Balázs Scheidler - Axofllow
by 
Balázs Scheidler
July 23, 2026

Closing the Data-Detection Gap: What We're Building

SANS 2026: 80% of detection teams can barely keep pace. Faster rule-writing won't help, a stable data layer will. See how to run Sigma in-stream, before the SIEM
SANS 2026: 80% of detection teams can barely keep pace. Faster rule-writing won't help, a stable data layer will. See how to run Sigma in-stream, before the SIEM
Bence Csáti - Axoflow
by 
Bence Csáti
July 20, 2026

Raw Logs Get AI Triage Wrong. Every Time.

We gave a security agent raw, unnormalized vendor logs and asked it to triage a real attack scenario. Nine runs, zero correct. Here's why raw logs break AI triage — and what changes once the data is normalized and enriched.
Raw Logs Get AI Triage Wrong. Every Time.

All Articles

AxoSyslog 4.23–4.28 adds Splunk HEC and Elasticsearch Bulk API sources, an Apache Arrow Flight destination, 50% leaner memory queues, and new FilterX functions.
Róbert Fekete - Axoflow
by 
Robert Fekete
September 30, 2026

AxoSyslog 4.23–4.28: Splunk HEC, Elastic Bulk & Arrow Flight

AxoSyslog 4.23-4.28 adds Splunk HEC and Elasticsearch Bulk API sources, an Apache Arrow Flight destination, 50% leaner memory queues, and new FilterX functions.
migrating-to-microsoft-sentinel
james-luby
by 
James Luby
September 24, 2026

Migrating to Microsoft Sentinel: Beware of Ingestion Volumes

Sentinel's per-GB pricing turns every noisy, duplicate, unnormalized log into a recurring cost. Here's how to fix the data layer before it shows up on your bill.
james-luby
by 
James Luby
September 14, 2026

Migrating to Google SecOps: Building a Data Foundation That Doesn't Lock You In Twice

If you're moving to Google Security Operations (SecOps, formerly Chronicle), it's worth pausing on whether your migration plan avoids trading one form of lock-in for another. Learn why an autonomous, open data layer in front of SecOps is the answer.
james-luby
by 
James Luby
August 31, 2026

Migrating to Palo Alto Cortex XSIAM: Solving the "Getting Data In" Problem

XSIAM's AI-driven detection depends on clean, schema-mapped data. Here's why ingestion breaks down during migration, and how an open data layer fixes it.
ASD's ACSC Best Practices for Event Logging and Threat Detection
Sándor Guba - Axoflow
by 
Sándor Guba
August 6, 2026

ASD's ACSC Best Practices for Event Logging and Threat Detection: What the 9-Country Advisory Means for Your SOC

In August 2024, ASD's ACSC and 14 partner agencies from eight other countries published a shared logging baseline. Here's what the advisory's four pillars actually require - and how Axoflow's autonomous security data layer meets them.
Migrating off IBM QRadar: a security architect's guide to de-risking the move
james-luby
by 
James Luby
August 4, 2026

Migrating Off IBM QRadar: A Security Architect's Guide to De-Risking the Move

IBM QRadar's proprietary DSMs, QID taxonomy, and appliance-centric collection make an exit far riskier than a lift-and-shift. Here's how to decouple your security data layer first and turn a multi-quarter gamble into a controlled, staged cutover.
How decoupling ingestion from the SIEM makes migration less risky
james-luby
by 
James Luby
July 28, 2026

Migrating Off Splunk: A Security Architect's Playbook for Breaking the Ingest-Cost Spiral

Splunk migrations are triggered by ingest-cost economics, not query language. This playbook covers why Splunk configs resist clean migration and how decoupling ingestion from the SIEM de-risks the cutover.
SANS 2026: 80% of detection teams can barely keep pace. Faster rule-writing won't help, a stable data layer will. See how to run Sigma in-stream, before the SIEM
Balázs Scheidler - Axofllow
by 
Balázs Scheidler
July 23, 2026

Closing the Data-Detection Gap: What We're Building

SANS 2026: 80% of detection teams can barely keep pace. Faster rule-writing won't help, a stable data layer will. See how to run Sigma in-stream, before the SIEM
Raw Logs Get AI Triage Wrong. Every Time.
Bence Csáti - Axoflow
by 
Bence Csáti
July 20, 2026

Raw Logs Get AI Triage Wrong. Every Time.

We gave a security agent raw, unnormalized vendor logs and asked it to triage a real attack scenario. Nine runs, zero correct. Here's why raw logs break AI triage — and what changes once the data is normalized and enriched.

Subscribe to stay in touch

Sign up for our newsletter to be the first to knew about new articles. We are excited to be realizing our vision above with a full Axoflow product suite.