Predictable Pricing. No Matter How Fast Your Telemetry Grows
Every plan includes the full NXLog Platform. NXLog licenses by number of sources — not data volume. Your price stays flat whether a source sends 1 event or 1 million per second.
Simple, Source-Based Pricing
No per-GB charges. No ingestion surprises. Every plan includes the full platform — choose based
on scale and support needs.
Free
Explore and test the full platform in small environments.
Up to 10 sources
- Full NXLog Platform — no feature limits
- All supported operating systems
- 120+ built-in integrations
- Community support
- Professional services
Features Details
Microsoft Windows support
NXLog collects various logs from MS Windows, including DHCP, DNS, file integrity monitoring, Active Directory, Exchange, IIS, SQL Server, etc
GNU/Linux support
NXLog runs on various enterprise Linux distributions such as RHEL/CentOS, Debian/Ubuntu, and SLES
Apple macOS support
Run on Apple macOS operating system
Support for x86 64-bit processors
Run the agent on current Intel and AMD 64-bit hardware
Support for x86 32-bit processors
Run the agent on Intel and AMD 32-bit hardware
Support for ARM 32-bit processors
Run the agent on 32-bit ARM systems such as armv7
Support for ARM 64-bit processors
Run the agent on 64-bit ARM systems such as Apple M1 and M2 and others
Support for IBM Power 64-bit processors
Run the agent on 64-bit IBM Power systems
Support for Sparc 64-bit processors
Run the agent on 64-bit Oracle/Sun/Hitachi Sparc systems
FreeBSD support
Run the agent on FreeBSD, a modern BSD UNIX distribution
IBM AIX support
Run the agent on the IBM AIX operating system
Oracle Solaris support
Support of Unix-like Solaris OS made for Oracle DB and Java apps
Health check
Provides HTTP response capabilities for checking NXLog's health status
External programs extension
Call an external program such as a shell script or native executable to process logs
External programs output
Sends logs to the input of an external program, such as a shell script or native executable
External programs input
Collects the output of an external program, such as a shell script or native executable
Python extension
Enhance NXLog with custom Python script support, compatible with Python 3
Python output
This module for custom log transport methods to Python scripts
Python input
Custom Python script feeds logs to NXLog. Python module required. Compatible with Python 3
Perl extension
Module extends NXLog with Perl script support for log processing
Perl output
This module makes it possible to execute Perl code in an output module that can handle the data directly in Perl
Perl input
Module makes it possible to execute Perl code in an input module to capture and inject event data directly into NXLog
Ruby extension
Module enables log processing with Ruby methods, offering logging and event manipulation functionalities
Ruby output
Customize log transport in Ruby, compatible with Ruby 2
Ruby input
This module is compatible with Ruby version 2 and has not been tested with newer versions
Java extension
Process NXLog log data using Java classes and methods
Java output
Send logs to a custom Java application. The Java application must implement the NXLog Java class to receive log records
Java input
Feed logs to NXLog from custom Java apps. Configure path and JVM
Go extension
Provides support for processing NXLog log data with methods written in the Go language
Go output
Send logs to Go scripts. Specify path to shared library
Go input
Collect logs using custom Go methods. Feed logs to NXLog. Configuration needs path to Go dynamic library
Event Log for Windows 2008/Vista/later
Collects Windows Event Log messages locally from Windows Vista/2008 and later
Collect logs from files
Provides support for collecting logs from files
Write mark log messages
Periodically generates the specified message to provide agent heartbeat
Receive logs via HTTP and HTTPS
Accepts log messages via HTTP or HTTPS connections. Supports multiline and multipart batching
Collect operational logs from NXLog
Collects the internal logs of the NXLog agent directly
Collect from the kernel log buffer
Collects logs from the kernel log buffer on Linux, BSD, and macOS
Event Log for Windows XP/2000/2003
Module to collect Windows Event Log messages on Windows XP, 2000, 2003
Collect logs from named pipes
Collects log messages from a named pipe on UNIX-like operating systems
Null input
This module does not write its output anywhere. It can be useful for creating a dummy route, for testing purposes
Systemd input
Collects system logs from the systemd journal on Linux systems
TCP input
Receives data over the network using plain TCP connections
Test generator
Generate simple events for testing, with an incremented integer up to the number of events specified
TLS/SSL input
Receives logs over the network using TLS/SSL-secured connections
Collect logs from Unix Domain Sockets
Collects logs over UNIX Domain Sockets (UDS) like /dev/log
WTMP
Parses wtmp and btmp logs on UNIX and Linux systems
Receive logs via UDP
Provides support to receive logs via the UDP protocol
Collect process accounting logs
This module can be used to collect process accounting logs from a Linux or BSD kernel
Basic Security Module Auditing input
Registers an InputType to parse BSM Auditing files & logs from kernel
Network traffic log collection
Collect network traffic information using passive network monitoring
Batched compression input
Provides a compressed network transport with optional SSL encryption
DBI input
Sends log data to a database table using the libdbi library
Linux Audit System input
Provides rule management and log collection for the Linux Audit Framework, without external dependencies
macOS ULS input
Collects logs from the Unified Logging System (ULS) on macOS 10.12 Sierra and later
Database log collection
Collects logs from database tables via Open Database Connectivity (ODBC) drivers
Basic Security Module Auditing
Collects Basic Security Module (BSM) logs used by BSD derivative operating systems, such as Solaris, macOS, and FreeBSD
AIX auditing
This feature reads audit logs directly from the AIX kernel
File integrity monitoring
Periodically scans files and directories and generates events when changes are detected
Collects logs from Google Pub/Sub
Subscribe and collect logs from a Google Pub/Sub topic using it's REST API
Collect from Apache Kafka topics
Publishes events via the Apache Kafka messaging system
macOS Endpoint Security input
Collects logs from Apple Endpoint Security on macOS 10.15 Catalina and later
Windows Performance Counters input
Collects Windows performance counters as logs
Windows Registry Monitoring input
Periodically scans the Windows Registry and generates events when changes are detected
Collect logs from Amazon S3
This module can be used to collect logs from Amazon S3 and compatible services
Collect from Microsoft Azure
Collects logs from Azure Table storage, Azure Blob storage, and Azure Log Analytics tables
Collect from Check Point devices
Collects logs remotely from Check Point devices using the Opsec LEA protocol
Event Tracing for Windows input
Collects logs from the Event Tracing for Windows (ETW) API
Collect from Google Cloud Logging
Collects logs from the Google Cloud Logging REST API
Collect logs from Microsoft 365 log collection
Collects logs from Microsoft 365 services
Collect logs from a Redis database
This module can retrieve data stored in a Redis server. The module issues LPOP commands using the Redis Protocol
Salesforce log collection
Collects Event Log Files from Salesforce using the REST API
Windows Event Collector input
This module collects Windows events forwarded by Microsoft Windows clients with Windows Event Forwarding (WEF)
Collect logs over ZeroMQ
Collects logs over ZeroMQ (zmq, 0mq) message transport
Parse NetFlow payloads
Collects and parses NetFlow and IPFIX data using UDP
Parse SNMP trap messages
Collects and parses Simple Network Management Protocol (SNMP) trap messages over UDP
Collects events from Okta System Log
The module can collect events from Okta System Logs with SWSS authorisation.
Collects metrics from bundled OSQuery
The module can collect OS-level metrics with embedded OSQuery engine.
Collects agent's internal metrics for forwarding
Collect agent's internal metrics for forwarding
Sends emails from the agent
Send emails from the agent
Filter
This module forwards logs if the specified condition is met.
Format Converter
This module can parse and convert logs to BSD syslog, IETF syslog, CSV, JSON, and XML data formats.
Timestamping
This module provides support for the Time-Stamp Protocol as defined in RFC 3161.
Character set converter
Tools for converting text between character sets
Parse or generate logs in CSV format
Parses and generates any comma- and delimiter-separated data (CSV)
File operations
Performs file operations for log rotation and log file management within the NXLog Agent
Processing logs in Graylog Extended Log Format (GELF)
Sends and receives logs in the Graylog Extended Log Format (GELF)
Parse and generate logs in JSON format
Parses and converts JSON formatted logs
Parse and generate logs formatted as key-value pairs
Provides functions and procedures for processing data formatted as key-value pairs (KVPs)
Grok pattern matcher
Grok patterns parse unstructured logs into structured data for analysis
NXLog pattern matcher
Performs efficient pattern matching with an XML pattern database file
Parse or generate logs in syslog format
Parses and converts log data to and from the various syslog formats
Parse and generate logs in XML format
Functions for XML log formatting and parsing, converting messages and extracting fields
Process multiline logs
Parses log messages that span multiple lines
W3C Extended Log Format
Parses log data in the W3C Extended Log File Format and similar formats
Blocker
This module blocks log messages and can be used to simulate a blocked route
Null processor
Module has no special processing but can be utilized with directives
macOS system logs
Collects and parses Apple System Logs (ASL) files on Apple macOS machines
Log compression and decompression
Compress and decompress data using gzip or zlib algorithm
Log encryption and decryption
On-the-fly encryption or decryption for log data to provide data-at-rest encryption for log files
Compare lists
Provides functions to implement file-based blacklisting and whitelisting functionality
Resolver
Functions for resolving IP addresses, user IDs, group IDs, and their names
Rewrite logs
Add, remove, delete, or rename fields in events. Useful for cleaning, enriching, or adjusting logs at the point of collection
Buffer processing
Module supports disk- and memory-based log message buffering
Pattern matching
This module makes it possible to execute pattern matching with a pattern database file in XML format
Event correlation
This feature provides conditional execution based on correlation between events
HMAC message integrity checking
This module is the pair of pm_hmac to check message integrity
De-Duplicator processing
This feature filters out repeating messages through checking the previous message against the current
Parse events in the AIX Audit format
Module parses AIX Audit logs for comprehensive log management
ArcSight Common Event Format
Generates and parses data in the Common Event Format (CEF) developed by Arcsight
Log Event Extended Format (LEEF)
Parses and generates data in the Log Event Extended Format (LEEF) by Qradar
Microsoft DNS Server
Parses debug logs generated by Microsoft DNS Server