Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional


Picture1

STAMFORD, Conn., Sept. 16, 2026 (GLOBE NEWSWIRE) -- Now in early access, AxoDetect runs Sigma rules in stream - alerts travel to the SIEM, and full-fidelity logs land in AxoLake, a low-cost security data lake Detection engineers do not need more detections. They need their existing detections to fire earlier, on cleaner data, without paying SIEM ingest rates for the privilege. Announced during Splunk .conf26, AxoDetect, Axoflow's detection component, now in early access, runs a customer's rules directly in the pipeline, on clean, normalized security data, before anything reaches the SIEM.

The result decomposes the SIEM's oldest bargain. Alerts travel to the SIEM. Full-fidelity logs land in AxoLake - Axoflow's low-cost security data lake that also runs on-prem. The SIEM stops working as an expensive log management solution and becomes what analysts actually use: a SecOps workflow engine, now optional to feed in full.

Detection engineers write new Sigma rules, tune existing ones, and pick up rules from the community, in one open format that carries across tools. AxoDetect runs them in the pipeline. What the platform adds is visibility that never lived in one place: what data is coming in, which detection each source feeds, and where a rule lacks the data it needs. Until now, that was back-and-forth between teams - detections owned by one, data by another - held together with duct tape and tool-switching. For the CISO, the champion's win reads as a SIEM bill cut by half or more, with coverage kept intact: a global industrial company cut SIEM costs 50% and mean time to resolution 85%; a government agency cut data volume 80% and infrastructure footprint 85%.

“The SIEM became the industry's most expensive data swamp because it was the place where we kept all of our raw data,” said Balázs Scheidler, CEO and co-founder of Axoflow and creator of syslog-ng. “That constraint is gone. Detection belongs in the data layer, on normalized data, before the ingest meter starts. Keep your workflow in the SIEM. Send the alerts, but not your entire data estate.”

Where the platform is going: the full detection lifecycle running where the data lives, rolling out in the months ahead.

About Axoflow
Axoflow is the autonomous security data layer, collecting, processing, routing, storing, and managing data, with in-stream detection in early access. AI-based autonomy, not just a chatbot, drives 10X faster investigations, 50% lower SIEM spend, and near-zero pipeline maintenance. From the creators of syslog-ng.

Contact

VP of Marketing
Mate Benedek
Axoflow
mate.benedek@axoflow.com

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/adaa94bd-cd8c-492f-bc21-5480dd7f1ffc



Tags

GlobeNewswire