A top 10 US airline achieved FAA and PCI DSS compliance with one log collection pipeline
With NXLog Platform, the airline collects logs from its e-enabled aircraft and ground infrastructure, feeds its SIEM and data warehouse from a single pipeline, and maintains the continued airworthiness of its fleet.
Business Demand
Meet FAA Aircraft Network Security Program (ANSP) and PCI DSS requirements across an e-enabled aircraft fleet.
Key Challenges
Collect logs from disparate aircraft and ground systems — Windows, Linux, VxWorks, and airline-specific platforms — without intruding on critical nodes, and deliver them to both a data warehouse and a SIEM.
Results
ANSP authorized, FAA and PCI DSS compliance achieved, and continued fleet airworthiness.
We are very satisfied working with NXLog and selected it over others to enable our Aircraft Network Security Program and to meet PCI DSS requirements. Safety and compliance are crucial for our long-term business strategy.
— General Manager, Cybersecurity Assurance
The Challenge
E-enabled aircraft use TCP/IP connectivity to move data to and from the aircraft without physical storage media — customer profiles, In-Flight Entertainment (IFE) content, navigational data, and aircraft health monitoring. That connectivity also creates real risk. A threat, intentional or unintentional, can degrade system performance or cause denial of service.
The FAA addresses this risk through advisory circular AC 119-1A, which sets out how operators gain authorization for an Aircraft Network Security Program (ANSP) — a requirement for the continued airworthiness of e-enabled aircraft. Where security logs are generated, operators must retain logs from the aircraft's core network and analyze them, continuously or on a schedule, to understand normal system behavior and identify security risks. And because the airline takes card payments on board, its aircraft also fall within the scope of PCI DSS, which requires an established log management process to protect customers' payment card data.
For the airline, that meant collecting logs from disparate systems across the fleet and its ground support infrastructure — Windows, Linux, VxWorks, and airline-specific platforms — many of them compressed or encrypted. The data had to reach both a data warehouse (Azure, Snowflake) and Google Security Operations (formerly Google Chronicle) SIEM for retention and threat analysis. The airline's Trellix (McAfee) agents had hit their limits, and any replacement had to be time-effective, cost-effective, and unintrusive on critical systems.
The Solution
The airline was naturally cautious about performance and reliability, so it evaluated a range of log collection options — including full Endpoint Detection & Response (EDR) products — before choosing NXLog Platform.
With NXLog, the airline collects logs from critical aircraft and ground systems using a lightweight agent with a small footprint, processes the many formats those systems produce, and forwards everything through one pipeline to both the data warehouse and the SIEM. Centralized agent management gives the team deployment and control at fleet scale, and NXLog's configuration language handles the airline-specific formats that generic agents struggled with.
The entire project took three months, from an extensive evaluation through several deployment phases. For the next stage, the airline planned to extend the pipeline across its Airbus A320 and A220 fleet with support from NXLog Professional Services, targeting 100% coverage of its e-enabled aircraft and infrastructure nodes.
Why it Worked
Lightweight agent with a small footprint on critical aircraft and ground systems
A configuration language flexible enough for airline-specific log formats
One pipeline feeding both the data warehouse and the SIEM
Centralized, scalable agent management across the fleet
Results
The airline's Aircraft Network Security Program received authorization, and the airline achieved compliance with both FAA requirements and PCI DSS — keeping its e-enabled fleet airworthy and its onboard payment card data protected.
Replacing the limited Trellix agents with NXLog gave the airline one professional log collection layer across systems that previously needed separate handling. Logs from Windows, Linux, VxWorks, and airline-specific platforms now flow to the data warehouse and SIEM for ongoing analysis and retention.
Deployment moved quickly — evaluation to production in three months. The agent's small footprint meant collection could run on critical nodes without interfering with them, a hard requirement in an environment where system performance affects airworthiness.
The airline relies on NXLog's expertise in security event and log management for continued regulatory compliance and fleet airworthiness, with fleet-wide expansion planned alongside NXLog Professional Services.
ANSP authorized
The airline's Aircraft Network Security Program received FAA authorization
FAA compliance
Security log retention and analysis meet AC 119-1A requirements for continued airworthiness
PCI DSS compliance
An established log management process protects payment card data on e-enabled aircraft
Fleet airworthiness
One log collection pipeline supports ongoing compliance across the fleet
About the airline
The customer is a leading US airline with operations across the U.S., North America, Latin America, and Europe. A public company with more than 20,000 crew members, it serves customers in over 100 destinations and competes in high-value geographies. It was ranked among the 10 largest airlines in the U.S. in 2021.