Thursday, October 8, 2026

Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional

Stamford, CT, September 16th, 2026, CyberNewswire

Now in early access, AxoDetect runs Sigma rules in stream alerts travel to the SIEM, and full-fidelity logs land in AxoLake, a low-cost security data lake

Detection engineers do not need more detections. They need their existing detections to fire earlier, on cleaner data, without paying SIEM ingest rates for the privilege.

Announced during Splunk .conf26, AxoDetect, Axoflow’s detection component, now in early access, runs a customer’s rules directly in the pipeline, on clean, normalized security data, before anything reaches the SIEM.

The result decomposes the SIEM’s oldest bargain. Alerts travel to the SIEM. Full-fidelity logs land in AxoLake – Axoflow’s low-cost security data lake that also runs on-prem.

The SIEM stops working as an expensive log management solution and becomes what analysts actually use: a SecOps workflow engine, now optional to feed in full.

Detection engineers write new Sigma rules, tune existing ones, and pick up rules from the community, in one open format that carries across tools. AxoDetect runs them in the pipeline.

What the platform adds is visibility that never lived in one place: what data is coming in, which detection each source feeds, and where a rule lacks the data it needs.

Until now, that was back-and-forth between teams detections owned by one, data by another held together with duct tape and tool-switching.

For the CISO, the champion’s win reads as a SIEM bill cut by half or more, with coverage kept intact: a global industrial company cut SIEM costs 50% and mean time to resolution 85%; a government agency cut data volume 80% and infrastructure footprint 85%.

“The SIEM became the industry’s most expensive data swamp because it was the place where we kept all of our raw data,” said Balázs Scheidler, CEO and co-founder of Axoflow and creator of syslog-ng.

“That constraint is gone. Detection belongs in the data layer, on normalized data, before the ingest meter starts. Keep your workflow in the SIEM. Send the alerts, but not your entire data estate.”

Where the platform is going: the full detection lifecycle running where the data lives, rolling out in the months ahead.

About Axoflow

Axoflow is the autonomous security data layer, collecting, processing, routing, storing, and managing data, with in-stream detection in early access.

AI-based autonomy, not just a chatbot, drives 10X faster investigations, 50% lower SIEM spend, and near-zero pipeline maintenance. From the creators of syslog-ng.

Contact

VP of Marketing

Mate Benedek

Axoflow

[email protected]

CyberNewswire
CyberNewswire
A PR Newswire Syndication Platform for Cybersecurity Companies

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR:...

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489,...

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to...

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to...

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational...

wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass

wolfSSL has released wolfSSH version 1.6.0, which addresses five...

Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code

Gitea has released version 28.0.0, addressing 20 vulnerabilities related...

Related Articles

Recent News