Windows  |  Telemetry collection  |  Telemetry auditing

Sysmon event IDs: what to collect for threat detection

Sysmon fills the visibility gaps that default Windows auditing leaves open — but only if you collect the right event IDs. Here’s the complete event ID reference, my recommended collection tiers for threat detection, and working configurations for getting Sysmon data off the endpoint with NXLog Agent. Sysmon (System Monitor) is a free Microsoft tool — a Windows system service and device driver — that logs detailed system activity, such as process creation, network connections, and registry changes, to the Windows Event Log.

NXLog Platform  |  Disaster recovery  |  AWS

Surviving a region outage: multi-region disaster recovery for NXLog Platform on AWS

When a cloud region goes down, most teams think about their applications first. But if your log management platform goes dark, you lose more than a dashboard — you lose your audit trail, your security telemetry, and in many industries, your compliance posture. Every minute your ingestion endpoint is unreachable is a minute of blind spots you can’t get back. The good news: if you run NXLog Platform on AWS, building a multi-region disaster recovery (DR) setup is more straightforward than you might expect.

Telemetry collection  |  Log aggregation

Log collection tools: 5 options compared for security operations

Log collection tools gather event data from endpoints, servers, network devices, and cloud services, normalize it into a consistent format, and route it to a SIEM, a database, or long-term storage. This article compares five log collection tools: NXLog Platform, Splunk Universal Forwarder, Elastic Agent, Fluent Bit, and Vector. All five move logs reliably. The factors that determine a purchase are operating system coverage, where processing happens, which destinations each tool can feed to, and whether fleet management and storage are included or have to be assembled from separate parts.

syslog  |  Telemetry collection  |  Log aggregation

What is syslog? Ports, severity levels, and RFC 3164 vs. RFC 5424

Syslog is the standard protocol that devices, operating systems, and applications use to send event messages to a log collector. NXLog Platform collects, parses, and forwards messages in both BSD (RFC 3164) and IETF (RFC 5424) formats with a single extension. Most security telemetry still travels as syslog at some point in its life. Firewalls, switches, Linux hosts, hypervisors, and a long list of security products emit it, and every major SIEM ingests it.

Telemetry collection  |  Telemetry pipeline management  |  NXLog Platform

5 Fluentd alternatives for security operations in 2026

The five Fluentd alternatives most worth evaluating for security operations in 2026 are NXLog Platform (collection agent, fleet management, and log storage in one product), Fluent Bit (the lightweight C collector from the same project family), Vector (a Rust pipeline built for high-volume transformation), OpenTelemetry Collector (the vendor-neutral CNCF standard), and Logstash (the Elastic Stack’s processing engine). Which one fits depends on your operating system mix, your throughput ceiling, and how many agents you need to manage.

Log analysis  |  Telemetry collection  |  NXLog Agent

Log enrichment with GeoIP: adding location context at the collection layer

A source IP address on its own answers almost none of the questions an analyst asks at triage. Did this login attempt come from a country where we have no users? Is the source a residential connection or a hosting provider? Log enrichment with GeoIP answers these questions before anyone has to ask them by resolving each IP address against a geolocation database and writing the results — country, city, coordinates, network owner — directly into the event record.

More

Log timestamp normalization to ISO 8601: Getting every source to agree on time

The audit blind spot: collecting logs from mainframes and core banking systems your SIEM doesn't speak

6 Logstash alternatives and competitors for security operations in 2026

Why the SIEM is the wrong layer to solve compliance: a pipeline-first framework for financial services

All Posts