A U.S. state government cut SIEM costs without losing security visibility

With NXLog Platform, the state brought a multi-vendor estate of network devices, Windows servers, and cloud systems into one pipeline, normalized events before transmission, and routed each stream to the right destination — Amazon S3 for bulk retention, Anomali for detection.

Nxlog us state case study hero 722x429
Group 25926

Business Demand

Improve security posture, meet regulatory obligations, and reduce SIEM costs.

Group 25926

Key Challenges

Collect from a mixed estate of Windows, Linux, and network devices producing many different log types, while migrating the SIEM from Splunk to Anomali.

Group 25926

Results

Reliable collection across a disparate multi-vendor estate, cloud and on-prem; security monitoring that holds up under heavy log volume; lower SIEM costs.

Local police

The Challenge

Facing a rising volume of cyber threats, a U.S. state government set out to overhaul its security monitoring. For years it had run Splunk as its SIEM. As log volumes grew, the deployment reached its limits: licensing tied to ingested data pushed costs up, and the pipelines struggled to keep pace, which delayed alerts and let some go unnoticed.

The estate itself was the harder problem. Legacy systems, cloud infrastructure, and a wide range of security tools each produced logs in their own format, so aggregating and normalizing them took constant effort.

Running the collection layer added to the load. Thousands of collection points needed attention, which pulled the security team away from security work while compliance obligations kept growing — and the resulting gaps in log collection put audit readiness at risk. The state decided to migrate to Anomali Security Analytics and rebuild its telemetry layer at the same time. It needed a way to collect, process, and deliver clean, structured logs fast enough to support real-time security operations.

Emoji objects

The Solution

After evaluating commercial and open-source options, the state chose NXLog Platform as the core of its new security data pipeline. NXLog Agent's small footprint, throughput, and configurability suited an estate this varied, and it could aggregate and forward logs from across that estate into the new SIEM.

Deployment covered the sources that mattered: network infrastructure from Juniper, Palo Alto Networks, F5, Zscaler, and Cisco; Windows environments, including event logs, Sysmon, and Active Directory logs; PRTG monitoring; and a set of custom in-house systems. However unusual the format, each stream was brought into one central collection pipeline.

Edge processing did much of the work. NXLog Agent parsed and filtered raw messages on the source host and converted them to structured JSON before anything left the network, enriching records with the context the security team needed for investigation. Data quality went up and noise went down.

Routing rules then sent each stream where it belonged. Bulk raw firewall logs went to Amazon S3, while endpoint data went to Anomali. That kept storage costs in proportion and kept SIEM ingestion focused on the events analysts query.

Between collection points, the team used NXLog Agent's batched compression transport to cut network overhead on the internal hops. Transmissions were encrypted, and the S3 bucket served as a secure staging area supporting the state's audit requirements.

Why it Worked

Group 26093

One collection layer across Windows, Linux, and network devices

Group 25927

Parsing and normalization at the source, before transmission

Group 25928

Routing rules that separate bulk retention from SIEM ingestion

Group 25929

Encrypted transport, with batched compression on internal hops

Results

Security operations costs came down, driven by smarter processing and lower SIEM ingestion volumes. The pipeline scaled with the estate, and the team kept real-time visibility even under heavy log load.

Automation replaced manual log handling, so analysts spend their time on threat detection and response instead of moving data around.

Anomali received clean, context-rich records, which made correlation faster and reduced false positives.

Check circle FILL1 wght400 GRAD0 opsz24 12

Lower SIEM costs

Smarter processing and reduced ingestion volumes

Check circle FILL1 wght400 GRAD0 opsz24 12

Reliable multi-vendor collection

One pipeline across a disparate estate, cloud and on-prem

Check circle FILL1 wght400 GRAD0 opsz24 12

Visibility under load

Security monitoring that holds up under heavy log streams

Check circle FILL1 wght400 GRAD0 opsz24 12

Cleaner detections

Structured, enriched records for faster correlation and fewer false positives

About the customer

The customer is a U.S. state government with a diverse economy built on energy, agriculture, and aerospace. The state has a long history in oil and natural gas production and is growing its renewable energy and advanced manufacturing sectors.

Nxlog us state case study about 560x420