Skip to content
OBSERVE. ANALYZE. ACT.
Support Login

Logs / Collection and intelligence

Turn local events into operational answers.

Collect Syslog at the site, make it searchable, and send the events that matter to your central tools. 01Layer brings intake, parsing, local retention, and selective delivery into one operating environment.

Syslog sources feed local parsing and evidence storage, with search at the site and selective delivery to central tools.
View the workflow at full size

Investigate at the source

Search local events as they arrive, without waiting for downstream ingestion.

Keep the evidence

Retain original messages alongside normalized fields and parser context.

Control what leaves

Apply filtering, redaction, and routing to downstream delivery.

Flexible intake

Meet the sources where they are.

Syslog Collector & Message Broker accepts legacy and modern event streams. Listener configuration defines transport, source access, message framing, and the limits used to receive each feed.

UDP

Connect existing emitters

Accept one-message datagrams from devices that use UDP Syslog. Size receive buffers for expected bursts and use visible drop counters to understand best-effort delivery.

Syslog function

TCP

Frame the complete message

Receive stream-based logs with RFC 6587 octet-counting or LF, NUL, and CRLF delimiters. Octet-counting keeps embedded newlines from splitting a message.

Broker controls

TLS / mTLS

Define trust at the listener

Configure server certificates, client CA material, client authentication, and the accepted TLS version. Preserve TLS peer identity separately from the hostname claimed inside the event.

Listener properties

Transparent processing

Keep the original. Understand the fields.

Parse RFC 5424 and RFC 3164 envelopes, then inspect the message body with CEF, LEEF, JSON, key-value, or selected vendor profiles. Tolerant parsing and raw fallback keep non-conforming input visible.

Envelope and payload
Extract facility, severity, host, application, event time, and supported payload fields. Keep dynamic payload fields namespaced.
Parser provenance
Expose the parser name, version, status, and error code so an operator can distinguish a parsed event from a raw fallback.
Raw evidence
Retain raw messages beside normalized fields. Optional SHA-256 hashing supports inspection of the original message record.
Delivery redaction
Use ordered redaction rules to construct a separate delivery message. Choose the output payload that downstream services receive.

The invalid-message policy and raw-fallback behavior are configurable. Review sample messages before deciding whether a parser failure should pass through or be dropped.

Syslog broker listener and TLS properties
The NextIO component exposes listener and TLS settings. Values shown are configuration examples. View full size.

Local evidence and analytics

Search first. Escalate with context.

The local store keeps normalized columns and raw evidence available for investigation. Search by time, source, host, severity, facility, application, payload type, parse status, or message text.

Work with the data locally

Use search, DuckDB SQL, notebooks, and dashboards to investigate a time window or a recurring event pattern. Add source, site, zone, and host context so the result can be compared with flow and traffic evidence.

Export CSV, JSONL, or Parquet when an investigation needs a portable dataset for an audit, notebook, or incident review.

Set retention by operational value

Apply disk quotas and separate schedules for raw and parsed data. Retention can follow listener, source, severity, payload type, or site.

Review disk use and the retained time horizon alongside event volume. A useful retention policy preserves the evidence required for the expected investigation window.

Controlled forwarding

Keep local depth. Share the selected events.

Connect collection to the delivery path that matches your central monitoring or security workflow.

Log delivery choices
PathUse it forHow it operates
Syslog relayExisting log receiversA Syslog sender defines destination transport, receiver address, port, and message rendering. Confirm framing and decoding at the receiver.
Approved analytics sinkCentral SIEM or HTTP ingestionApply source, severity, filtering, and redaction rules before forwarding selected events. Validate the receiving format and route.
Kafka across a one-way boundarySegmented log and telemetry pipelinesKafka Message Broker and Sender prepare and reconstruct events around a Data Diode path, with optional encryption and destination-side secured publishing.
Evidence exportCase review and offline analysisExport a scoped dataset in CSV, JSONL, or Parquet, keeping the source and time range with the findings.

One-way transfer uses the dedicated Data Diode service design. A normal Syslog or Kafka connection alone does not establish a one-way boundary.

From intake to delivery

Make every stage observable.

A useful log service shows both event content and the health of the path carrying it.

  1. Define the listeners

    Set transports, ports, source allowlists, connection limits, certificates, and maximum message size.

  2. Test the interpretation

    Run representative RFC, vendor, multiline, and malformed samples through the selected parsers. Review timestamps, raw fallback, and normalized columns.

  3. Set storage and routes

    Choose raw and parsed retention, redaction rules, severity or facility filters, and the destination for each selected event class.

  4. Verify the live path

    Review event and byte rates, source inventory, drops, parse quality, queue pressure, disk use, and downstream receipt before expanding the feed.

Keep exploring

From overview to operation.

Open the function descriptions, component controls, and related workflows behind this capability.

Build a log service around your operation.

Discuss the sources, service requirements, and deployment that fit your operation.

Talk to our team