Axoflow has launched AxoDetect, a new capability that runs Sigma detection rules directly in its data pipeline rather than after logs land in a customer’s security information and event management (SIEM) platform. The feature, now in early access, sends triggered alerts on to the customer’s SIEM while routing full-fidelity logs to AxoLake, the company’s own storage layer, which Axoflow says lets organizations retain complete audit trails at lower cost than storing everything in a traditional SIEM.
Axoflow, founded by Balazs Scheidler, creator of the open-source syslog-ng project, markets its platform as a security data layer that discovers, classifies, parses, normalizes and reduces security telemetry before it reaches downstream analytics tools. AxoDetect extends that existing pipeline to include in-stream detection logic ahead of the SIEM.
The company is demonstrating AxoDetect this week at Splunk’s .conf26 conference in Denver, running September 14-17, at booth P1, and plans to show the capability again at the Gartner Security & Risk Management Summit in London later this month.
Why it matters
In-stream detection is a direct response to SIEM cost pressure: if triage logic can run before ingestion, organizations can route only actionable alerts to their most expensive analytics tier while still retaining full logs elsewhere for investigation.

Leave a Reply