A top 10 US airline achieved FAA and PCI DSS compliance with one log collection pipeline

With NXLog Platform, the airline collects logs from its e-enabled aircraft and ground infrastructure, feeds its SIEM and data warehouse from a single pipeline, and maintains the continued airworthiness of its fleet.

Hero mobile crop
Group 25926

Business Demand

Meet FAA Aircraft Network Security Program (ANSP) and PCI DSS requirements across an e-enabled aircraft fleet.

Group 25926

Key Challenges

Collect logs from disparate aircraft and ground systems — Windows, Linux, VxWorks, and airline-specific platforms — without intruding on critical nodes, and deliver them to both a data warehouse and a SIEM.

Group 25926

Results

ANSP authorized, FAA and PCI DSS compliance achieved, and continued fleet airworthiness.

We are very satisfied working with NXLog and selected it over others to enable our Aircraft Network Security Program and to meet PCI DSS requirements. Safety and compliance are crucial for our long-term business strategy.

— General Manager, Cybersecurity Assurance

Local police

The Challenge

E-enabled aircraft use TCP/IP connectivity to move data to and from the aircraft without physical storage media — customer profiles, In-Flight Entertainment (IFE) content, navigational data, and aircraft health monitoring. That connectivity also creates real risk. A threat, intentional or unintentional, can degrade system performance or cause denial of service.

The FAA addresses this risk through advisory circular AC 119-1A, which sets out how operators gain authorization for an Aircraft Network Security Program (ANSP) — a requirement for the continued airworthiness of e-enabled aircraft. Where security logs are generated, operators must retain logs from the aircraft's core network and analyze them, continuously or on a schedule, to understand normal system behavior and identify security risks. And because the airline takes card payments on board, its aircraft also fall within the scope of PCI DSS, which requires an established log management process to protect customers' payment card data.

For the airline, that meant collecting logs from disparate systems across the fleet and its ground support infrastructure — Windows, Linux, VxWorks, and airline-specific platforms — many of them compressed or encrypted. The data had to reach both a data warehouse (Azure, Snowflake) and Google Security Operations (formerly Google Chronicle) SIEM for retention and threat analysis. The airline's Trellix (McAfee) agents had hit their limits, and any replacement had to be time-effective, cost-effective, and unintrusive on critical systems.

Emoji objects

The Solution

The airline was naturally cautious about performance and reliability, so it evaluated a range of log collection options — including full Endpoint Detection & Response (EDR) products — before choosing NXLog Platform.

With NXLog, the airline collects logs from critical aircraft and ground systems using a lightweight agent with a small footprint, processes the many formats those systems produce, and forwards everything through one pipeline to both the data warehouse and the SIEM. Centralized agent management gives the team deployment and control at fleet scale, and NXLog's configuration language handles the airline-specific formats that generic agents struggled with.

The entire project took three months, from an extensive evaluation through several deployment phases. For the next stage, the airline planned to extend the pipeline across its Airbus A320 and A220 fleet with support from NXLog Professional Services, targeting 100% coverage of its e-enabled aircraft and infrastructure nodes.

Why it Worked

Group 26093

Lightweight agent with a small footprint on critical aircraft and ground systems

Group 25927

A configuration language flexible enough for airline-specific log formats

Group 25928

One pipeline feeding both the data warehouse and the SIEM

Group 25929

Centralized, scalable agent management across the fleet

Results

The airline's Aircraft Network Security Program received authorization, and the airline achieved compliance with both FAA requirements and PCI DSS — keeping its e-enabled fleet airworthy and its onboard payment card data protected.

Replacing the limited Trellix agents with NXLog gave the airline one professional log collection layer across systems that previously needed separate handling. Logs from Windows, Linux, VxWorks, and airline-specific platforms now flow to the data warehouse and SIEM for ongoing analysis and retention.

Deployment moved quickly — evaluation to production in three months. The agent's small footprint meant collection could run on critical nodes without interfering with them, a hard requirement in an environment where system performance affects airworthiness.

The airline relies on NXLog's expertise in security event and log management for continued regulatory compliance and fleet airworthiness, with fleet-wide expansion planned alongside NXLog Professional Services.

Check circle FILL1 wght400 GRAD0 opsz24 12

ANSP authorized

The airline's Aircraft Network Security Program received FAA authorization

Check circle FILL1 wght400 GRAD0 opsz24 12

FAA compliance

Security log retention and analysis meet AC 119-1A requirements for continued airworthiness

Check circle FILL1 wght400 GRAD0 opsz24 12

PCI DSS compliance

An established log management process protects payment card data on e-enabled aircraft

Check circle FILL1 wght400 GRAD0 opsz24 12

Fleet airworthiness

One log collection pipeline supports ongoing compliance across the fleet

About the airline

The customer is a leading US airline with operations across the U.S., North America, Latin America, and Europe. A public company with more than 20,000 crew members, it serves customers in over 100 destinations and competes in high-value geographies. It was ranked among the 10 largest airlines in the U.S. in 2021.

Hero mobile crop