A Logz.io alternative for log management | NXLog

Collect everything. Pay by source, not by gigabyte.

NXLog Platform collects security telemetry from Windows, Linux, macOS, and the legacy systems your auditors still ask about. It processes data at the source and stores it on infrastructure you control — self-hosted or NXLog-hosted. No ingestion meter, no retention clock.

Collection hero diagram

Fortune 500 companies trust NXLog

Verizon 2024 1 Frame Group 25762 Fujitsu Logo 1 J P Morgan Logo 2008 1 1

Logz.io vs. NXLog Platform at a glance

With Logz.io today
With NXLog Platform
Deployment model
SaaS only, running in the public cloud
Self-hosted or NXLog-hosted — your choice
Pricing basis
Per ingested GB per day, plus retention tier
Per source, flat — no volume component
Cost during an incident
Rises with volume; overage billed at a premium
No change — source count stays the same
Log retention
Hot storage for days to weeks; then archive and restore
You set it, on storage you control
Windows security telemetry
Event Log via a per-host OpenTelemetry collector
Event Log, ETW, WEF, Registry, FIM — built in
Agent fleet management
Collectors deployed and maintained host by host
Central enrollment, config, and updates
Operating system coverage
Mainstream platforms via OpenTelemetry and Beats
Windows, Linux, macOS, FreeBSD, AIX, Solaris
Restricted and air-gapped networks
Needs outbound access to Logz.io listeners
Fully supported — data can stay inside

Walk through NXLog Platform at your own pace — agent management, storage, and search included

Why teams choose NXLog Platform

Group 25814

Your data stays where you put it

Logz.io runs only in the public cloud — its own FAQ says so. NXLog Platform runs where your policy requires: your data center, your cloud account, or hosted by us. Air-gapped networks included.

Group 25812

A bill that ignores traffic spikes

With per-GB pricing, cost climbs at the worst possible moment — during an incident, when systems get loud. NXLog licenses by source. An endpoint under attack costs the same as an endpoint at rest.

Group 25815

One console for the whole fleet

Enroll agents, push configuration, watch health, and roll out updates from NXLog Platform. No per-host config files to hand-edit, no wondering which version runs where.

Group 25813

Retention your auditors can sign off on

Compliance frameworks often expect a year or more of searchable log history. On NXLog Platform, on-premises storage is included and you set the retention policy — no hot-storage clock, no restore step before you can search older data.

Group 25811

Windows telemetry beyond the Event Log

NXLog Agent collects ETW traces, Windows Event Forwarding streams without local agents, Registry changes, file integrity events, and Microsoft DNS Server logs. A generic collector stops at the Event Log.

07 cap4 icon

Filter noise before it crosses the meter

NXLog Agent drops, rewrites, and converts events at the source, so only data worth keeping leaves the host. If Logz.io stays in your stack, this is the fastest way to shrink its bill.

Not sure where to start? We're happy to map out what collection, routing, and retention would look like on NXLog Platform

Value by Team

Group 25783

SOC engineers

You need every signal during an investigation — not the subset that fits last quarter's ingestion budget. Collect from every endpoint without watching a volume gauge.

Group 25784

Compliance owners

Data residency, multi-year retention, and a clear chain of custody. Keep logs on infrastructure inside your jurisdiction, with HMAC integrity checking on the pipeline.

Group 25922

IT operations

Thousands of agents are a fleet, not a folder of config files. Enroll, configure, monitor, and update them from one console — on Windows, Linux, macOS, and the legacy boxes nobody wants to touch.

Group 25923

MSSPs

Per-source pricing you can quote to a client in advance. No end-of-month surprises when a customer's environment gets noisy, and volume discounts as you grow past 100 sources.

What you get with NXLog Platform 

Deploy it your way

Run NXLog Platform in your data center, in your own cloud account, or let us host it. Isolated and air-gapped environments work because nothing has to phone home. Your data crosses only the network boundaries you choose.

Source-based licensing, explained

A source is a system, device, or application NXLog collects from — a server, a firewall, a container cluster. You pay per source, and that's it: no per-GB fees, no events-per-second caps, no data volume limits. The Free plan covers up to 10 sources with the full feature set.

Native Windows security collection

Windows Event Log through the modern API, Event Tracing for Windows for the channels Event Log can't reach, agentless collection from Windows Event Forwarding, Registry monitoring, file integrity monitoring, performance counters, and Microsoft DNS Server log parsing. Legacy modules cover Windows XP, 2000, and 2003 where they still run.

Manage agents like a fleet

NXLog Platform enrolls agents, distributes configuration centrally, monitors agent health, and handles updates remotely. Solution packs give you working pipelines for common routes — Windows to Microsoft Sentinel, syslog to an OpenTelemetry backend, Okta to Google SecOps — without starting from a blank file.

Process at the source

Filter events, rewrite fields, and convert between formats — syslog, JSON, XML, CSV, CEF, LEEF, GELF — before data leaves the host. Buffer to disk through outages, compress and encrypt in transit, and de-duplicate repeating messages. Less noise shipped means lower storage and SIEM costs everywhere downstream.

Keep Logz.io in the loop — if you want

You don't have to rip anything out on day one. Logz .io's own shipping docs keep a dedicated NXLog listener on port 8010, and NXLog Agent also speaks OTLP to OpenTelemetry endpoints. Put NXLog in front: reach the sources Logz.io's collectors can't, cut the gigabytes crossing the meter, and keep a clean exit path. Swapping the backend later is a configuration change, not a re-instrumentation project.

Try NXLog Platform for free

FAQs

For security log collection, management, storage, and search — yes, and you gain deployment control that a SaaS can't offer. Logz.io also spans DevOps observability: metrics, distributed tracing, and Kubernetes monitoring. If you rely on those, keep them where they are — NXLog Agent can still be the collection layer underneath, and forwards to any backend you choose.

It's a real security analytics layer — prebuilt detection rules, threat intelligence enrichment, dashboards. It also inherits the platform's constraints: it runs only in Logz.io's cloud, on data you pay to ingest per gigabyte. If those constraints fit your policy, NXLog Agent can feed it. If they don't, NXLog Platform forwards to the SIEM of your choice — Microsoft Sentinel, Splunk, IBM QRadar, Google SecOps, Securonix, ArcSight — or stores and searches the data itself.

As of July 2026, Logz.io's consumption pricing lists $0.92 per ingested GB per day for the logging index with a 7-day hot retention tier, and usage above a committed plan bills as On Demand at 1.4 times the plan rate. NXLog Platform Premium is priced per source: $12.12 per source per month at 11 sources, falling to $5.58 at 100, with volume discounts above that — and the Free plan covers up to 10 sources. The structural difference matters more than any single figure: on Logz.io the bill tracks how loud your systems are; on NXLog it tracks how many systems you have.

Yes. Logz.io's shipping documentation lists NXLog as a supported method with its own listener port (8010), and NXLog Agent's OpenTelemetry exporter can deliver over OTLP as well. Many teams run this way: NXLog handles collection and source-side filtering, Logz.io stays as the analytics backend.

A source is any distinct system, device, or application NXLog collects from; virtual machines count individually. There are no per-GB fees, no events-per-second caps, and no data volume limits on any plan — a source at peak incident load costs the same as one that logs once a day.

Windows, Linux, and macOS, plus FreeBSD, IBM AIX, and Oracle Solaris — on x86, ARM, IBM Power, and SPARC hardware. Legacy input modules cover Windows XP, 2000, and 2003. That includes the systems most collectors dropped support for years ago.

Logz.io is a trademark of Logshero Ltd. All other product names, logos, and brands are the property of their respective owners.