The syslog-ng alternative for Windows, Linux, and macOS

One agent across six operating systems, managed from a single console.

syslog-ng covers Linux well. Your infrastructure runs on more than Linux. NXLog Platform gives you one agent for Windows, Linux, macOS, BSD, Solaris, and AIX - with native Windows Event Log collection, SNMPv3 trap reception, and centralized management for the whole fleet. Keep your SIEM. Close the gaps.

Collection hero diagram

Fortune 500 companies trust NXLog

Verizon 2024 1 Frame Group 25762 Fujitsu Logo 1 J P Morgan Logo 2008 1 1

syslog-ng vs. NXLog Platform at a glance

With syslog-ng today
With NXLog Platform
Platform Support
Linux and Unix, server-side. Windows needs the separate syslog-ng Agent for Windows, which sits on its own 6.0.x version line rather than the 8.2 PE release; macOS has community Homebrew builds but no vendor-supported package.
One agent, six operating systems. The same agent runs natively on Windows, Linux, macOS, BSD, Solaris, and AIX.
Windows Event Collection
Separate agent, text forwarding. The Windows Agent forwards event logs as text, without full Event Log API parsing.
Native collection, full fidelity. The im_msvistalog module reads the Windows Event Log API directly and preserves rich event data, including custom channels.
Central configuration
Per-host configuration. There is no fleet-wide agent configuration management; teams script rollouts or push configs through GPO.
One console for the whole fleet. Group agents, apply templates, and push configuration updates remotely from NXLog Platform.
Outputs and extensibility
Extra packages per destination. Many destinations, such as Elasticsearch or Kafka, ship as separate syslog-ng-mod-* packages you install per host.
120+ modules included. Inputs and outputs for SIEMs, databases, message queues, and cloud services come with the agent - no external runtimes.
SNMP Traps
Depends on an external daemon. The snmptrap() source reads Net-SNMP’s snmptrapd output; syslog-ng has no native trap listener.
Native SNMP v1, v2c, and v3. The agent receives and parses traps directly, with SNMPv3 authentication and encryption (USM).
Metrics
Log transport, with OTLP support. syslog-ng 4.x can receive and forward OpenTelemetry data, but has no host or application metric collection.
Logs and metrics in one pipeline. Collect, process, and route metrics alongside logs with the same agent and the same configuration.
Security & Compliance
TLS transport in the open source edition. Encrypted log storage and appliance-level access control sit in the commercial Premium Edition products.
Security controls built in. TLS and mutual TLS, log encryption, role-based access with audit logs, file integrity monitoring, and PII masking.
Support model
Community support for OSE. Commercial support requires syslog-ng Premium Edition through One Identity.
Support from the vendor. NXLog Platform subscriptions include support from the team that builds the agent.
Scale and resilience
High throughput, manual fleet design. Relay tiers, buffering, and balancing are assembled per deployment, with no fleet-level health view.
Buffering, balancing, and failover included. Disk buffering, load-balanced outputs, and automatic failover keep logs flowing, with agent health visible in the console.

Already on syslog-ng Premium Edition?

syslog-ng PE vs. NXLog Platform

With syslog-ng PE
With NXLog Platform
Platform Support
Split across product lines. The current PE line targets Linux on x86_64, AIX stays on PE 6 LTS, and Windows means a separate agent on its own 6.0.x line.
One agent, one version, six operating systems.
Windows
Two separate products. The Windows Agent does basic filtering only, with no parsing or classification and no disk buffering. The PE server does not install on Windows.
The same agent reads the Windows Event Log API directly, then parses and filters before it sends.
Central config
Store Box adds a GUI, but it configures the appliance, not your agents. Windows agents take config through group policy.
Group agents, apply templates, and push updates to the whole fleet from one console.

Need help? Book a short migration workshop

Why teams choose NXLog Platform

Group 25814

Windows done right

Collect Windows Event Log and ETW natively, read EVT and EVTX archives, and run Windows Event Collection on Windows or Linux with full WEF support. No extra forwarder on any host.

Group 25815

One agent for every OS

Run the same agent on Windows, Linux, macOS, BSD, Solaris, and AIX. Parse, filter, normalize, and enrich at the source, so every platform ships consistent data.

Group 25810

Manage the fleet centrally

Control up to 100,000 agents from one console: grouping, templates, visual routing, remote configuration updates, and health monitoring.

Group 25811

Integrates with your stack

More than 120 modules connect SIEMs, databases, message queues, and cloud services. Route to several destinations at once for redundancy or retention requirements.

Group 25812

Reliable at scale

Multithreaded processing, disk buffering, load balancing, and automatic failover keep data flowing through spikes and outages.

Group 25813

Security and compliance built in

TLS and mutual TLS, log encryption, role-based access with audit trails, file integrity monitoring, PII masking, and SNMPv3 trap security.

Value by Team

Group 25783

Platform / Observability engineer

• Replace per-host syslog-ng configs with one agent and one console across six operating systems.
• Parse and enrich at the source to cut central pipeline load.
• Collect logs and metrics in the same pipeline, instead of running a metrics agent alongside syslog-ng.

Group 25784

DevOps / SRE

• Keep your log paths, but filter noise before it reaches incident tools.
• Cut MTTR with structured, correlated data instead of forwarded text.
• Get buffering, failover, and load balancing without hand-built relay tiers.

Group 25922

Cloud / Infrastructure engineer

• Deploy one agent on VMs, bare metal, and containers, with no separate Windows forwarder.
• Fan out one route to several platforms at once.
• Automate rollout with templates and CI/CD instead of scripting per-host config pushes.

Group 25923

Platform owner / IT architect

• Enforce governance with role-based access and audit trails, included rather than edition-gated, included rather than edition-gated.
• Standardize on a vendor-neutral pipeline and avoid lock-in.
• Control spend with selective routing, filtering, and built-in retention.

Try NXLog Platform for free

FAQs

NXLog Platform is a full replacement for syslog-ng, but not a drop-in fork - it’s a different agent with its own configuration format. The building blocks map almost one-to-one: sources become Input blocks, destinations become Output blocks, and log paths become Routes. The migration section above shows the translation, and our engineers run short workshops if you want a guided start.

Yes. NXLog Platform is vendor-neutral and feeds Splunk, Elastic, Microsoft Sentinel, Graylog, Datadog, and other analytics platforms through built-in output modules. Many teams run NXLog in front of the SIEM to filter and enrich data first, which improves data quality and trims ingest volume.

The agent receives SNMP v1, v2c, and v3 traps natively and parses them into structured fields - SNMPv3 uses the User-based Security Model for authentication and encryption, with no external trap parser. Beyond SNMP, NXLog Platform collects sources outside syslog-ng’s scope, including Windows ETW.

No. The NXLog agent on Windows reads the Windows Event Log API directly through its im_msvistalog module - Application, Security, System, and custom channels - and preserves full event detail, including the XML. There is no equivalent of the separate syslog-ng Agent for Windows to install or maintain.

Yes. The agent processes high event rates with multithreaded processing, and disk buffering holds data when a destination slows down or drops. Automatic failover switches to a secondary target until the primary returns, and load balancing spreads traffic across receivers - so the pipeline keeps flowing under stress.

syslog-ng is a trademark of One Identity LLC. Product information is based on publicly available documentation for syslog-ng OSE 4.12 and syslog-ng PE 8.2 as of August 2026.