
Axoflow at Splunk .conf26
Axoflow is heading back to Splunk .conf26, September 14–17, 2026, at the Colorado Convention Center in Denver.
This is our third .conf, and it's a room we genuinely like being in. The people who come by our booth (P1 at the Platform area) love Splunk — it's the platform their SOC runs on, and they have no intention of leaving it. What they don't love is what it costs to keep feeding it everything. This year we're bringing something new to show them.
Your SIEM isn't expensive. Your noise is.
Every .conf conversation starts the same way: SIEM costs are climbing faster than budgets. The instinct is to blame the platform, but it's rarely the platform. Most environments are indexing raw, unfiltered log volume because nobody built the layer that decides what's worth indexing before it hits Splunk.
That's the pitch at our booth this year: don't send raw logs to your SIEM. Route them through a pipeline that classifies, normalizes, and decides what's signal before Splunk ever sees it — so what you're paying to index is what you actually need to detect, investigate, and keep. Everything else lands in low-cost storage, at a fraction of SIEM cost, still there in full when you need it for an investigation or an audit.
What we're demoing: detection before ingest
The new part this year is Detection running in-stream. Sigma rules execute in the pipeline itself — before the event reaches Splunk — and only the findings get forwarded on to Splunk ES. Not the raw log, only the alert.
That's a different cost equation than sending everything and letting Splunk sort it out afterward, and it's a different reliability equation for the detection engineer: the rule runs against data Axoflow already normalized, so a vendor log-format change upstream doesn't quietly break the detection downstream.
It's also the first shipped piece of where we're taking the platform:
- a pipeline that stops needing to be babysat,
- storage that adapts to whatever you throw at it,
- detection that runs where the data already lives,
- and AI woven through all three rather than bolted onto one.
The Autonomous Security Data Layer, in full, is the direction. Detection running in-stream is the first step actually in your hands.
Detection is in early access now, with a small group of design partners ahead of general availability. Come see it live at the booth.
Catch us on the schedule
Both sessions run back-to-back on Tuesday, September 15.
Talk — 11:30–11:50 AM MDT: When Attacks Move at Machine Speed: Self-Healing Security (SEC2008). AI compresses the kill chain from days to minutes, and manual detection and response can't keep up — neither can AI agents trapped inside your SIEM, blind to how data is collected. Balázs shows how AI spanning pipeline, detection, and SIEM creates self-healing security: federated analytics where data lives, and continuous loops that auto-tune coverage in real time.
Workshop — 1:00–2:00 PM MDT: Building Self-Healing Detection Pipelines: A Hands-On Workshop (SEC2009). Balázs and Sándor walk through an end-to-end detection-as-code toolkit — managing data in the pipeline, writing detection-as-code, generating Splunk SPL — and why detection-as-code alone isn't enough: the whole loop from collection through classification to detection has to be automated, so agents can adjust every stage.
If the in-stream detection demo at the booth catches your interest, the workshop is where you get your hands on it.
Who's there
Balázs Scheidler — CEO & Co-founder. Creator of syslog-ng, presenting both sessions above.
Sándor Guba — CTO & Co-founder. Creator of the Kubernetes Logging Operator, leads Axoflow's technical vision — and co-presents the SEC2009 workshop.
Neil Boyd — VP of Sales & Co-founder. Eight-plus years driving syslog-ng adoption in North America; works directly with CISOs on cutting SIEM cost without cutting coverage.
Laurakate Bayman — Director of Sales. With a career spanning enterprise sales and customer success across security markets, Laurakate blends technical understanding with a customer-first approach. From driving adoption of syslog-ng to designing success programs for Fortune 500 organizations, she helps teams solve complex data problems and turn them into real outcomes.
Richard Hosgood — Director of Sales Engineering. He'll walk you through exactly how Axoflow slots in front of the Splunk ingestion you already run.
Book a meeting
We'll be running one-on-one sessions throughout the show. If you're attending .conf26 and want to talk about cutting your Splunk ingest bill, keeping detections stable when log formats change, or seeing in-stream detection live, book time with us.
Follow Our Progress!
We are excited to be realizing our vision above with a full Axoflow product suite.
Sign Me UpFighting data Loss?

Book a free 30-min consultation with syslog-ng creator Balázs Scheidler
