Releases  |  NXLog Platform

Announcing NXLog Platform 1.15

We are happy to announce the latest release of NXLog Platform, version 1.15. This update lets you export log search results for offline analysis, gives you clearer visibility into agent connectivity, and makes it easier to manage agent configurations programmatically. NXLog Agent 6.16 supports more reliable macOS log collection and automatic format detection for incoming telemetry data. Read on for more details about these updates. Export log search results for offline analysis and reporting NXLog Platform 1.

Splunk  |  Telemetry pipeline management  |  Log noise

How to reduce Splunk ingest cost without losing detection coverage

Short answer: Splunk meters the raw bytes that reach its indexing pipeline, so you reduce Splunk ingest cost by stopping low-value data before that point. Fix noisy audit policies at the source, filter events by ID and pattern at the endpoint, remove fields you don’t search, collapse repeats, and route archive-only telemetry data to cheaper storage. Compression alone does not lower the meter. Splunk bills climb because every event arrives at full size, including the ones nobody searches.

Kubernetes  |  Telemetry collection  |  Centralized logging

Kubernetes DaemonSet log collection: a practical guide for SecOps

Kubernetes DaemonSet log collection runs one log-collector pod on every node in your cluster. The collector reads all container logs from the node’s /var/log/containers directory through read-only hostPath mounts and forwards them to your SIEM, with no changes to your application pods. When the cluster adds a node, the DaemonSet adds a collector, so coverage scales automatically. This guide shows you how the pattern works, how Kubernetes writes container logs in 2026, and how to deploy NXLog Agent as a DaemonSet that ships container and audit logs to Microsoft Sentinel or Splunk.

syslog  |  Telemetry collection  |  Log forwarding

From journald to syslog: 4 ways to forward systemd journal logs

The major Linux distributions write their logs to the systemd journal: a binary, indexed, local-first store. However, your SIEM and collectors still expect syslog, which has been the plain text, line-oriented, network-native standard for more than four decades. If you run SecOps, you have to bridge that gap on every Linux host you monitor, and the obvious-looking switch, ForwardToSyslog=yes, moves nothing off the host by itself. Quick answer: how to forward journald to syslog?

Kubernetes  |  Docker  |  Centralized logging

Containerized log collection: how to capture Docker and Kubernetes logs before they disappear

Key takeaways Container logs share the container’s lifecycle. The Kubernetes documentation states that when a pod is evicted from a node, it removes the containers along with their logs. Container lifespans keep shrinking. Sysdig’s 2025 Cloud-Native Security and Usage Report found that 60% of containers live for 60 seconds or less. Collection has to be continuous, not scheduled. A node-level agent (a DaemonSet on Kubernetes) covers every container on a node without changing your applications.

Telemetry pipeline management  |  Telemetry collection  |  Observability

Clean data: the foundation of AI-era security

The market has already answered whether telemetry is infrastructure. Cisco paid $28 billion for Splunk. Twelve days apart in 2025, CrowdStrike bought Spain’s Onum and SentinelOne moved to acquire Observo AI, both to embed AI-driven data pipelines directly beneath their platforms, while AI-native pipeline startups keep raising eight-figure rounds on the same thesis. When the largest names in security spend that kind of capital on the layer that collects, filters, and routes data, they are conceding something they rarely say out loud: detection, response, and every AI capability stacked on top are only ever as good as the pipeline underneath.

More

Log shipper offline buffering: how to keep logs safe when the destination goes down

USB device auditing on Windows: event IDs, tools, and blocking

WEC (Windows Event Collector) scaling limits: what breaks first, and what to do about it

Windows Task Scheduler event IDs: auditing scheduled task creation and abuse

All Posts