Axoflow Launches AxoDetect, Bringing Detection Into The Pipeline and Making The SIEM Optional
Now in early access, AxoDetect runs Sigma rules in stream - alerts travel to the SIEM, and full-fidelity logs land in AxoLake, a low-cost security data lake
Stamford, Connecticut - On September 16th, 2026, Axoflow unveiled AxoDetect, a detection component designed to run a customer's rules directly in the pipeline. This innovation allows detection engineers to catch alerts earlier, using clean, normalized security data, all without incurring SIEM ingest rates.
The result of this launch is a significant shift in how detection and SIEM usage are managed. Alerts are sent to the SIEM, while full-fidelity logs are stored in AxoLake, Axoflow's cost-effective security data lake, which can also be deployed on-premises. This arrangement transforms the SIEM from an expensive log management solution into a workflow engine for SecOps, which can now be used as needed.
Detection engineers have the capability to write new Sigma rules, adjust existing ones, and utilize rules from the community, all within one open format that is interchangeable across tools. AxoDetect takes these rules and runs them in the pipeline. The platform's unique offering is the visibility it provides, showing where data comes from, which detection each source feeds, and where a rule is lacking necessary data.
Previously, detection teams and data teams were at odds, with each group responsible for distinct aspects of the process. This created a fragmented experience that required significant time and effort to coordinate. However, AxoDetect has eliminated this back-and-forth, allowing CISOs to see a reduction in SIEM costs by half or more, while maintaining coverage.
For instance, a large industrial firm reported a 50% reduction in SIEM costs, with a 85% decrease in mean time to resolution. Similarly, a government agency managed to cut data volume by 80% and reduce infrastructure footprint by 85%.
According to Balázs Scheidler, CEO and co-founder of Axoflow and the creator of syslog-ng, "Detection belongs in the data layer, on normalized data, before the ingest meter starts." The platform is currently in early access, with plans to expand the full detection lifecycle within the months to come, all while running where the data resides.
Axoflow, the autonomous security data layer, is committed to delivering a comprehensive security solution. The inclusion of AI-based autonomy in this platform promises to accelerate investigations by a factor of 10, reduce SIEM spend by 50%, and ensure near-zero pipeline maintenance. The creators of syslog-ng are behind this innovative security solution. For more information, you can contact Axoflow's VP of Marketing, Mate Benedek, at mate.benedek@axoflow.com.
Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.