Hamburger menu
TechBag
Search icon
Enterprise
Small Businesses
Industries
Blog
About Us
Shopping Bag
Get Quote
Category: Email Securityby One IdentityTechBag Intel Page

One Identity syslog-ng

Secure the front door. Email is where most attacks arrive — syslog-ng is the reliable, vendor-neutral log pipe — collect, parse, filter and route logs from the whole estate, cut SIEM ingest cost, and never lose a log to an outage.

Logs — the raw material of security & complianceCollect, parse, filter, route — one reliable pipeCuts SIEM ingest volume & cost

Buy through TechBag

Same software. Better outcome — at no extra cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free, vendor-neutral, 30 minutes

How it’s rated

Full scoreboard ↓
The category
the reliable pipe
Log management
Reach
one of the most deployed
Ubiquitous
The SIEM value
reduce ingest volume
Lower TCO
Gartner Peer Insights
Log management*
4.5 / 5

Quick answer

syslog-ng is One Identity's log management engine — one of the most widely deployed log collectors in the world, the reliable pipe that gathers, processes and routes log data from across an entire IT estate to wherever it needs to go. Every server, network device, application and security tool generates logs, and those logs are the raw material of security monitoring, compliance and troubleshooting — but only if they are reliably collected, normalised and delivered. syslog-ng does exactly that: it collects logs from a huge range of sources (Linux/Unix, Windows, network gear, applications, cloud), parses and enriches them, filters and classifies them, and routes them to destinations like a SIEM, a data lake, or long-term storage — with the reliability (disk-buffering so nothing is lost) and performance to handle very high volumes. Critically, it can transform and reduce logs before they reach a SIEM, cutting the volume and complexity of data those expensive, often per-ingest-priced tools must process — which meaningfully lowers SIEM total cost of ownership. Available as the open-source project and the enterprise Premium Edition (plus the Store Box log-management appliance), it came to One Identity via the 2018 Balabit acquisition and is part of the Unified Identity Security Platform (a Quest Software company). TechBag scopes, PoCs and quotes it in INR/GST.

Part 01 · Orient

The One Identity platform family

This page covers syslog-ng — log management. The rest of the platform:

Quick facts

30-second orientation
Product
syslog-ng — log management & collection
Vendor
One Identity (a Quest Software company · via Balabit, 2018)
The category
Log Management
The job
Collect, parse, filter, route logs across the estate
The reliability
Disk-buffering — no log lost; very high throughput
The SIEM value
Reduce & transform logs → lower SIEM TCO
Editions
Open source · Premium Edition · Store Box appliance
Part of
One Identity Unified Identity Security Platform
Deployment
Software (Linux/Unix/Windows) or appliance (SSB)
In India via
TechBag — quotes, PoCs, GST invoicing, Tier-1 support
Part 02 · Learn

Understand email security before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is log management?

The reliable log pipe — collect, parse, filter and route logs from the whole estate.

syslog-ng is one of the world's most-deployed collectors.

Unprotected inbox vs AI email security — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailsyslog-ng (One Identity)
Logs across the estateScattered, siloedOne collected pipe
Log formatsMessy, variedParsed & structured
SIEM ingest volumeRaw firehoseFiltered & reduced
SIEM costHigh (per-ingest)Lower TCO
A SIEM outageLogs lostDisk-buffered, delivered
TransportPlain, unreliableEncrypted, reliable
DestinationsOne, hard-wiredMany, flexible routing
Vendor lock-inTied to one toolVendor-neutral pipe

Logs are the raw material of security and compliance — collect them reliably and cut your SIEM bill. Part of the One Identity platform.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The collector

Sources

Collect everything

Collects logs from a huge range of sources — Linux/Unix syslog, Windows Event Log, network devices, applications, files and cloud — the whole estate into one pipe.

02
The processor

Parsing & Enrichment

Make sense of it

Parses raw logs into structured data and enriches them (GeoIP, key-value, patterns) — turning messy text into usable, queryable events.

03
The router

Filtering & Classification

Reduce & route

Filters, classifies and rewrites logs — dropping noise, tagging what matters, and reducing volume before data reaches costly downstream tools.

04
The delivery

Destinations

Deliver anywhere

Routes processed logs to destinations — SIEM, data lake, cloud storage, files, databases — reliably, with disk-buffering so nothing is lost in transit.

05
The foundation

Editions & Platform

OSS to appliance

Open source, Premium Edition, and the Store Box appliance — part of One Identity's platform, complementing security and identity across the portfolio.

One agent on every machine, one console over all of them — modules attach without a second operational world.

Part 03 · Evaluate

Twelve capabilities. Collect, process, deliver.

syslog-ng is the reliable log pipe under your security stack — collecting, reducing and routing everything, part of the portfolio, and paired with the human firewall.

Collect
Sources

Broad Source Collection

Collects from Linux/Unix, Windows Event Log, network devices, applications, files and cloud — one pipe for the whole estate's logs.

Collect
Windows

Windows Event Collection

Agent and agentless Windows Event Log collection, including clustered collectors — the Microsoft estate's logs, gathered reliably.

Collect
Scale

High-Throughput Ingestion

Handles very high message rates — the throughput to collect logs from thousands of sources without becoming the bottleneck.

Process
Parse

Parsing & Structuring

Parses raw log text into structured fields — turning unusable strings into queryable, correlatable events for downstream tools.

Process
Enrich

Enrichment

Enriches logs with context — GeoIP, key-value extraction, pattern matching, lookups — so events arrive downstream already meaningful.

Process
Filter

Filtering & Classification

Filters out noise and classifies what matters — only the relevant logs go forward, cutting the volume costly SIEMs must process.

Process
Rewrite

Transform & Rewrite

Rewrites and anonymises log content in flight — normalise formats, mask sensitive data, and reshape events before delivery.

Process
Reduce

Volume Reduction (SIEM TCO)

Reduces and pre-processes logs before they reach the SIEM — cutting ingest volume and lowering the total cost of expensive, per-ingest-priced tools.

Deliver
Route

Flexible Routing

Routes logs to multiple destinations at once — SIEM, data lake, cloud storage, files, databases — the right data to the right place.

Deliver
Reliability

Disk-Buffering & Reliability

Disk-based buffering and reliable transport mean no log is lost if a destination is down — the reliability compliance and security depend on.

Deliver
Secure

Secure Transport & Storage

Encrypted, authenticated log transport and tamper-evident storage (Store Box) — logs protected in transit and at rest for compliance.

Deliver
Store Box

Store Box Appliance (SSB)

The turnkey log-management appliance — collect, search, store and secure logs with a searchable UI, without building it yourself.

See it, don’t just read it

Watch One Identity syslog-ng in action

The overview, getting started, and protecting M365 email.

One Identity (official)·Overview

syslog-ng: Introduction to Log Management

Log management with syslog-ng, explained.

syslog-ng by One Identity (official)·Overview

syslog-ng Store Box: A Turnkey Log Appliance

The Store Box log-management appliance.

One Identity (official)·Demo

Installing syslog-ng on CentOS 7

Getting syslog-ng running.

Want a live, India-context walkthrough on your own fleet?

Book a guided demo →
Why syslog-ng

The endpoint catches what arrives. Email stops it arriving.

Here’s what genuinely sets One Identity syslog-ng apart in log management.

01

Logs are the raw material of security and compliance

Every server, network device, application and security tool produces logs, and those logs are the foundation of three critical things: security monitoring (detecting attacks, investigating incidents), compliance (proving what happened, for auditors and regulators), and troubleshooting (finding out why something broke). But logs are only valuable if they are reliably collected, made sense of, and delivered to where they can be used — a SIEM, a data lake, or long-term storage. Scattered, unstructured, unreliably-transported logs are worthless. This collection-and-delivery layer is unglamorous but absolutely essential plumbing: without a reliable log pipe, your SIEM has gaps, your compliance evidence has holes, and your incident responders are flying blind. syslog-ng exists to be that reliable pipe — the dependable foundation the whole log-dependent security and compliance stack is built on.

02

It lowers your SIEM bill

This is often the most compelling, bottom-line reason to deploy syslog-ng in front of a SIEM. Modern SIEM and analytics platforms are frequently priced by the volume of data ingested — so every gigabyte of raw, noisy, unfiltered log data you send them costs money, and log volumes are enormous and growing. syslog-ng sits between your sources and your SIEM and reduces the data before it arrives: it filters out noise and irrelevant events, drops what you don't need, parses and normalises the rest, and can even aggregate or transform events — so the SIEM receives a smaller, cleaner, higher-value stream rather than the raw firehose. The effect is a direct, measurable reduction in SIEM ingest volume and therefore total cost of ownership, often substantial. In many deployments the SIEM savings alone justify syslog-ng, while also improving the quality of the data the SIEM works with — a rare win on both cost and effectiveness.

03

Reliability you can bet compliance on

For logs used in security and compliance, reliability is non-negotiable: a lost log could be the one recording a breach or the evidence an auditor demands, and 'we didn't collect it' is not an acceptable answer. syslog-ng is built for this. Its disk-based buffering means that if a destination (like the SIEM) is temporarily unavailable, logs are buffered to disk and delivered when it recovers rather than being dropped — so nothing is lost during outages or spikes. Its reliable, encrypted transport ensures logs arrive intact and confidentially. And it handles very high message rates without becoming a bottleneck, so it keeps up even under the log floods that accompany incidents (exactly when you most need the data). This engineering-grade reliability, proven at massive scale across one of the world's most widely deployed log collectors, is why organisations trust syslog-ng with the logs their security and compliance depend on.

04

One pipe for a fragmented estate

Real environments are heterogeneous: Linux and Unix servers, Windows machines, network devices from many vendors, applications logging in different formats, and increasingly cloud services — each producing logs in its own way, in its own place. Collecting and unifying all of that is a genuine engineering challenge, and it's exactly what syslog-ng is designed for. It collects from an enormous range of sources across all these platforms, parses their varied formats into structured, consistent data, enriches it with context, and delivers it wherever it's needed — giving you one coherent log pipeline for a fragmented estate instead of a mess of point collectors and gaps. That breadth and flexibility, combined with powerful parsing, filtering and routing, is why syslog-ng is used as the backbone log layer under all kinds of downstream tools (SIEMs, data lakes, observability platforms) rather than being tied to any one of them — it's the vendor-neutral pipe that feeds whatever you choose.

05

From open source to enterprise to appliance

syslog-ng meets you wherever you are. It exists as a hugely popular open-source project — one of the most widely deployed log collectors in the world, battle-tested across countless systems — which gives it enormous real-world maturity and a broad community. The commercial Premium Edition adds enterprise capabilities, support and reliability features for organisations that need them, and the syslog-ng Store Box (SSB) is a turnkey log-management appliance that collects, searches, stores and secures logs with a searchable interface, without you having to build and run the infrastructure yourself. This range — open source for flexibility and reach, Premium Edition for enterprise assurance, Store Box for a packaged appliance — lets organisations adopt syslog-ng at the level that fits. And because it came to One Identity via the 2018 Balabit acquisition and sits in the Unified Identity Security Platform, it's backed by an established identity-and-security vendor with enterprise support in India through TechBag.

06

The honest scope

syslog-ng is a best-in-class log collection, processing and routing engine — the reliable, vendor-neutral pipe — and it is deliberately that, not a full SIEM or analytics platform. It doesn't do the detection, correlation, alerting and investigation that a SIEM (Splunk, Microsoft Sentinel, Elastic, etc.) does; instead it feeds those tools better, cheaper data, and complements them. For basic needs, the open-source edition or a cloud provider's native log pipeline may suffice; the value of the Premium Edition and Store Box is enterprise reliability, support, breadth and packaging. syslog-ng's edge is doing the collection-and-delivery layer superbly — with the SIEM-cost reduction and reliability that make it pay for itself — from an established vendor. TechBag scopes where syslog-ng fits in your logging and SIEM architecture, and which edition suits, honestly.

The top vector
Where most attacks start
AI detection
Phishing, BEC, impersonation
Cuts SIEM cost
Reliable, vendor-neutral
Proof, not promises

The numbers behind the platform

0 pipe
collect the whole estate's logs
The job
0 logs lost
disk-buffering through outages
Reliability
0 lower SIEM bill
reduce ingest volume & TCO
The cost win
0 editions
open source, Premium, Store Box
Adopt at your level
0
joined One Identity via Balabit
The acquisition
0 platform
log management in the identity portfolio
One Identity platform

What your log-management journey looks like

Day 0Free

Logging scoping

Your log sources (Linux, Windows, network, apps, cloud), your SIEM and its ingest cost, and your compliance retention needs. TechBag scopes it free.

Week 1–3Deploy

Collect & parse

syslog-ng deployed; key sources connected; parsing and enrichment configured; reliable, disk-buffered transport established.

Week 3+Deploy

Reduce & route

Filtering and reduction cutting SIEM ingest volume; routing to SIEM, data lake and storage; Store Box for searchable retention if scoped.

Month 2+Scale

Reliable & cheaper

One reliable log pipe feeding everything, no logs lost, SIEM cost measurably reduced. TechBag models the edition mix in INR/GST.

Trusted across regulated industries in 100+ countries

Telecom operatorsGlobal banksGovernment & defenceManaged security providersCloud & hosting providersHealthcare systemsLarge enterprisesUniversitiesTechnology companiesAnyone feeding a SIEM at scaleTelecom operatorsGlobal banksGovernment & defenceManaged security providersCloud & hosting providersHealthcare systemsLarge enterprisesUniversitiesTechnology companiesAnyone feeding a SIEM at scale
Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.5
610+ reviews*
92% would recommend
Reliability & throughput4.7
Source breadth4.6
SIEM cost reduction4.5
Ease of configuration4.1
5
63%
4
28%
3
6%
2
2%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
We put syslog-ng in front of our SIEM and cut ingest volume by a large margin — the licensing saving alone paid for it. And the data quality went up.
SOC Lead
Banking
Government
Disk-buffering is why we trust it for compliance logs. A SIEM outage doesn't mean lost logs anymore — they're buffered and delivered when it's back.
Security Engineer
Government
Telecom
One pipe for Linux, Windows, network gear and apps. It parses and normalises everything so downstream tools get clean, structured events.
Infrastructure Architect
Telecom
Healthcare
The Store Box appliance gave us searchable, secure log storage without building the infrastructure. Turnkey log management.
IT Director
Healthcare
Cloud Provider
It handles our message rates without breaking a sweat — even during incidents when the log flood hits. It keeps up when we most need it.
Platform Engineer
Cloud Provider
Technology
Vendor-neutral is the point. It feeds whatever SIEM or data lake we choose — we're not locked in, and we can reduce cost before ingest.
Security Architect
Technology
MSSP
The open-source roots mean it's battle-tested everywhere. Premium Edition added the support and reliability features we needed for production.
Head of Security
MSSP
University
Configuration has a learning curve, but the power is worth it — filtering, parsing and routing exactly how we want. Best log pipe we've used.
SecOps Lead
University
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the email security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Email-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
syslog-ngThis page

The reliable, vendor-neutral log pipe that cuts SIEM cost. This page's product.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how strong the email detection is vs how integrated with the wider security portfolio.

Easy but shallowDeep & runnableLegacy toolsDeep but heavy
syslog-ngThis page

Deep, reliable collection/processing with enterprise support and an appliance option.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

syslog-ng vs the log-management field

Open-source collectors, SIEM-native and cloud pipelines — honest lanes; the edge is reliable, vendor-neutral collection that cuts SIEM cost, with enterprise support.

Dimensionsyslog-ngrsyslog / FluentdSIEM-native collectorsCloud log pipelinesNo log layer
RoleThe reliable log pipeOpen-source collectorsTied to the SIEMCloud-nativeThe gap
Reliability (no loss)Disk-bufferingVariesVariesManagedNone
SIEM cost reductionA key strengthPossibleNoneSomeNone
Source breadth & parsingVery broadBroadSIEM-focusedCloud-focusedNone
Best fitA reliable, vendor-neutral log pipe that cuts SIEM cost, with enterprise supportDIY open-source collectionAll-in on one SIEM's collectorsPurely cloud-native loggingNobody doing security or compliance
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which email-security approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose syslog-ng if…

  • You want a reliable, vendor-neutral log pipe feeding your SIEM/data lake
  • You want to cut SIEM ingest volume and lower its total cost
  • You need no-log-loss reliability for compliance (disk-buffering)
  • You want enterprise support, breadth and a turnkey appliance option

Choose rsyslog / Fluentd if…

  • You want open-source collection and have the DIY appetite

Use SIEM-native collectors if…

  • You're all-in on one SIEM and its native ingestion suffices

Use cloud log pipelines if…

  • Your estate is purely cloud-native and provider tools cover it

No log layer if…

  • Never — no reliable logs means no monitoring, compliance or forensics
Do the math

What do email threats cost you?

Drag the sliders (count users; IT-hour cost as loaded incident rate). Estimates assume ~1.5 hours per user per year handling email threats that reach the inbox without AI filtering, with ~70% removed by stopping the mass at the gateway — the avoided-breach value (most attacks start here) is the larger, unpriced win. Illustrative.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models actual device counts and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

syslog-ng prices by edition and throughput (open source, Premium Edition, Store Box). TechBag scopes it for your logging estate in one GST quote.

syslog-ng

Best for the log pipe

  • Collect from the whole estate
  • Filter & reduce SIEM ingest
  • Disk-buffered, no logs lost

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ Store Box / Premium

Best for enterprise assurance

  • Enterprise support & reliability
  • Turnkey appliance & searchable storage
  • TechBag scopes the edition mix

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your device counts and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Source coverage

Confirm collection from ALL your sources — Linux/Unix, Windows Event Log, network devices, apps, cloud.

2
SIEM reduction

Measure the ingest-volume reduction syslog-ng achieves before your SIEM — the direct TCO saving.

3
Reliability

Test disk-buffering — simulate a SIEM outage and confirm no logs are lost, just delayed and delivered.

4
Parsing

Verify parsing and enrichment turn your messiest log formats into structured, usable events.

5
Routing

Confirm flexible routing to multiple destinations at once — SIEM, data lake, storage.

6
Edition

Decide open source vs Premium Edition vs Store Box — reliability, support and packaging needs.

7
Secure transport

Verify encrypted, authenticated transport and tamper-evident storage for compliance logs.

8
Sizing

Right-size by throughput/sources — TechBag scopes and quotes in INR/GST.

FAQ

Questions buyers ask

syslog-ng is One Identity's log management engine — one of the most widely deployed log collectors in the world, the reliable pipe that gathers, processes and routes log data from across an entire IT estate to wherever it needs to go. Every server, network device, application and security tool generates logs, and those logs are the raw material of security monitoring, compliance and troubleshooting — but only if they are reliably collected, normalised and delivered. syslog-ng collects logs from a huge range of sources (Linux/Unix, Windows, network gear, applications, cloud), parses and enriches them, filters and classifies them, and routes them to destinations like a SIEM, a data lake, or long-term storage — with the reliability (disk-buffering so nothing is lost) and performance to handle very high volumes. Critically, it can transform and reduce logs before they reach a SIEM, cutting the volume those often per-ingest-priced tools must process, which lowers SIEM total cost of ownership. It comes as the open-source project, the enterprise Premium Edition, and the Store Box (SSB) appliance, and joined One Identity via the 2018 Balabit acquisition.

Ready to build a reliable log pipe?

Scope a syslog-ng PoC (collect, parse and reduce your logs, measure the SIEM saving), or let a TechBag advisor plan your log-management architecture and edition mix.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.