One pipeline · one schema
From raw log ingestion to threat detection, reporting, and compliance — L-Flow covers the full workflow.
Receive logs from firewalls, WAFs, servers, and endpoints via UDP/TCP syslog. Vector normalizes every field to ECS before storage.
Full-text and structured queries with time range presets, pagination, and expandable row detail. Save and share queries across your team.
11 built-in alert presets — brute force, data exfiltration, high-severity IPS hits. Automatic evaluation with Telegram notifications.
Visualize attack origins in real-time with geo-resolved arcs. Color-coded by allow/deny. Pivotable to IP relationship graphs.
Generate PDF and CSV reports on demand or on schedule. Includes traffic summaries, policy hits, and security event timelines.
Hard tenant boundaries enforced at every layer — query, API, and storage. Webmasters can switch context; tenants only see their data.
From raw syslog to actionable intelligence in three steps — no proprietary agents, no lock-in.
Firewalls, WAFs, Linux servers, and Windows endpoints send syslog over UDP/TCP. No proprietary agents required — just point your device at a port.
Vector VRL transforms map each source's raw fields to Elastic Common Schema. One query syntax works across all your sources — no per-device silos.
LogsQL lets you query billions of events instantly. Alert rules evaluate every 60 seconds and flag anomalies the moment thresholds are crossed.
When a rule fires, L-Flow sends instant Telegram messages and logs every event to an immutable audit trail — so nothing slips through unnoticed.
There's no per-vendor integration to install. Sources send standard syslog; the pipeline normalizes what it understands into ECS — and every raw line is collected, searchable, and archived either way.