01

Real detection. Without the jump.
The measured step between full-scale log management and a complete AI SIEM.
On your infrastructure, at your pace, under your control.
Where PLUS fits
PLUS or AI SIEM? The line is simple.
Same platform. Same data. Same engineers. Moving up is a licence change — never a migration.
LogMan.io PLUS is SIEM, focused on the essentials.
A curated set of correlation rules for the most common attack patterns, real-time alerting, and compliance built in — the core of threat detection, run by rules you can read and control. Everything a growing team needs to start catching real threats, without the full engine.
LogMan.io AI SIEM is the full picture.
The complete correlation engine, plus autonomous AI agents, behavioural baselines that learn your environment, sovereign local inference, and natural-language investigation — detection that hunts on its own, at full scale.
The same engine underneath — now put to work.
500,000 events per second
The step up to detection costs you nothing in scale. PLUS runs on the same high-performance engine, sized for your busiest day and still holding headroom.
Detection out of the box
A curated rule set for the most common attack patterns runs from day one — no scripting, no consultants. Extend it yourself in plain SP-Lang whenever you need.
18 months, fully retained
Every event signed, compressed, and kept — an audit-ready archive purpose-built for NIS2 and the Czech Cybersecurity Act.
Not one byte offshore
Correlation, alerting, and enrichment run entirely on your infrastructure, on European soil. Detection never means handing over control.
From chaos to clarity: How LogMan.io works.
Input
Processing
02
Normalise
03
Enrich
04
Store & visualise
Output

What PLUS adds
Everything LogMan.io does — now watching for you.
Real-time event correlation
PLUS connects the dots across sources as events arrive — a failed login here, an unusual transfer there — and reconstructs the attack path mid-flight. A curated set of essential rules out of the box, plus your own in clean, readable SP-Lang.
Threat intelligence enrichment
Every ingested log is cross-referenced in real time against live feeds of known malicious IPs, command-and-control servers, and Indicators of Compromise — so a known-bad actor is flagged the moment it appears, not after the damage is done.
Automated alerts & notifications
Stop going to look. PLUS groups the raw noise into prioritised, actionable incidents and comes to you — the moment something crosses a line, your team knows, through the channels they already work in.
Compliance automation
Skip weeks of manual audit prep. Pre-built modules map your logs continuously to NIS2 and ISO 27001, and auditor-ready dashboards turn evidence-gathering into a single click.
Engineered for serious analytics
Stream-processing rule engine
Heavy correlation usually taxes the very system it's meant to protect. PLUS evaluates threat rules on the fly with lightweight stream processing — full analytics, no performance cliff.
Granular access control (RBAC)
Role-based permissions down to the log. Your security team, your departments, and external auditors each see only what their scope — and the law — allows.
Intelligent cold-storage archiving
Offload historical logs to cost-effective long-term storage while keeping every event instantly searchable. Historical queries run up to 10× faster — so an unexpected audit never means a wait.
Move at your own pace
One platform. Three tiers. No migrations, ever.
Start with LogMan.io for high-performance log management. Step up to PLUS the day you need active detection. Move to AI SIEM when you're ready for autonomous, AI-driven defence. Every step is a licence activation on the same platform — no new hardware, no data migration, no downtime, and the same engineers beside you the whole way.
Connects with your stack
Trusted where it matters
Protecting European enterprise and critical infrastructure — from national government and healthcare networks to media, logistics, and finance. The organisations that legally cannot send their data abroad run LogMan.io.

