A government institution built one log collection pipeline for its whole SOC
With NXLog, the security team collects events from Windows, DNS, SQL, and file-based sources across a hybrid estate, filters them at the agent and the forwarder, and feeds every SOC tool from one pipeline — with less data for its EPS-licensed tools to carry.
Business Demand
Improve the security posture of internal infrastructure, along with SOC performance and reliability.
Key Challenges
Build one collection pipeline across a multi-vendor, hybrid estate, and pre-filter events on agents and forwarders to bring EPS volume down.
Results
One unified collection pipeline, faster security tools, and a stronger security posture.
The Challenge
Government institutions hold everything from personal records to classified material, which keeps them near the top of every attack-volume ranking. They also run on smaller budgets than commercial organizations, with smaller security teams and a mix of older software that modern security tools were never designed to talk to.
For this institution's security team, log collection was the constraint. Its estate spanned several vendors, each with its own logging mechanism, and a hybrid mix of cloud and on-premises systems that no single existing approach covered consistently.
Volume made it harder. As log data grew, the tools consuming it slowed down — and several of those tools were licensed by events per second, so every unnecessary event carried a cost as well as a delay.
The Solution
Rather than shortlisting on features, the security team wrote down what a new collection system had to do, then ran a proof of concept with several vendors from the log collection market. NXLog was the only product that met every requirement on the list:
• Collection from varied input sources — text files, Windows Event Log, DNS, and SQL databases among them.
• Output in the formats each tool needs — syslog and JSON, so each destination gets data in the shape it expects.
• Delivery to multiple destinations — one pipeline feeding every security service, not a separate path per tool.
• Processing on the data itself — normalization, reformatting, and filtering applied to the raw events.
• Central configuration management — consistent configuration across the estate from one place.
• Central monitoring — health checks that show whether each source is still sending.
In production, the team filters events on the agents and forwarders before the data leaves the source, so the volume reaching each security tool is smaller and more relevant. NXLog Platform manages that configuration centrally and reports on collection health, which closes the visibility gap the team had flagged.
Why it Worked
Windows Event Log, Microsoft DNS through Event Tracing for Windows, SQL databases, and plain text files — collected by one agent.
Pre-filtering on agents and forwarders cuts the event volume the SOC tools have to absorb, and the EPS volume they bill for.
Each security service receives what it needs, in the format it expects, from a single collection path.
Consistent configuration across the estate, plus visibility into whether each source is still sending.
Results
The institution now runs one collection pipeline across the sources in scope, instead of a different mechanism per vendor. The same pipeline feeds each of the security services the SOC depends on, in the format each one expects.
Because events are filtered at the agent and the forwarder, the tools downstream receive less data and less noise. That showed up as better performance in the security tools themselves, and it matters commercially too: where a tool is licensed by events per second, filtering earlier in the pipeline means paying for fewer events.
Central configuration keeps agents consistent as the estate changes, and collection health monitoring means a source that stops sending is now visible rather than silently absent — the gap the team named at the start of the project.
Forensics, monitoring, threat hunting, investigations, and incident response all draw on the same collection layer, so improvements to it reach every one of those areas at once.
Unified collection pipeline
One collection path for every in-scope source, replacing a mechanism per vendor
Faster security tools
Less data and less noise to absorb downstream
Lower EPS volume
Filtering before forwarding reduces what EPS-licensed tools have to bill for
Stronger security posture
One collection layer supporting forensics, monitoring, threat hunting, investigations, and incident response
About the customer
The customer is a government institution serving one of the world's ten largest economies. Its Office of the Chief Technology Officer runs security operations across the institution's internal infrastructure, covering forensics, monitoring, threat hunting, investigations, and incident response.