA S.A., which dates from 2001. The product is actively maintained, currently at version 8.0.
- Choosing a selection results in a full page refresh.
- Opens in a new window.