A government institution built one log collection pipeline for its whole SOC

With NXLog, the security team collects events from Windows, DNS, SQL, and file-based sources across a hybrid estate, filters them at the agent and the forwarder, and feeds every SOC tool from one pipeline — with less data for its EPS-licensed tools to carry.

Nxlog gov case study hero 722x429
Group 25926

Business Demand

Improve the security posture of internal infrastructure, along with SOC performance and reliability.

Group 25926

Key Challenges

Build one collection pipeline across a multi-vendor, hybrid estate, and pre-filter events on agents and forwarders to bring EPS volume down.

Group 25926

Results

One unified collection pipeline, faster security tools, and a stronger security posture.

Local police

The Challenge

Government institutions hold everything from personal records to classified material, which keeps them near the top of every attack-volume ranking. They also run on smaller budgets than commercial organizations, with smaller security teams and a mix of older software that modern security tools were never designed to talk to.

For this institution's security team, log collection was the constraint. Its estate spanned several vendors, each with its own logging mechanism, and a hybrid mix of cloud and on-premises systems that no single existing approach covered consistently.

Volume made it harder. As log data grew, the tools consuming it slowed down — and several of those tools were licensed by events per second, so every unnecessary event carried a cost as well as a delay.

Emoji objects

The Solution

Rather than shortlisting on features, the security team wrote down what a new collection system had to do, then ran a proof of concept with several vendors from the log collection market. NXLog was the only product that met every requirement on the list:

•  Collection from varied input sources — text files, Windows Event Log, DNS, and SQL databases among them.

•  Output in the formats each tool needs — syslog and JSON, so each destination gets data in the shape it expects.

•  Delivery to multiple destinations — one pipeline feeding every security service, not a separate path per tool.

•  Processing on the data itself — normalization, reformatting, and filtering applied to the raw events.

•  Central configuration management — consistent configuration across the estate from one place.

•  Central monitoring — health checks that show whether each source is still sending.

In production, the team filters events on the agents and forwarders before the data leaves the source, so the volume reaching each security tool is smaller and more relevant. NXLog Platform manages that configuration centrally and reports on collection health, which closes the visibility gap the team had flagged.

Why it Worked

Group 26093

Windows Event Log, Microsoft DNS through Event Tracing for Windows, SQL databases, and plain text files — collected by one agent.

Group 25927

Pre-filtering on agents and forwarders cuts the event volume the SOC tools have to absorb, and the EPS volume they bill for.

Group 25928

Each security service receives what it needs, in the format it expects, from a single collection path.

Group 25929

Consistent configuration across the estate, plus visibility into whether each source is still sending.

Results

The institution now runs one collection pipeline across the sources in scope, instead of a different mechanism per vendor. The same pipeline feeds each of the security services the SOC depends on, in the format each one expects.

Because events are filtered at the agent and the forwarder, the tools downstream receive less data and less noise. That showed up as better performance in the security tools themselves, and it matters commercially too: where a tool is licensed by events per second, filtering earlier in the pipeline means paying for fewer events.

Central configuration keeps agents consistent as the estate changes, and collection health monitoring means a source that stops sending is now visible rather than silently absent — the gap the team named at the start of the project.

Forensics, monitoring, threat hunting, investigations, and incident response all draw on the same collection layer, so improvements to it reach every one of those areas at once.

Check circle FILL1 wght400 GRAD0 opsz24 12

Unified collection pipeline

One collection path for every in-scope source, replacing a mechanism per vendor

Check circle FILL1 wght400 GRAD0 opsz24 12

Faster security tools

Less data and less noise to absorb downstream

Check circle FILL1 wght400 GRAD0 opsz24 12

Lower EPS volume

Filtering before forwarding reduces what EPS-licensed tools have to bill for

Check circle FILL1 wght400 GRAD0 opsz24 12

Stronger security posture

One collection layer supporting forensics, monitoring, threat hunting, investigations, and incident response

About the customer

The customer is a government institution serving one of the world's ten largest economies. Its Office of the Chief Technology Officer runs security operations across the institution's internal infrastructure, covering forensics, monitoring, threat hunting, investigations, and incident response.

Nxlog gov case study about 240x160