Standard syslog · ECS-normalized · Real-time

Every log. One flow.Zero blind spots.

Your firewalls, servers, and endpoints already speak syslog. L-Flow collects it, normalizes it into one schema, and turns it into real-time answers.

Open PlatformView Dashboard →
FirewallRouterEndpointServerNew source

One pipeline · one schema

TrafficIPSWeb filterAntivirusVPNAuthenticationApp controlSystem eventsSD-WANEndpoint logsWeb access
How it works

Everything your SOC needs

From raw log ingestion to threat detection, reporting, and compliance — L-Flow covers the full workflow.

Real-Time Log Ingestion

Receive logs from firewalls, WAFs, servers, and endpoints via UDP/TCP syslog. Vector normalizes every field to ECS before storage.

LogsQL Query Explorer

Full-text and structured queries with time range presets, pagination, and expandable row detail. Save and share queries across your team.

Threat Detection & Alerts

11 built-in alert presets — brute force, data exfiltration, high-severity IPS hits. Automatic evaluation with Telegram notifications.

3D Threat Map

Visualize attack origins in real-time with geo-resolved arcs. Color-coded by allow/deny. Pivotable to IP relationship graphs.

Reports & Compliance

Generate PDF and CSV reports on demand or on schedule. Includes traffic summaries, policy hits, and security event timelines.

Multi-Tenant Isolation

Hard tenant boundaries enforced at every layer — query, API, and storage. Webmasters can switch context; tenants only see their data.

How it works

From raw syslog to actionable intelligence in three steps — no proprietary agents, no lock-in.

STEP 01

Ingest

Firewalls, WAFs, Linux servers, and Windows endpoints send syslog over UDP/TCP. No proprietary agents required — just point your device at a port.

STEP 02

Normalize

Vector VRL transforms map each source's raw fields to Elastic Common Schema. One query syntax works across all your sources — no per-device silos.

STEP 03

Detect & Query

LogsQL lets you query billions of events instantly. Alert rules evaluate every 60 seconds and flag anomalies the moment thresholds are crossed.

STEP 04

Alert & Notify

When a rule fires, L-Flow sends instant Telegram messages and logs every event to an immutable audit trail — so nothing slips through unnoticed.

Built on standard syslog

There's no per-vendor integration to install. Sources send standard syslog; the pipeline normalizes what it understands into ECS — and every raw line is collected, searchable, and archived either way.

Firewalls & UTM
Perimeter appliances — traffic, IPS, web filtering, VPN, and system events.
Routers & network gear
Edge and core devices streaming connection, config, and system logs.
Linux servers
Standard syslog from any distro — auth, kernel, process, and service activity.
Windows endpoints
Forwarded event logs — logons, processes, and policy changes, structured on arrival.
Web servers & WAFs
Access and error streams from your web tier, parsed into queryable fields.
No parser yet? Still covered.
Unrecognized sources are collected anyway — full-text searchable and archived raw, so nothing is lost while normalization catches up.

The workspace, live

Pin panels, run LogsQL, watch results stream in — the same workspace your analysts get on day one.

lflow.internal / my-workspace
Analyze
Dashboard
Explore
Traffic
My Workspace
Security
VPN
IPS / Threats
Web Filter
My Workspace
Drag panels to customize your view
+ Add panel
Area Chart
Donut Chart
Bar Chart
Total Events
2.4M
↑ 12% vs last 24h
Blocked
18,432
↑ 3% vs last 24h
Top Sources
192.168.10.582%
10.0.0.4157%
172.16.3.841%
Traffic over time — last 24h
Allowed
You
0
Log types normalized
0
RBAC permissions
0
Alert rule presets
ECS
Normalized schema

Ready to bring clarity
to your logs?

From raw syslog to actionable alerts — see what's happening across your network right now.

Launch L-Flow