Introduction

Axoflow has launched AxoDetect, a detection engine that operates directly in the security data pipeline on normalized information before it reaches the SIEM. The platform aims to separate detection from costly data ingestion, giving engineers earlier visibility and lower operational expenses.

What Happened

Announced at Splunk .conf26, AxoDetect runs customer Sigma rules on clean, normalized data streaming through the pipeline. Full-fidelity logs are diverted to AxoLake, Axoflow’s low-cost security data lake, while only alerts flow to the SIEM. Detection engineers can write, tune, and share Sigma rules in a single open format that works across tools. The platform provides visibility into incoming data, which detection each source feeds, and where a rule lacks needed context. Previously, detections and data were split between teams, held together with manual tool-switching and “duct tape.” CISOs have seen tangible results: a global industrial company cut SIEM costs by 50% and mean time to resolution by 85%, while a government agency reduced data volume by 80% and infrastructure footprint by 85%.

Why This Matters

The SIEM has long been forced to serve as both a workflow engine and a data repository, driving up ingest rates and turning the system into what the CEO calls “the industry’s most expensive data swamp.” By moving detection into the pipeline on normalized data, AxoDetect lets the SIEM return to its core role: orchestrating response, not storing raw logs. Analysts gain a clear view of data gaps, detection coverage improves, and teams spend less time toggling between tools. For organizations drowning in log volume, the model offers a path to trim the data estate without sacrificing detection fidelity.

Key Takeaways

  • AxoDetect runs Sigma rules in the pipeline on clean, normalized data before the SIEM ingest meter starts.
  • Full-fidelity logs land in AxoLake, a low-cost security data lake that also supports on-prem deployment.
  • Only alerts are forwarded to the SIEM, keeping the SIEM as a workflow engine rather than a data warehouse.
  • Customers have reported up to 50% SIEM cost reduction and 85% faster mean time to resolution.
  • Detection engineers gain visibility into data gaps and coverage holes across all sources.
  • The platform is in early access, with a full detection lifecycle rolling out in the months ahead.

Conclusion

Axoflow positions AxoDetect as the first component of an autonomous security data layer that collects, processes, routes, stores, and manages security data with in-stream detection built in. AI-driven autonomy, not just a chatbot, promises 10X faster investigations, near-zero pipeline maintenance, and a fundamental shift away from the SIEM-as-data-model mindset. Early access is available now, with the full detection lifecycle coming in the coming months.