Balabit IT Security is an international security vendor headquartered in Luxembourg, founded in 2000 in Hungary, and still operating R&D centers there while maintaining sales offices across Europe, the US, and Russia. Its portfolio spans log management, privileged activity monitoring, and user behavior analytics, bundled as the Contextual Security Intelligence (CSI) Suite. The company’s best-known product is syslog-ng, a widely deployed log management tool for Unix-like systems with over a million installations.
Amid rising attack volumes and regulatory compliance demands, organizations increasingly need stronger event and incident analysis and response capabilities. The market splits between domain-specific tools (e.g., identity and access, privileged accounts, specialized network analytics) and generic cross-system log solutions, including log collection, SIEM, and more advanced Real Time Security Intelligence (RTSI). These tools are often complementary: log collectors can pre-process for SIEM, and SIEM can feed advanced analytics.
syslog-ng can serve either as a customizable log analysis platform or as an upstream collector/filter in front of SIEM. It comes in three editions: the Open Source Edition (OSE), the commercial Premium Edition (PE), and Store Box (SSB), an appliance. OSE extends traditional syslogd with content-based filtering, parsing/rewriting, pattern classification, correlation, metadata enrichment, broader sources/destinations (e.g., JSON, MongoDB), scalability features (multi-threading), queueing (AMQP/STOMP), TLS, and reliable TCP transport. PE adds cross-platform installers, Windows and IBM System i support via agents, and stronger security such as encryption, signing, timestamping, disk buffering, SQL destinations, and the proprietary Reliable Log Transfer Protocol (RLTP) to prevent loss or duplication. PE also introduced direct integration into Big Data targets (Hadoop, Elasticsearch, MongoDB, Kafka), centralized deployment via Puppet, improved monitoring statistics, and performance gains. SSB adds a web UI for search, drill-down, reporting, LDAP/RADIUS-based access control, multi-logspace support, and can act as a SIEM alternative or noise-reducing filter. Strengths center on breadth, security, Big Data integration, and manageability; challenges include limited preconfigurations and comparatively limited agent coverage.
See All Locations
See All Locations