A Fluent Bit alternative built for security teams

Collect what Fluent Bit can't see.

Windows Event Log, ETW, file integrity, syslog, and network capture — one cross-platform agent, managed from a single console and delivered to any SIEM.

NXLog Syslog Server

Fortune 500 companies trust NXLog

Verizon 2024 1 Frame Group 25762 Fujitsu Logo 1 J P Morgan Logo 2008 1 1

Fluent Bit vs. NXLog Platform at a glance

With Fluent Bit today
With NXLog Platform
Built for
Cloud-native observability — logs, metrics, and traces for containers
Security log collection, from endpoint to SIEM
Windows Event Log
winevtlog plugin: interval polling, 512 KiB default read limit per cycle, offset database optional
Native collection with full EventData/UserData and SID-to-account resolution
ETW telemetry (DNS, Firewall, kernel)
Not available
im_etw reads ETW providers directly, no trace files
Agentless Windows collection (WEF)
Not available
NXLog Agent runs as a Windows Event Collector for remote hosts
File integrity & Registry monitoring
Not available
im_fim on Windows and Linux; im_regmon for the Windows Registry
Network capture
Not available
Passive capture with im_pcap, including ICS protocols
Operating systems
Linux, macOS, Windows, BSD
Adds AIX and Solaris; x86/x64/ARM/PowerPC
Fleet management & support
Per-host config files; central management and support sold by third parties
Built in: enrollment, configuration, monitoring, up to 100,000 agents per node, vendor support

Try NXLog Platform alongside Fluent Bit

Why teams choose NXLog Platform

Group 25814

Windows done fully, not partially

Fluent Bit reads Windows Event Log channels. NXLog Agent goes further: complete EventData and UserData fields, SID-to-account resolution, XPath filtering, and remote collection over Windows Event Forwarding — from one agent, without extra tooling.

Group 25812

See below the Event Log

Debug and Analytical channels — DNS Server, Windows Firewall, kernel providers — are ETW-based and can't be collected as regular Event Log channels. The im_etw module reads ETW providers directly, with no intermediate trace files to parse.

Group 25813

Sources observability agents skip

File integrity monitoring, Windows Registry changes, passive packet capture, ODBC databases, Check Point OPSEC LEA, Linux Audit, and macOS ULS. NXLog Agent collects the sources SOC work depends on, not just container logs.

Group 25811

Management is in the box

Open-source Fluent Bit is configured one host at a time, and central fleet management for Fluent Bit agents is a separate commercial product (Chronosphere Telemetry Pipeline). NXLog Platform includes enrollment, configuration, monitoring, and updates for up to 100,000 agents per node.

Group 25815

Keep Fluent Bit where it's strong

Fluent Bit is a solid choice for container and Kubernetes log routing — keep it there if it serves you well. Run NXLog Agent across your Windows fleet, servers, and compliance scope, and let both deliver to the same SIEM.

07 cap4 icon

Any SIEM, no lock-in

NXLog is vendor-agnostic. Deliver parsed, normalized events to Splunk, Microsoft Sentinel, Elastic, Google SecOps, or any syslog, HTTP(S), or Kafka destination — with built-in storage and analytics when you want retention outside the SIEM.

Need help? Book a short migration workshop

Value by Team

Group 25783

SecOps Engineer

Close the collection gaps that stall investigations. ETW, file integrity events, and complete Event Log fields turn "we don't have that data" into detections.

Group 25784

Detection Engineer

Hunt with richer telemetry: DNS analytical logs, Sysmon, PowerShell, Registry changes, and packet-level fields — parsed and normalized at the source.

Group 25922

Compliance & GRC Owner

Meet file integrity and audit-trail requirements without another tool: FIM on Windows and Linux, TLS-encrypted delivery, tamper-proof audit logs, and built-in retention.

Group 25923

Security Architect

One agent across six operating systems, on-premises deployment options, and no vendor lock-in — collection that fits the estate you run today.

What you get with NXLog Platform 

One agent, every OS you run

A single cross-platform agent for Windows, Linux, macOS, BSD, AIX, and Solaris on x86/x64/ARM/PowerPC — collect, parse, and route at the source.

Windows telemetry in full

Event Log with complete fields and SID resolution, ETW providers, Windows Event Collector mode for agentless hosts, Registry monitoring, and Windows performance counters.

Security sources beyond the OS

File integrity monitoring, passive network capture with ICS protocol support, ODBC database collection, Check Point OPSEC LEA, Linux Audit, and macOS ULS.

Parse, filter, and enrich at the source

Parse syslog, JSON, XML, CSV, and key-value data, filter noise before it reaches your SIEM, and enrich events at the point of collection. Need custom logic? Extend the agent with Perl, Python, Ruby, Java, or Go.

Fleet management built in

Enroll, configure, monitor, and update agents from one console — with role-based access control, audit trails, and support for up to 100,000 agents per node.

Storage and analytics without add-ons

Built-in high-compression retention, fast search, and dashboards. Use them alongside your SIEM or on their own.

Try NXLog Platform for free

FAQs

For syslog, file tailing, and Windows Event Log forwarding — yes. NXLog Agent collects the same data and delivers it to the same destinations, then adds sources Fluent Bit doesn't offer: ETW, file integrity monitoring, packet capture, Windows Event Forwarding, and databases. Many teams keep Fluent Bit in Kubernetes and run NXLog everywhere else.

Yes. Both deliver to the same SIEMs and log platforms, so a phased rollout is safe: one destination, two collection layers, no downtime.

ETW providers (including DNS Server analytical logging and Windows Firewall), Debug and Analytical channels, remote collection over Windows Event Forwarding, Registry change monitoring, and file integrity events. Fluent Bit's Windows log inputs cover Event Log channels only.

Yes. NXLog integrates with OpenTelemetry pipelines, so adopting NXLog Platform doesn't take you off open standards. See the NXLog OpenTelemetry solution page for details.

No. Agent enrollment, configuration, health monitoring, and updates are part of NXLog Platform. With open-source Fluent Bit, central management comes from separate commercial tools.

Splunk, Microsoft Sentinel, Elastic, Google SecOps, OpenSearch, and any syslog, HTTP(S), or Kafka destination. NXLog Platform also includes its own storage and analytics if you want retention outside the SIEM.

Fluent Bit is a trademark of The Linux Foundation (project hosted by the Cloud Native Computing Foundation). Product information is based on publicly available documentation as of July 2026.