Axoflow Launches AxoDetect to Run Threat Detection Inside the Security Data Pipeline

Axoflow has launched AxoDetect, a new capability that runs Sigma detection rules directly in its data pipeline rather than after logs land in a customer’s security information and event management (SIEM) platform. The feature, now in early access, sends triggered alerts on to the customer’s SIEM while routing full-fidelity logs to AxoLake, the company’s own storage layer, which Axoflow says lets organizations retain complete audit trails at lower cost than storing everything in a traditional SIEM.

Axoflow, founded by Balazs Scheidler, creator of the open-source syslog-ng project, markets its platform as a security data layer that discovers, classifies, parses, normalizes and reduces security telemetry before it reaches downstream analytics tools. AxoDetect extends that existing pipeline to include in-stream detection logic ahead of the SIEM.

The company is demonstrating AxoDetect this week at Splunk’s .conf26 conference in Denver, running September 14-17, at booth P1, and plans to show the capability again at the Gartner Security & Risk Management Summit in London later this month.

Why it matters

In-stream detection is a direct response to SIEM cost pressure: if triage logic can run before ingestion, organizations can route only actionable alerts to their most expensive analytics tier while still retaining full logs elsewhere for investigation.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *