Predictable Pricing. No Matter How Fast Your Telemetry Grows

Every plan includes the full NXLog Platform. NXLog licenses by number of sources — not data volume. Your price stays flat whether a source sends 1 event or 1 million per second.  

Contact sales
Full Premium features · 30-day trial · No credit card required

Simple, Source-Based Pricing

No per-GB charges. No ingestion surprises. Every plan includes the full platform — choose based
on scale and support needs.

Free

Explore and test the full platform in small environments.

Up to 10 sources

  • Full NXLog Platform — no feature limits
  • All supported operating systems
  • 120+ built-in integrations
  • Community support
  • Professional services
MOST POPULAR

Premium

For security and IT teams running production pipelines. Unlimited sources, zero volume caps.

Unlimited sources

  • Everything in Free
  • Professional services available as add-ons
  • Multi-year discounts
Number of sources Per source / month Total / year
11 $12.12 $1623.99
50 $7.17 $4279.66
100 $5.58 $6669.11
>100 Volume discounts available

Features Details

Download features list

Microsoft Windows support

NXLog collects various logs from MS Windows, including DHCP, DNS, file integrity monitoring, Active Directory, Exchange, IIS, SQL Server, etc

GNU/Linux support

NXLog runs on various enterprise Linux distributions such as RHEL/CentOS, Debian/Ubuntu, and SLES

Apple macOS support

Run on Apple macOS operating system

Support for x86 64-bit processors

Run the agent on current Intel and AMD 64-bit hardware

Support for x86 32-bit processors

Run the agent on Intel and AMD 32-bit hardware

Support for ARM 32-bit processors

Run the agent on 32-bit ARM systems such as armv7

Support for ARM 64-bit processors

Run the agent on 64-bit ARM systems such as Apple M1 and M2 and others

Support for IBM Power 64-bit processors

Run the agent on 64-bit IBM Power systems

Support for Sparc 64-bit processors

Run the agent on 64-bit Oracle/Sun/Hitachi Sparc systems

FreeBSD support

Run the agent on FreeBSD, a modern BSD UNIX distribution

IBM AIX support

Run the agent on the IBM AIX operating system

Oracle Solaris support

Support of Unix-like Solaris OS made for Oracle DB and Java apps

Health check

Provides HTTP response capabilities for checking NXLog's health status

External programs extension

Call an external program such as a shell script or native executable to process logs

External programs output

Sends logs to the input of an external program, such as a shell script or native executable

External programs input

Collects the output of an external program, such as a shell script or native executable

Python extension

Enhance NXLog with custom Python script support, compatible with Python 3

Python output

This module for custom log transport methods to Python scripts

Python input

Custom Python script feeds logs to NXLog. Python module required. Compatible with Python 3

Perl extension

Module extends NXLog with Perl script support for log processing

Perl output

This module makes it possible to execute Perl code in an output module that can handle the data directly in Perl

Perl input

Module makes it possible to execute Perl code in an input module to capture and inject event data directly into NXLog

Ruby extension

Module enables log processing with Ruby methods, offering logging and event manipulation functionalities

Ruby output

Customize log transport in Ruby, compatible with Ruby 2

Ruby input

This module is compatible with Ruby version 2 and has not been tested with newer versions

Java extension

Process NXLog log data using Java classes and methods

Java output

Send logs to a custom Java application. The Java application must implement the NXLog Java class to receive log records

Java input

Feed logs to NXLog from custom Java apps. Configure path and JVM

Go extension

Provides support for processing NXLog log data with methods written in the Go language

Go output

Send logs to Go scripts. Specify path to shared library

Go input

Collect logs using custom Go methods. Feed logs to NXLog. Configuration needs path to Go dynamic library

Event Log for Windows 2008/Vista/later

Collects Windows Event Log messages locally from Windows Vista/2008 and later

Collect logs from files

Provides support for collecting logs from files

Write mark log messages

Periodically generates the specified message to provide agent heartbeat

Receive logs via HTTP and HTTPS

Accepts log messages via HTTP or HTTPS connections. Supports multiline and multipart batching

Collect operational logs from NXLog

Collects the internal logs of the NXLog agent directly

Collect from the kernel log buffer

Collects logs from the kernel log buffer on Linux, BSD, and macOS

Event Log for Windows XP/2000/2003

Module to collect Windows Event Log messages on Windows XP, 2000, 2003

Collect logs from named pipes

Collects log messages from a named pipe on UNIX-like operating systems

Null input

This module does not write its output anywhere. It can be useful for creating a dummy route, for testing purposes

Systemd input

Collects system logs from the systemd journal on Linux systems

TCP input

Receives data over the network using plain TCP connections

Test generator

Generate simple events for testing, with an incremented integer up to the number of events specified

TLS/SSL input

Receives logs over the network using TLS/SSL-secured connections

Collect logs from Unix Domain Sockets

Collects logs over UNIX Domain Sockets (UDS) like /dev/log

WTMP

Parses wtmp and btmp logs on UNIX and Linux systems

Receive logs via UDP

Provides support to receive logs via the UDP protocol

Collect process accounting logs

This module can be used to collect process accounting logs from a Linux or BSD kernel

Basic Security Module Auditing input

Registers an InputType to parse BSM Auditing files & logs from kernel

Network traffic log collection

Collect network traffic information using passive network monitoring

Batched compression input

Provides a compressed network transport with optional SSL encryption

DBI input

Sends log data to a database table using the libdbi library

Linux Audit System input

Provides rule management and log collection for the Linux Audit Framework, without external dependencies

macOS ULS input

Collects logs from the Unified Logging System (ULS) on macOS 10.12 Sierra and later

Database log collection

Collects logs from database tables via Open Database Connectivity (ODBC) drivers

Basic Security Module Auditing

Collects Basic Security Module (BSM) logs used by BSD derivative operating systems, such as Solaris, macOS, and FreeBSD

AIX auditing

This feature reads audit logs directly from the AIX kernel

File integrity monitoring

Periodically scans files and directories and generates events when changes are detected

Collects logs from Google Pub/Sub

Subscribe and collect logs from a Google Pub/Sub topic using it's REST API

Collect from Apache Kafka topics

Publishes events via the Apache Kafka messaging system

macOS Endpoint Security input

Collects logs from Apple Endpoint Security on macOS 10.15 Catalina and later

Windows Performance Counters input

Collects Windows performance counters as logs

Windows Registry Monitoring input

Periodically scans the Windows Registry and generates events when changes are detected

Collect logs from Amazon S3

This module can be used to collect logs from Amazon S3 and compatible services

Collect from Microsoft Azure

Collects logs from Azure Table storage, Azure Blob storage, and Azure Log Analytics tables

Collect from Check Point devices

Collects logs remotely from Check Point devices using the Opsec LEA protocol

Event Tracing for Windows input

Collects logs from the Event Tracing for Windows (ETW) API

Collect from Google Cloud Logging

Collects logs from the Google Cloud Logging REST API

Collect logs from Microsoft 365 log collection

Collects logs from Microsoft 365 services

Collect logs from a Redis database

This module can retrieve data stored in a Redis server. The module issues LPOP commands using the Redis Protocol

Salesforce log collection

Collects Event Log Files from Salesforce using the REST API

Windows Event Collector input

This module collects Windows events forwarded by Microsoft Windows clients with Windows Event Forwarding (WEF)

Collect logs over ZeroMQ

Collects logs over ZeroMQ (zmq, 0mq) message transport

Parse NetFlow payloads

Collects and parses NetFlow and IPFIX data using UDP

Parse SNMP trap messages

Collects and parses Simple Network Management Protocol (SNMP) trap messages over UDP

Collects events from Okta System Log

The module can collect events from Okta System Logs with SWSS authorisation.

Collects metrics from bundled OSQuery

The module can collect OS-level metrics with embedded OSQuery engine.

Collects agent's internal metrics for forwarding

Collect agent's internal metrics for forwarding

Sends emails from the agent

Send emails from the agent

Filter

This module forwards logs if the specified condition is met.

Format Converter

This module can parse and convert logs to BSD syslog, IETF syslog, CSV, JSON, and XML data formats.

Timestamping

This module provides support for the Time-Stamp Protocol as defined in RFC 3161.

Character set converter

Tools for converting text between character sets

Parse or generate logs in CSV format

Parses and generates any comma- and delimiter-separated data (CSV)

File operations

Performs file operations for log rotation and log file management within the NXLog Agent

Processing logs in Graylog Extended Log Format (GELF)

Sends and receives logs in the Graylog Extended Log Format (GELF)

Parse and generate logs in JSON format

Parses and converts JSON formatted logs

Parse and generate logs formatted as key-value pairs

Provides functions and procedures for processing data formatted as key-value pairs (KVPs)

Grok pattern matcher

Grok patterns parse unstructured logs into structured data for analysis

NXLog pattern matcher

Performs efficient pattern matching with an XML pattern database file

Parse or generate logs in syslog format

Parses and converts log data to and from the various syslog formats

Parse and generate logs in XML format

Functions for XML log formatting and parsing, converting messages and extracting fields

Process multiline logs

Parses log messages that span multiple lines

W3C Extended Log Format

Parses log data in the W3C Extended Log File Format and similar formats

Blocker

This module blocks log messages and can be used to simulate a blocked route

Null processor

Module has no special processing but can be utilized with directives

macOS system logs

Collects and parses Apple System Logs (ASL) files on Apple macOS machines

Log compression and decompression

Compress and decompress data using gzip or zlib algorithm

Log encryption and decryption

On-the-fly encryption or decryption for log data to provide data-at-rest encryption for log files

Compare lists

Provides functions to implement file-based blacklisting and whitelisting functionality

Resolver

Functions for resolving IP addresses, user IDs, group IDs, and their names

Rewrite logs

Add, remove, delete, or rename fields in events. Useful for cleaning, enriching, or adjusting logs at the point of collection

Buffer processing

Module supports disk- and memory-based log message buffering

Pattern matching

This module makes it possible to execute pattern matching with a pattern database file in XML format

Event correlation

This feature provides conditional execution based on correlation between events

HMAC message integrity checking

This module is the pair of pm_hmac to check message integrity

De-Duplicator processing

This feature filters out repeating messages through checking the previous message against the current

Parse events in the AIX Audit format

Module parses AIX Audit logs for comprehensive log management

ArcSight Common Event Format

Generates and parses data in the Common Event Format (CEF) developed by Arcsight

Log Event Extended Format (LEEF)

Parses and generates data in the Log Event Extended Format (LEEF) by Qradar

Microsoft DNS Server

Parses debug logs generated by Microsoft DNS Server

Microsoft Network Policy Server