syslog  |  Telemetry collection  |  Log aggregation

Free syslog server and viewer: setup, limitations, and when to upgrade

You can centralize logs from firewalls, switches, and Linux hosts with a free syslog server - rsyslog, syslog-ng OSE, and the free plan of NXLog Platform all do the job. The real differences show up in Windows support, secure transport, viewers, and what happens when your environment grows. A firewall, a switch, or an auditor says "send your logs somewhere," and there’s no budget line for it. A free syslog server solves the immediate problem in an afternoon.

Log analysis  |  Telemetry collection  |  Centralized logging

Firewall log analyzer: How to centralize and analyze firewall logs

Your firewalls already record allowed and denied connections and policy changes. Each vendor logs them in its own format. This post shows you how to get those records into one searchable structure, with working configurations for the most common sources. A firewall log analyzer is a tool that collects logs from firewalls, parses each vendor’s log format into structured fields, and stores the results in one place for searching, alerting, and reporting.

Log analysis  |  Telemetry collection  |  Centralized logging

Server log analysis: collection, parsing, monitoring, and troubleshooting

Server log analysis turns the raw event records your Windows and Linux servers already produce into security detections, audit evidence, and troubleshooting answers. NXLog Agent and NXLog Platform provide that pipeline: collection and parsing at the source, centralized storage and search on top. Every server you run writes down what happens to it: who logged in, which services started, what the web server returned, why a process crashed. Attackers know this too.

Windows  |  Telemetry collection  |  Telemetry auditing

Sysmon event IDs: what to collect for threat detection

Sysmon fills the visibility gaps that default Windows auditing leaves open — but only if you collect the right event IDs. Here’s the complete event ID reference, my recommended collection tiers for threat detection, and working configurations for getting Sysmon data off the endpoint with NXLog Agent. Sysmon (System Monitor) is a free Microsoft tool — a Windows system service and device driver — that logs detailed system activity, such as process creation, network connections, and registry changes, to the Windows Event Log.

NXLog Platform  |  Disaster recovery  |  AWS

Surviving a region outage: multi-region disaster recovery for NXLog Platform on AWS

When a cloud region goes down, most teams think about their applications first. But if your log management platform goes dark, you lose more than a dashboard — you lose your audit trail, your security telemetry, and in many industries, your compliance posture. Every minute your ingestion endpoint is unreachable is a minute of blind spots you can’t get back. The good news: if you run NXLog Platform on AWS, building a multi-region disaster recovery (DR) setup is more straightforward than you might expect.

Telemetry collection  |  Log aggregation

Log collection tools: 5 options compared for security operations

Log collection tools gather event data from endpoints, servers, network devices, and cloud services, normalize it into a consistent format, and route it to a SIEM, a database, or long-term storage. This article compares five log collection tools: NXLog Platform, Splunk Universal Forwarder, Elastic Agent, Fluent Bit, and Vector. All five move logs reliably. The factors that determine a purchase are operating system coverage, where processing happens, which destinations each tool can feed to, and whether fleet management and storage are included or have to be assembled from separate parts.

More

What is syslog? Ports, severity levels, and RFC 3164 vs. RFC 5424

5 Fluentd alternatives for security operations in 2026

Log enrichment with GeoIP: adding location context at the collection layer

Log timestamp normalization to ISO 8601: Getting every source to agree on time

All Posts