Case study - Storage modernization
- Greater than 300,000 staff and employees servicing over 1,000,000 students.
- Storage needs data volume: 80 TBs
- Deployment type: The environment is an air-gapped on-premises deployment.
35%
Reduction of costs
25%
Infrastructure reduction
40%
MTTR reduction in open tickets
With Axoflow, modernizing our legacy syslog-ng™ storage infrastructure was quick and painless.
Problem
The customer was looking to: strengthen their cyber threat detection and analysis capabilities as well solving a compliance problem. The existing log storage appliance had stopped keeping pace with new EU initiatives and ECCC Regulation (EU’s Cybersecurity Strategy for the Digital Decade objectives, NIS 2 Directive, the Cybersecurity Act) - and the vendor was no longer developing it to support them. Finding an air-gapped, on-premises replacement that also delivered SOC management visibility and multi-team access to stored data proved to be a combination no other vendor could provide out-of-the-box. EU compliance deadlines meant the decision couldn't wait.
Deployment
- Implementation plan was developed together with the customer in a way that it would be non-distruptive: minimally impact production and could not impact the operational efficiency of the existing log collection layer
- Axoflow Lockers is a compatible replacement for SSB and syslog-ngTM deployments
Tech stack (customer's existing tools)
- Firewalls/network: Palo Alto, F5, Cisco
- OS/endpoints: Windows Event Logs, Linux
- Other: syslog-ngTM and syslog Store BoxTM
Tech stack
F5
Palo Alto Networks Firewall
Windows Event Logs
Linux System Logs

Cisco
syslog-ng PE

syslog Store BoxTM
Axoflow products used
Axosyslog CV
Axoflow Locker
Benefits
- Data Insights
- Air-gapped, on-prem storage capability with federated search and access controls to the data
- Automatic data quality improvements
- Visibility into all log sources across all remote sites and data centers
- Eliminating syslog-ng message drops
- Ease of use, no code environment for resource constrained users.
Results
- Infrastructure reduction 25%
- Cost reduction 35%
- MTTR reduction in open tickets 40%