syslog-ng

AxoSyslog vs syslog-ng, one year on: 17 releases to 5. Compare the 2025–2026 feature additions, FilterX advances, and release cadence of both syslog projects.

AxoSyslog Year 2: Progress Comparison vs. syslog-ng

AxoSyslog vs syslog-ng, one year on: 17 releases to 5. Compare the 2025–2026 feature additions, FilterX advances, and release cadence of both syslog projects.

How AxoSyslog implements in-application ACK, flow control, memory and disk buffers, batching, and how log-iw-size interacts with batch-lines under the hood

AxoSyslog internals: flow control, window size, queues, and batching

How AxoSyslog implements in-application ACK, flow control, memory and disk buffers, batching, and how log-iw-size interacts with batch-lines under the hood

Why Detection Engineering Can't Work Without a Pipeline That Keeps Up

No More Parser Maintenance: Why Detection Engineering Can't Work Without a Pipeline That Keeps Up

Detection rules fail silently when parsers miss schema changes. Learn how autonomous classification keeps your fields where your detections expect them.

parser schema drift detection gaps

When Your Parser Breaks: Schema Drift and Detection Gaps That Sneak Up On You

Schema drift silently breaks parsers and creates detection gaps. Learn how pipeline-layer validation catches drift before your SIEM does.

syslog-ng earned its reputation as a trusted tool, and for many teams, it was the right choice for years. But the demands on log pipelines today require more than stability alone: modern log infrastructure needs to evolve.

When Trusted Tools Reach Their Limits: The Evolution of Log Pipelines

syslog-ng was the right choice for years, but modern log pipelines demand more than stability. Why log infrastructure needs to evolve, and where to go next.

What’s new in AxoSyslog versions 4.18–4.22: FilterX enhancements, improved ClickHouse and S3 outputs, OTLP keep-alive support, and smarter worker autoscaling for high-performance log pipelines.

What’s New in AxoSyslog Versions 4.18 – 4.22

AxoSyslog 4.18-4.22: FilterX enhancements, better ClickHouse and S3 outputs, OTLP keep-alive, and smarter worker autoscaling for log pipelines.

Learn how a leading U.S. healthcare company used Axoflow to gain log observability, improve syslog-ng monitoring, and cut data costs by 30% in days.

Cutting Storage Costs and Boosting Visibility: How a Leading Healthcare Company Reduced Log Storage Costs by 30% with Axoflow

Learn how a leading U.S. healthcare company used Axoflow to gain log observability, improve syslog-ng monitoring, and cut data costs by 30% in days.

Discover what’s new in AxoSyslog 4.13–4.17, from advanced log formatting and smarter parsing to cloud integration and performance tuning. Build faster, more reliable log pipelines with the latest features.

What's New in AxoSyslog Versions 4.13–4.17

What's new in AxoSyslog 4.13-4.17: advanced log formatting, smarter parsing, cloud integrations, and performance tuning for reliable pipelines.

AxoSyslog: the syslog-ng™ fork built by its original developers. Get secure, supported, binary-compatible log management with advanced observability, daily vulnerability scans, and enterprise-ready features.

Why Choose AxoSyslog over syslog-ng

AxoSyslog: the syslog-ng fork built by its original developers. Secure, supported, binary-compatible log management with enterprise features.

AxoSyslog, our syslog-ng™ fork, simplifies its licensing by adopting a single, clear open source license: GNU General Public License version 3 or later (GPL-3.0-or-later)

AxoSyslog License Update: Moving to GPL3

AxoSyslog, our syslog-ng fork, moves to a single clear open source license: GPL-3.0-or-later. What changes for users and contributors.

Activity report of the first year of AxoSyslog, our drop-in syslog-ng fork.

1 year of AxoSyslog

Activity report of the first year of AxoSyslog, our drop-in syslog-ng fork.

How to parse firewall logs with AxoSyslog FilterX

Parse FortiGate, Palo Alto & SonicWall Logs with FilterX

Turn messy firewall logs into clean, SIEM-ready data. FilterX parses FortiGate, Palo Alto, and SonicWall logs and routes them accurately — see how.

Send syslog data to Grafana Loki with syslog-ng

Send Syslog to Grafana Loki with syslog-ng (Step-by-Step)

Route syslog data to Grafana Loki with AxoSyslog, the drop-in syslog-ng replacement. Dynamic labels, less noise, scalable ingestion — full config inside.

How to upgrade from syslog-ng to AxoSyslog

How to upgrade syslog-ng to AxoSyslog

Upgrade syslog-ng to AxoSyslog in minutes with no configuration changes. What the drop-in replacement means and how the migration works.

Google Pub/Sub gRPC, Azure Monitor, Microsoft Sentinel destinations for enhanced cloud integration

Google Pub/Sub gRPC, Sentinel and Azure Monitor destinations in AxoSyslog 4.10

AxoSyslog 4.10 adds Google Pub/Sub gRPC, Microsoft Sentinel, and Azure Monitor destinations. Key features and configuration examples inside.

Send logs to ClickHouse database with AxoSyslog

Sending log data to ClickHouse with AxoSyslog

AxoSyslog 4.9 adds ClickHouse as a destination: send logs directly to your self-hosted ClickHouse database for efficient storage and analysis.

AxoSyslog syslog-ng fork

First 6 months of AxoSyslog, our syslog-ng fork

Six months into AxoSyslog, the binary-compatible syslog-ng fork: development activity, new features, and what's ahead for the project.

AxoSyslog 4.9 release with ClickHouse destination and FilterX

ClickHouse support and FilterX updates in AxoSyslog 4.9

AxoSyslog 4.9 highlights: ClickHouse destination, gRPC improvements, new FilterX features, and bug fixes for the AxoSyslog and the syslog-ng projects.

Install AxoSyslog, our syslog-ng fork from our repository on RPM-based Linux distributions, like RHEL, Fedora, or AlmaLinux

How to install AxoSyslog on RHEL and AlmaLinux

Learn how to install AxoSyslog, our syslog-ng™ fork from our repository on RPM-based Linux distributions like RHEL, Fedora, or AlmaLinux.

AxoSyslog APT repository, syslog-ng alternative, send logs to Elasticsearch data streams

Elasticsearch data stream, APT repository in AxoSyslog 4.8

AxoSyslog 4.8 release with APT repository, gRPC and S3 destination improvements, and the ability to send logs to Elasticsearch data streams

AxoSyslog, the syslog-ng fork by the original creator

AxoSyslog is now a real fork

AxoSyslog is now a real fork of syslog-ng: still open source under the same license, actively maintained with new features from its creators.

Metrics, management, and alternatives for syslog-ng Premium Edition. Modernize your syslog-ng based logging infrastructure without disrupting your deployments!

Axoflow metrics for syslog-ng Premium Edition

Metrics, management, and alternatives for syslog-ng Premium Edition. Modernize your syslog-ng based logging infrastructure without disrupting your deployments!

syslog-ng 4.7 with better OpenTelemetry performance, gRPC improvements, new metrics

New metrics and performance improvements in syslog-ng 4.7

syslog-ng 4.7 brings better OpenTelemetry performance, gRPC improvements, new metrics, and features to integrate your telemetry pipeline.

Metrics for SC4S and Splunk

Metrics for telemetry pipelines based on SC4S and Splunk

Metrics and management for telemetry pipelines based on Syslog Connect for Splunk (SC4S) and Splunk: observe your telemetry pipeline in real time!

Axoflow Management Plane and a syslog-ng deployment

Metrics for syslog-ng based log management infrastructures

Metrics and management for syslog-ng based enterprise logging: gain visibility into your telemetry pipeline health and reduce downtime.

Sending logs to OpenObserve, the open source Elasticsearch alternative — Axoflow blog cover

Send Logs to OpenObserve: The Free Elasticsearch Alternative

Ship Kubernetes logs to OpenObserve, the lightweight Elasticsearch alternative, with syslog-ng and the Logging operator. Step-by-step AxoSyslog setup.

Diagram of a UDP packet drop: kernel socket buffer unable to receive although the NIC queue has free space

How to detect TCP and UDP packet drops in syslog and telemetry pipelines

Silently losing logs? Detect TCP and UDP packet drops in syslog and telemetry pipelines, learn why they happen, and the metrics that catch them early.

macOS logging with syslog-ng's native macOS system() source — Axoflow blog cover

Enhance macOS logging with syslog-ng’s native macOS system() source

Collect logs from the native macOS OSlog or log stream with syslog-ng's new darwin-os sources!

syslog-ng 4.6 release with Google BigQuery, macOS, and Windows XML support — Axoflow blog cover

Google BigQuery, macOS, and Windows XML support in syslog-ng version 4.6

syslog-ng 4.6 allows you to send data directly to Google BigQuery, better collect logs on macOS, parse Windows XML logs, and improves OpenTelemetry performance

syslog-ng contributions by Axoflow, 2023

syslog-ng 2023 community activity report

syslog-ng in 2023: new features (OpenTelemetry, Google Pub/Sub, Splunk, Grafana Loki, Amazon S3, OpenObserve drivers), contributions, and other developments

Sending logs to Grafana Loki with syslog-ng and Logging operator — Axoflow blog cover

Send logs to Grafana Loki with syslog-ng and Logging operator

Forward Kubernetes logs to Grafana Loki using syslog-ng and the Logging operator with AxoSyslog. Cloud-native setup, dynamic labels, and full config.

Sending log and telemetry data to Google BigQuery with syslog-ng — Axoflow blog cover

How to send log and telemetry data to Google BigQuery with syslog-ng

Send logs and telemetry data directly to Google BigQuery with syslog-ng, using gRPC

Google Pub/Sub and OpenObserve support in syslog-ng 4.5 — Axoflow blog cover

Google Pub/Sub and OpenObserve support in syslog-ng version 4.5

syslog-ng 4.5 integrates your telemetry pipeline to Google Pub/Sub and OpenObserve

Multi-tenancy and namespace-based routing in Logging operator 4.4 — Axoflow blog cover

Multi-tenancy, namespace-based routing, new outputs in Logging operator 4.4

Logging operator 4.4 brings multi-tenancy with namespace-based routing, outputs like S3, ElasticSearch, Loki, and Splunk for the syslog-ng aggregator, and more

syslog-ng AxoSyslog 4.4.0 release with Amazon S3 and Grafana Loki destinations

AxoSyslog and syslog-ng 4.4.0 release

syslog-ng 4.4 comes with new drivers and lots of new metrics to help you manage your cloud-native and on-premise observability supply chain.

Sending structured logs from syslog-ng to CrowdStrike Falcon LogScale — Axoflow blog cover

From syslog-ng to LogScale: structured logs from any source

Send structured log messages from syslog-ng to Falcon LogScale via its Ingest Structured Data API, and other destinations in parallel.

syslog-ng and AxoSyslog documentation updates, August 2023 — open book cover image

syslog-ng and AxoSyslog documentation updates 2023-08

Documentation updates for AxoSyslog, the cloud-native syslog-ng distribution: OpenTelemetry support, Splunk HEC destination, eBPF support, and new parsers

OpenTelemetry support in AxoSyslog and syslog-ng — Axoflow blog cover

OpenTelemetry support in more detail in AxoSyslog and syslog-ng

Receive or send any kinds of OpenTelemetry logs, traces, and metrics with syslog-ng and AxoSyslog 4.3 using OTLP/gRPC

Scaling syslog over UDP to 1M events per second with eBPF — Axoflow blog cover

Scaling syslog to 1M EPS with eBPF

How to parallelize syslog message processing to scale syslog over UDP reception on a single node: dos, dont's, and trade-offs, and the power of eBPF.

AxoSyslog Core documentation and syslog-ng similarities — open book cover image

syslog-ng documentation and similarities with AxoSyslog Core

Republishing syslog-ng documentation in a new format, under the AxoSyslog Core name to comply with the syslog-ng Open Source Edition documentation license

Syslog-ng disk buffering for a resilient syslog architecture

How syslog-ng disk buffering protects logs from crashes, network outages, and overload — plus the config to make your syslog architecture resilient.

AxoSyslog and syslog-ng 4.2.0 release announcement — Axoflow blog cover

AxoSyslog and syslog-ng 4.2.0 release

syslog-ng 4.2 comes with new drivers and lots of new metrics to help you manage your cloud-native and on-premise observability supply chain.

AxoSyslog, log collection for Kubernetes — Axoflow blog cover

AxoSyslog - Log Collection for Kubernetes

Install syslog-ng using the AxoSyslog Helm charts to send Kubernetes logs into OpenSearch. AxoSyslog is a cloud native syslog-ng distribution by Axoflow.

Kernel and syslog-ng tuning to avoid losing messages with syslog over UDP — diagram cover

Tune the Kernel & syslog-ng to Stop UDP Syslog Loss

syslog over UDP drops messages under load. The exact kernel and syslog-ng buffer tuning to minimize loss — settings you can apply today.

Syslog-ng release 4.1

Exploring the Exciting New Features of syslog-ng 4.1

Version 4.1 with its new metrics system brings syslog-ng closer to the cloud-native ecosystem and the modern observability supply chain.

ARM processor chip illustrating multi-architecture cloud-ready syslog-ng container images

Cloud-Ready syslog-ng Images

Axoflow is happy to announce that our flavored syslog-ng container images are available for download.

Subscribe to stay in touch

Sign up for our newsletter to be the first to knew about new articles. We are excited to be realizing our vision above with a full Axoflow product suite.