Secure the front door. Email is where most attacks arrive — syslog-ng is the reliable, vendor-neutral log pipe — collect, parse, filter and route logs from the whole estate, cut SIEM ingest cost, and never lose a log to an outage.
Buy through TechBag
Same software. Better outcome — at no extra cost.
Free, vendor-neutral, 30 minutes
How it’s rated
Full scoreboard ↓Quick answer
syslog-ng is One Identity's log management engine — one of the most widely deployed log collectors in the world, the reliable pipe that gathers, processes and routes log data from across an entire IT estate to wherever it needs to go. Every server, network device, application and security tool generates logs, and those logs are the raw material of security monitoring, compliance and troubleshooting — but only if they are reliably collected, normalised and delivered. syslog-ng does exactly that: it collects logs from a huge range of sources (Linux/Unix, Windows, network gear, applications, cloud), parses and enriches them, filters and classifies them, and routes them to destinations like a SIEM, a data lake, or long-term storage — with the reliability (disk-buffering so nothing is lost) and performance to handle very high volumes. Critically, it can transform and reduce logs before they reach a SIEM, cutting the volume and complexity of data those expensive, often per-ingest-priced tools must process — which meaningfully lowers SIEM total cost of ownership. Available as the open-source project and the enterprise Premium Edition (plus the Store Box log-management appliance), it came to One Identity via the 2018 Balabit acquisition and is part of the Unified Identity Security Platform (a Quest Software company). TechBag scopes, PoCs and quotes it in INR/GST.
This page covers syslog-ng — log management. The rest of the platform:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
The reliable log pipe — collect, parse, filter and route logs from the whole estate.
syslog-ng is one of the world's most-deployed collectors.
What consolidation actually replaces, dimension by dimension.
| Dimension | Unprotected / signature email | syslog-ng (One Identity) |
|---|---|---|
| Logs across the estate | Scattered, siloed | One collected pipe |
| Log formats | Messy, varied | Parsed & structured |
| SIEM ingest volume | Raw firehose | Filtered & reduced |
| SIEM cost | High (per-ingest) | Lower TCO |
| A SIEM outage | Logs lost | Disk-buffered, delivered |
| Transport | Plain, unreliable | Encrypted, reliable |
| Destinations | One, hard-wired | Many, flexible routing |
| Vendor lock-in | Tied to one tool | Vendor-neutral pipe |
Logs are the raw material of security and compliance — collect them reliably and cut your SIEM bill. Part of the One Identity platform.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Collects logs from a huge range of sources — Linux/Unix syslog, Windows Event Log, network devices, applications, files and cloud — the whole estate into one pipe.
Parses raw logs into structured data and enriches them (GeoIP, key-value, patterns) — turning messy text into usable, queryable events.
Filters, classifies and rewrites logs — dropping noise, tagging what matters, and reducing volume before data reaches costly downstream tools.
Routes processed logs to destinations — SIEM, data lake, cloud storage, files, databases — reliably, with disk-buffering so nothing is lost in transit.
Open source, Premium Edition, and the Store Box appliance — part of One Identity's platform, complementing security and identity across the portfolio.
One agent on every machine, one console over all of them — modules attach without a second operational world.
syslog-ng is the reliable log pipe under your security stack — collecting, reducing and routing everything, part of the portfolio, and paired with the human firewall.
Collects from Linux/Unix, Windows Event Log, network devices, applications, files and cloud — one pipe for the whole estate's logs.
Agent and agentless Windows Event Log collection, including clustered collectors — the Microsoft estate's logs, gathered reliably.
Handles very high message rates — the throughput to collect logs from thousands of sources without becoming the bottleneck.
Parses raw log text into structured fields — turning unusable strings into queryable, correlatable events for downstream tools.
Enriches logs with context — GeoIP, key-value extraction, pattern matching, lookups — so events arrive downstream already meaningful.
Filters out noise and classifies what matters — only the relevant logs go forward, cutting the volume costly SIEMs must process.
Rewrites and anonymises log content in flight — normalise formats, mask sensitive data, and reshape events before delivery.
Reduces and pre-processes logs before they reach the SIEM — cutting ingest volume and lowering the total cost of expensive, per-ingest-priced tools.
Routes logs to multiple destinations at once — SIEM, data lake, cloud storage, files, databases — the right data to the right place.
Disk-based buffering and reliable transport mean no log is lost if a destination is down — the reliability compliance and security depend on.
Encrypted, authenticated log transport and tamper-evident storage (Store Box) — logs protected in transit and at rest for compliance.
The turnkey log-management appliance — collect, search, store and secure logs with a searchable UI, without building it yourself.
The overview, getting started, and protecting M365 email.
Log management with syslog-ng, explained.
The Store Box log-management appliance.
Getting syslog-ng running.
Want a live, India-context walkthrough on your own fleet?
Book a guided demo →Here’s what genuinely sets One Identity syslog-ng apart in log management.
Every server, network device, application and security tool produces logs, and those logs are the foundation of three critical things: security monitoring (detecting attacks, investigating incidents), compliance (proving what happened, for auditors and regulators), and troubleshooting (finding out why something broke). But logs are only valuable if they are reliably collected, made sense of, and delivered to where they can be used — a SIEM, a data lake, or long-term storage. Scattered, unstructured, unreliably-transported logs are worthless. This collection-and-delivery layer is unglamorous but absolutely essential plumbing: without a reliable log pipe, your SIEM has gaps, your compliance evidence has holes, and your incident responders are flying blind. syslog-ng exists to be that reliable pipe — the dependable foundation the whole log-dependent security and compliance stack is built on.
This is often the most compelling, bottom-line reason to deploy syslog-ng in front of a SIEM. Modern SIEM and analytics platforms are frequently priced by the volume of data ingested — so every gigabyte of raw, noisy, unfiltered log data you send them costs money, and log volumes are enormous and growing. syslog-ng sits between your sources and your SIEM and reduces the data before it arrives: it filters out noise and irrelevant events, drops what you don't need, parses and normalises the rest, and can even aggregate or transform events — so the SIEM receives a smaller, cleaner, higher-value stream rather than the raw firehose. The effect is a direct, measurable reduction in SIEM ingest volume and therefore total cost of ownership, often substantial. In many deployments the SIEM savings alone justify syslog-ng, while also improving the quality of the data the SIEM works with — a rare win on both cost and effectiveness.
For logs used in security and compliance, reliability is non-negotiable: a lost log could be the one recording a breach or the evidence an auditor demands, and 'we didn't collect it' is not an acceptable answer. syslog-ng is built for this. Its disk-based buffering means that if a destination (like the SIEM) is temporarily unavailable, logs are buffered to disk and delivered when it recovers rather than being dropped — so nothing is lost during outages or spikes. Its reliable, encrypted transport ensures logs arrive intact and confidentially. And it handles very high message rates without becoming a bottleneck, so it keeps up even under the log floods that accompany incidents (exactly when you most need the data). This engineering-grade reliability, proven at massive scale across one of the world's most widely deployed log collectors, is why organisations trust syslog-ng with the logs their security and compliance depend on.
Real environments are heterogeneous: Linux and Unix servers, Windows machines, network devices from many vendors, applications logging in different formats, and increasingly cloud services — each producing logs in its own way, in its own place. Collecting and unifying all of that is a genuine engineering challenge, and it's exactly what syslog-ng is designed for. It collects from an enormous range of sources across all these platforms, parses their varied formats into structured, consistent data, enriches it with context, and delivers it wherever it's needed — giving you one coherent log pipeline for a fragmented estate instead of a mess of point collectors and gaps. That breadth and flexibility, combined with powerful parsing, filtering and routing, is why syslog-ng is used as the backbone log layer under all kinds of downstream tools (SIEMs, data lakes, observability platforms) rather than being tied to any one of them — it's the vendor-neutral pipe that feeds whatever you choose.
syslog-ng meets you wherever you are. It exists as a hugely popular open-source project — one of the most widely deployed log collectors in the world, battle-tested across countless systems — which gives it enormous real-world maturity and a broad community. The commercial Premium Edition adds enterprise capabilities, support and reliability features for organisations that need them, and the syslog-ng Store Box (SSB) is a turnkey log-management appliance that collects, searches, stores and secures logs with a searchable interface, without you having to build and run the infrastructure yourself. This range — open source for flexibility and reach, Premium Edition for enterprise assurance, Store Box for a packaged appliance — lets organisations adopt syslog-ng at the level that fits. And because it came to One Identity via the 2018 Balabit acquisition and sits in the Unified Identity Security Platform, it's backed by an established identity-and-security vendor with enterprise support in India through TechBag.
syslog-ng is a best-in-class log collection, processing and routing engine — the reliable, vendor-neutral pipe — and it is deliberately that, not a full SIEM or analytics platform. It doesn't do the detection, correlation, alerting and investigation that a SIEM (Splunk, Microsoft Sentinel, Elastic, etc.) does; instead it feeds those tools better, cheaper data, and complements them. For basic needs, the open-source edition or a cloud provider's native log pipeline may suffice; the value of the Premium Edition and Store Box is enterprise reliability, support, breadth and packaging. syslog-ng's edge is doing the collection-and-delivery layer superbly — with the SIEM-cost reduction and reliability that make it pay for itself — from an established vendor. TechBag scopes where syslog-ng fits in your logging and SIEM architecture, and which edition suits, honestly.
Your log sources (Linux, Windows, network, apps, cloud), your SIEM and its ingest cost, and your compliance retention needs. TechBag scopes it free.
syslog-ng deployed; key sources connected; parsing and enrichment configured; reliable, disk-buffered transport established.
Filtering and reduction cutting SIEM ingest volume; routing to SIEM, data lake and storage; Store Box for searchable retention if scoped.
One reliable log pipe feeding everything, no logs lost, SIEM cost measurably reduced. TechBag models the edition mix in INR/GST.
Trusted across regulated industries in 100+ countries
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We put syslog-ng in front of our SIEM and cut ingest volume by a large margin — the licensing saving alone paid for it. And the data quality went up.”
“Disk-buffering is why we trust it for compliance logs. A SIEM outage doesn't mean lost logs anymore — they're buffered and delivered when it's back.”
“One pipe for Linux, Windows, network gear and apps. It parses and normalises everything so downstream tools get clean, structured events.”
“The Store Box appliance gave us searchable, secure log storage without building the infrastructure. Turnkey log management.”
“It handles our message rates without breaking a sweat — even during incidents when the log flood hits. It keeps up when we most need it.”
“Vendor-neutral is the point. It feeds whatever SIEM or data lake we choose — we're not locked in, and we can reduce cost before ingest.”
“The open-source roots mean it's battle-tested everywhere. Premium Edition added the support and reliability features we needed for production.”
“Configuration has a learning curve, but the power is worth it — filtering, parsing and routing exactly how we want. Best log pipe we've used.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the email security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
The reliable, vendor-neutral log pipe that cuts SIEM cost. This page's product.
The grid nobody publishes — how strong the email detection is vs how integrated with the wider security portfolio.
Deep, reliable collection/processing with enterprise support and an appliance option.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Open-source collectors, SIEM-native and cloud pipelines — honest lanes; the edge is reliable, vendor-neutral collection that cuts SIEM cost, with enterprise support.
| Dimension | syslog-ng | rsyslog / Fluentd | SIEM-native collectors | Cloud log pipelines | No log layer |
|---|---|---|---|---|---|
| Role | The reliable log pipe | Open-source collectors | Tied to the SIEM | Cloud-native | The gap |
| Reliability (no loss) | Disk-buffering | Varies | Varies | Managed | None |
| SIEM cost reduction | A key strength | Possible | None | Some | None |
| Source breadth & parsing | Very broad | Broad | SIEM-focused | Cloud-focused | None |
| Best fit | A reliable, vendor-neutral log pipe that cuts SIEM cost, with enterprise support | DIY open-source collection | All-in on one SIEM's collectors | Purely cloud-native logging | Nobody doing security or compliance |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Drag the sliders (count users; IT-hour cost as loaded incident rate). Estimates assume ~1.5 hours per user per year handling email threats that reach the inbox without AI filtering, with ~70% removed by stopping the mass at the gateway — the avoided-breach value (most attacks start here) is the larger, unpriced win. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models actual device counts and modules.
syslog-ng prices by edition and throughput (open source, Premium Edition, Store Box). TechBag scopes it for your logging estate in one GST quote.
Best for the log pipe
Best for a broader rollout
Best for enterprise assurance
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your device counts and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Confirm collection from ALL your sources — Linux/Unix, Windows Event Log, network devices, apps, cloud.
Measure the ingest-volume reduction syslog-ng achieves before your SIEM — the direct TCO saving.
Test disk-buffering — simulate a SIEM outage and confirm no logs are lost, just delayed and delivered.
Verify parsing and enrichment turn your messiest log formats into structured, usable events.
Confirm flexible routing to multiple destinations at once — SIEM, data lake, storage.
Decide open source vs Premium Edition vs Store Box — reliability, support and packaging needs.
Verify encrypted, authenticated transport and tamper-evident storage for compliance logs.
Right-size by throughput/sources — TechBag scopes and quotes in INR/GST.
Scope a syslog-ng PoC (collect, parse and reduce your logs, measure the SIEM saving), or let a TechBag advisor plan your log-management architecture and edition mix.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.