Blog
Stay in the loop: Updates, Innovations, and Community Insights
Featured Articles


Beyond Cutting Cost: Why Data Quality Makes Security Pipelines Strategic
Anton Chuvakin and Tim Peacock interview Balázs Scheidler (Axoflow CEO and syslog-ng founder) about the industry’s move from centralization to data access. They discuss why poor data quality weakens SIEM value, how modern pipelines normalize and enrich data so it is ready for immediate use, and meet data quality requirements.


Axoflow’s Storage Strategy: Building the Security Data Layer
Discover Axoflow’s storage solutions for the Security Data Layer. From edge storage and cost-efficient data lakes to stream processing and air-gapped deployments, learn how Axoflow powers scalable, flexible, and reliable security data pipelines.


Splunk .conf25 - The Role of the Pipeline
Splunk .conf2025 experiences, and the increasing importance of the security data pipeline
All Articles


Log tapping to find rogue devices and parsing errors
Watch how to use log tapping to detect rogue devices, investigate parsing errors, and find out what’s wrong with the syslog messages your devices are sending.


How to install AxoSyslog on RHEL and AlmaLinux
Learn how to install AxoSyslog, our syslog-ng™ fork from our repository on RPM-based Linux distributions like RHEL, Fedora, or AlmaLinux.


AxoRouter, the security data curation pipeline engine
Most network appliances send improperly formatted log messages. AxoRouter automatically identifies your log sources, and fixes common errors in the incoming data, correcting missing hostnames, invalid timestamps, formatting errors, and so on. Don't spend time creating and maintaining rules or trying to fix processing bottlenecks.


Elasticsearch data stream, APT repository in AxoSyslog 4.8
AxoSyslog 4.8 release with APT repository, gRPC and S3 destination improvements, and the ability to send logs to Elasticsearch data streams


Logging operator 4.8 release
Logging operator 4.8 has arrived with routing based on namespace labels for multi-tenant scenarios, and other exciting features!


Using Telemetry Controller with Logging Operator
The Telemetry Controller turns telemetry event streams - logs, metrics, and traces - into Kubernetes resources. It provides a multi-tenant API on top of OpenTelemetry for isolation and access control for telemetry data.


Troubleshooting syslog errors with log tapping
Log tapping samples the log flow of your security data pipeline on demand. You can use labels to filter for specific messages and tap only those messages. You can investigate problematic events with a few clicks.


Logging operator 4.7 release
Logging operator 4.7 release comes with protected ClusterOutputs, disk buffer improvements, and more!


AxoSyslog is now a real fork
AxoSyslog is now a real fork of syslog-ng™. This blog post shows our plans going forward. TL;DR: AxoSyslog remains open source, uses the same license as syslog-ng™, and we continue to maintain it and add new features in the AxoSyslog repository.
Subscribe to stay in touch
Sign up for our newsletter to be the first to knew about new articles. We are excited to be realizing our vision above with a full Axoflow product suite.
