A Logmanager alternative built for security teams

Every OS in. Any SIEM out.

One appliance shouldn't decide what you can see. NXLog Agent collects security telemetry from Windows to AIX and delivers it to Splunk, Microsoft Sentinel, Google SecOps, OpenSearch, or Elastic — several at once — and NXLog Platform retains it without a per-GB meter.

NXLog Syslog Server

Fortune 500 companies trust NXLog

Verizon 2024 1 Frame Group 25762 Fujitsu Logo 1 J P Morgan Logo 2008 1 1

Logmanager vs. NXLog Platform at a glance

With Logmanager today
With NXLog Platform
Built for
An all-in-one appliance: collect, store, and search in one self-hosted box
Security log collection from every endpoint to any SIEM — storage included
Collection agents
Windows only — Elastic Filebeat and Winlogbeat under a Logmanager Orchestrator; other systems push syslog you configure per host
NXLog Agent on Windows, Linux, macOS, FreeBSD, AIX, and Solaris, on x86/x64, ARM, and PowerPC
Windows telemetry
Event Log channels and flat files — the documented scope of the bundled Beats
Every Event Log field with XPath filtering, ETW providers, file integrity, Registry, and performance counters
Sources beyond Windows
Syslog receivers and Microsoft 365; file logs on Linux mean hand-configured syslog daemons
Linux Audit, macOS unified log, ODBC databases, packet capture with ICS protocols, Check Point OPSEC LEA
SIEM delivery
One exit: a syslog output over TCP — messages are lost if the remote side stops responding, per the documentation
Native delivery to Splunk, Microsoft Sentinel, Google SecOps, Elastic, and OpenSearch, plus Kafka and OpenTelemetry — parallel routes with buffering
Agent management
Windows agents pull configuration from the appliance on a one-hour heartbeat
Enrollment, configuration, monitoring, and updates on every supported OS — up to 100,000 agents per node
Pricing & retention
Per GB stored; when the storage limit is exceeded, the oldest data is overwritten
Per source — no volume caps, no EPS limits, high-compression storage
Deployment
Self-hosted virtual appliance (VMware, Hyper-V, Proxmox) or hardware on demand
Cloud-hosted or on your own infrastructure — your choice

Run NXLog Agent alongside Logmanager and compare coverage

Why teams choose NXLog Platform

Group 25814

Deliver past the box

Logmanager's route to a third-party SIEM is a syslog output over TCP, and its documentation notes that messages are lost when the remote side stops responding. NXLog Agent delivers natively to Splunk, Microsoft Sentinel, Google SecOps, OpenSearch, and Elastic — several destinations in parallel, with disk buffering when a link goes down.

Group 25812

Agents where Logmanager has none

The Logmanager agent runs on Windows only; Linux and macOS hosts push syslog you set up and maintain per machine. NXLog Agent installs as a supported package on Windows, Linux, macOS, FreeBSD, AIX, and Solaris — one collection layer, enrolled and managed the same way everywhere.

Group 25813

Windows depth past Event Log channels

Logmanager's agent bundles Elastic Filebeat and Winlogbeat, so its documented scope is Event Log channels and flat files. NXLog Agent adds ETW providers, file integrity and Registry monitoring, performance counters, and a Windows Event Forwarding collector role — which can run on a Linux host.

Group 25811

Fleet changes without the hourly wait

Logmanager's Windows agents pull configuration from the appliance on a one-hour heartbeat. NXLog Platform handles enrollment, configuration, monitoring, and updates fleet-wide — up to 100,000 agents per node, with RBAC and audit trails over who changed what.

Group 25815

Keep Logmanager where it fits

A mostly-Windows estate, syslog-speaking network gear, one admin? Logmanager covers that well — keep it. NXLog Agent can feed the same box over syslog while adding what it lacks: agents beyond Windows, deeper endpoint telemetry, and delivery to the SIEM on your roadmap.

07 cap4 icon

Shape events before they ship

Logmanager drops events at the agent with Beats filters and parses on the appliance, after everything crosses the wire. NXLog Agent parses, rewrites, enriches, and masks at the source — extensible in Perl, Python, Ruby, Java, or Go — so what lands downstream is already clean.

Planning a rollout? Book a short workshop

Value by Team

Group 25783

SecOps Engineer

Feed Microsoft Sentinel, keep Logmanager's dashboards alive, and store an archive copy — all from the same agents, while the hand-edited rsyslog configs on your Linux fleet finally retire.

Group 25784

Detection Engineer

Detection logic is only as good as its inputs. Get full-fidelity Event Log fields, ETW providers, and Registry and file integrity changes, normalized by the agent — not reconstructed from syslog strings.

Group 25922

Compliance & GRC Owner

Retention set by policy, not by appliance capacity: high-compression storage, encrypted transport, file integrity events from the collection agent itself, and an audit trail on every fleet change.

Group 25923

Security Architect

One collection layer that can feed Logmanager today, your next SIEM tomorrow, and both during the switch — deployed from Windows to AIX, cloud or on-prem, so the next SIEM decision doesn't force the next agent rollout.

What you get with NXLog Platform 

Agents from Windows to AIX

One agent, from desktop Windows to AIX in the datacenter — supported packages on six operating systems and four processor families, with the same configuration language on all of them.

The full Windows security surface

Every Event Log channel and field with XPath filtering, ETW providers, Registry and file integrity monitoring, performance counters, and a collector role for Windows Event Forwarding — supported modules in one agent.

Sources past the syslog stream

Rows from databases over ODBC, Linux Audit rules, the macOS unified log and Endpoint Security, packet capture with ICS protocol support, Check Point OPSEC LEA, and Microsoft 365 — collected without side tooling.

Parse first, ship second

Events get parsed, filtered, and masked on the host that produced them — syslog, JSON, XML, CSV, and key-value pairs — with custom logic in Perl, Python, Ruby, Java, or Go when the built-ins aren't enough.

A fleet console built for scale

Enrollment, configuration, updates, and health for the whole estate in one console — gated by RBAC, recorded in audit trails, and rated for up to 100,000 agents per node.

Retention without a meter

Storage, search, and dashboards are part of the platform, with high compression keeping the footprint down. Hold data as long as policy demands, keep a copy outside the SIEM, or skip the SIEM entirely — the per-source price doesn't move.

Try NXLog Platform for free

FAQs

For collection, storage, search, and dashboards — yes, and each gets wider: agents on six operating systems instead of one, native SIEM delivery instead of a syslog output, and retention priced by source. Logmanager's correlation alerts don't transfer as-is; most teams rebuild detection in the SIEM that NXLog feeds, where those rules live long term.

Yes. Logmanager ingests syslog, and NXLog Agent speaks it — so you can upgrade the collection layer first and keep the box as your store. The same agents can mirror a second stream to Microsoft Sentinel, Splunk, or OpenSearch while you evaluate.

The Logmanager agent bundles Elastic Filebeat and Winlogbeat, which cover Windows Event Log channels and flat files. NXLog Agent adds ETW providers, file integrity and Registry monitoring, packet capture with ICS protocol support, database collection over ODBC, Linux Audit, and the macOS unified log — and it runs as a managed agent on Linux and macOS, which Logmanager's doesn't.

Yes. Deploy NXLog Platform on your own infrastructure or use the cloud-hosted service — agents, delivery, and storage work the same either way, so the choice is about where you want the console, not what you give up.

Logmanager charges for the data you store; by its own documentation, once the storage limit is exceeded the oldest data is overwritten to make room. NXLog Platform licenses by source: verbose applications, incident spikes, and longer retention don't change the bill, and there are no EPS or volume caps.

Microsoft Sentinel, Splunk, Google SecOps, Elastic, and OpenSearch natively; IBM QRadar and ArcSight through LEEF and CEF; plus syslog, HTTP(S), Kafka, and OpenTelemetry for everything else — several routes at once when you want a SIEM feed and an archive. Retention inside NXLog Platform covers the copy you keep.

Logmanager is a trademark of its respective owner. Product information is based on publicly available documentation as of July 2026.