securityonline.info 16 Sept 2026, 10:09 UTC

Axoflow Pre-Processes Sigma Detections to Cut SIEM Data Volumes

Axoflow Pre-Processes Sigma Detections to Cut SIEM Data Volumes
CyberSIXT Evidence Panel Source marked as original reporting

AXOFLOW has announced AxoDetect, a detection component now available in early access. Introduced during Splunk .conf26 on 16 September 2026, it runs Sigma rules within the security-data pipeline, before data reaches a security information and event management (SIEM) platform. The company says the system operates on cleaned and normalised data, sending detection alerts to the SIEM while storing full-fidelity logs in AxoLake, its lower-cost security data lake, which can also run on premises.

Axoflow says this approach is intended to reduce the volume of data sent to SIEM systems while preserving analysts’ existing workflows. Detection engineers can create, tune and reuse Sigma rules, while AxoDetect shows which incoming data sources support each detection and where required information is missing.

The company cites claimed results from a global industrial organisation that cut SIEM costs by 50% and mean time to resolution by 85%, and a government agency that reduced data volume by 80% and infrastructure footprint by 85%; the announcement provides no further evidence or independent verification of those figures. Axoflow says it plans to expand the platform to cover the full detection lifecycle in the coming months.

View full article

Article by CyberSIXT