ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional

infoToolsimportance 22
What's new: First merged summary for this story: Axoflow introduced AxoDetect in early access, shifting Sigma detection execution into the data pipeline so full SIEM feeding becomes optional — alerts go to the SIEM while full-fidelity logs are retained in AxoLake.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Axoflow's AxoDetect enters early access, executing customer Sigma rules in-stream so only alerts reach the SIEM while full-fidelity logs land in the AxoLake data lake.

Axoflow announced AxoDetect, now in early access and unveiled at Splunk .conf26 (per reports dated 2026-09-16), which runs customer Sigma detection rules in-stream on normalized security data before SIEM ingestion. Alerts travel to the SIEM while full-fidelity logs land in AxoLake, the company's low-cost security data lake that also runs on-premises. Vendor-cited outcomes include a global industrial company cutting SIEM spend 50% and mean time to resolution 85%, and a government agency cutting data volume 80%. GBHackers adds that the product was built by syslog-ng creator Balázs Scheidler. Both sources agree on the launch details and figures.

  • AxoDetect is in early access, announced at Splunk .conf26; reports published 2026-09-16
  • Runs customer Sigma rules in-stream on normalized data before SIEM ingest; alerts, not raw logs, reach the SIEM
  • Full-fidelity logs are stored in AxoLake, a low-cost security data lake capable of running on-premises
  • Vendor-cited outcomes: a global industrial company cut SIEM costs 50% and mean time to resolution 85%; a government agency cut data volume 80%
  • Built by syslog-ng creator Balázs Scheidler (reported by GBHackers)

Coverage timeline

  1. · 1h ago
    Cyber Security News· 20
    Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional

    Axoflow's AxoDetect enters early access, executing Sigma rules in-stream so only alerts reach the SIEM while full-fidelity logs land in the AxoLake data lake.

  2. · 1h ago
    GBHackers· 22
    Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional

    Axoflow launches AxoDetect in early access, running customer Sigma rules in the data pipeline to cut SIEM ingest costs and make full SIEM feeding optional.