axodetect-launch

Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional

Now in early access, AxoDetect runs Sigma rules in stream - alerts travel to the SIEM, full-fidelity logs land in AxoLake, a low-cost security data lake

Stamford, CT, September 16, 2026 - Detection engineers do not need more detections. They need their existing detections to fire earlier, on cleaner data, without paying SIEM ingest rates for the privilege. Announced during Splunk .conf26, AxoDetect, Axoflow's detection component, now in early access, runs a customer's rules directly in the pipeline, on clean, normalized security data, before anything reaches the SIEM.

The result decomposes the SIEM's oldest bargain. Alerts travel to the SIEM. Full-fidelity logs land in AxoLake - Axoflow's low-cost security data lake that also runs on-prem. The SIEM stops working as an expensive log management solution and becomes what analysts actually use: a SecOps workflow engine, now optional to feed in full.

Detection engineers write new Sigma rules, tune existing ones, and pick up rules from the community, in one open format that carries across tools. AxoDetect runs them in the pipeline. What the platform adds is visibility that never lived in one place: what data is coming in, which detection each source feeds, and where a rule lacks the data it needs. Until now that was back-and-forth between teams - detections owned by one, data by another - held together with duct tape and tool-switching. For the CISO, the champion's win reads as a SIEM bill cut by half or more, with coverage kept intact: a global industrial company cut SIEM costs 50% and mean time to resolution 85%; a government agency cut data volume 80% and infrastructure footprint 85%.

"The SIEM became the industry's most expensive data swamp because it was the place where we kept all of our raw data," said Balázs Scheidler, CEO and co-founder of Axoflow and creator of syslog-ng™.

That constraint is gone. Detection belongs in the data layer, on normalized data, before the ingest meter starts. Keep your workflow in the SIEM. Send the alerts, but not your entire data estate."

Where the platform is going: the full detection lifecycle running where the data lives, rolling out in the months ahead.

Follow Our Progress!

We are excited to be realizing our vision above with a full Axoflow product suite.

Sign Me Up
This button is added to each code block on the live site, then its parent is removed from here.

Fighting data Loss?

Balázs Scheidler

Book a free 30-min consultation with syslog-ng creator Balázs Scheidler

Recent News

Axoflow Named Finalist in SiliconANGLE's 2026 TechForward Awards for Security Operations & Response
Axoflow at Gartner Security & Risk Management Summit, London
Axoflow at Splunk .conf26