CENTRALIZED LOG MANAGEMENT

All Your Logs in One Place. Zero Loss, Signed Archive.

izLog collects, understands and stores logs from your servers, firewalls, databases, applications and files in one platform, searches them in seconds, raises real-time alerts, and keeps them in a signed, legally admissible archive for as long as you need. Installed on your own server with a single command; your data never leaves.

Zero Log Loss
Court-Grade Signed Archive
Compliance-Focused
Your Data Stays On-Site

Who Is It For?

Built for organizations that must not only keep logs but prove their integrity, with real compliance obligations.

Compliance Frameworks

5651 KVKK ISO 27001 PCI-DSS

Sectors

Banking & Payments Public Sector Hosting & Service Providers Enterprise IT Teams

An Enterprise Log Platform Built by IzHost

izLog is a closed-source commercial product we develop and control end to end. It installs on a single server and runs independent, single-purpose services: if one service stops, the others keep running and the stopped one resumes where it left off. The core promise is simple — the source is never told "received" until a record is durably written; that is why nothing is lost.

Zero Log Loss
Court-Grade Signed Archive
Compliance-Focused
Your Data Stays On-Site

Why izLog?

Ten core values — all working in the product, verified in the field.

Your Logs Are Never Lost

No acknowledgement until a record is durably written. The device agent buffers to disk when it cannot reach the server and sends once connectivity returns. Even if the search layer fails, collection and archiving continue.

Court-Grade Archive

Every archive package carries a SHA-256 chain, an Ed25519 digital signature and an RFC 3161 timestamp, and is locked against deletion in object storage. The claim "this log was not altered" is proven mathematically.

No Silent Failures

A stopped log stream, a halted service or a full disk instantly becomes an alert in the panel. Problems do not disappear quietly; critical faults show red, warnings amber.

No Technical Expertise Required

A product-catalog device wizard (FortiGate, Windows, IIS, MSSQL…), alerting without a query language, and defining a parser by selecting fields from a sample log with the mouse. You pick the product, not the protocol.

Your Data Stays With You

izLog runs in air-gapped networks; there is no cloud requirement. All logs, archive and settings remain on your own server — data sovereignty is entirely yours.

One-Command Install, Self-Updating

Installation is a single command; components install, disks are prepared, the system comes up and starts monitoring itself. New versions self-update; if a health check fails, it automatically rolls back to the previous version.

Every Action Is Recorded

Every admin action in the panel, every login attempt (success/failure) and every search is written to an audit log: who, when, on which record, and before/after.

Enterprise Identity Integration

Sign in with Active Directory / LDAP or RADIUS; list users from an AD group and authorize them in bulk. Each user sees only the devices assigned to them — enforced server-side.

Migration From Your Old System

Historical logs from an existing Elastic, Graylog or QRadar deployment are imported with their original timestamps. Nothing is left behind when you move off the old system.

Turkish Product, Turkish Support

The interface is fully available in Turkish and English. The product is developed by IzHost; support comes straight from the team that builds it.

The Journey of a Log

Every stage is independent and resilient. If one layer slows, data is not lost; it is buffered and resumes where it left off once the layer recovers.

1

Receive

A device sends syslog, an agent forwards, or izLog pulls it (Syslog UDP/TCP/TLS, HTTP).

2

Durable Queue

No "received" until it is written to the transport buffer (Kafka/Redpanda). The log is safe.

3

Understand

The device and log type are detected automatically; fields (user, IP, action, path) map to a common schema, and the raw log is preserved.

4

Index

Written to the search engine (OpenSearch); searchable in the panel within seconds.

5

Alert

Threshold / absence / match rules over the stream; email, Telegram, Teams, webhook notifications.

6

Archive

Enters a signed, timestamped, immutable package stored on a disk independent of the live data.

Manage It All From One Panel

A single browser interface, in Turkish and English. Every page answers a concrete question.

Overview

"What is the system doing right now?" Live log flow, daily volume, top log-producing devices, severity distribution and system health.

Log Search

"When, by whom, and from where did this happen?" Date + filter + free search; AND/OR/NOT, exact phrase, wildcard and parsed field names.

Log Sources

"Which devices are sending logs, and which went quiet?" Device list, collection method, agent version, last log time and the new-device wizard.

User Activity

"On Windows, who logged on, which account changed?" Logon/logoff, account management, service and software installation.

File Integrity (FIM)

"Which file changed, and who changed it?" Create/modify/delete/rename events, the user and process behind the change, hash comparison.

Alerts

"Notify me when this happens." Rule + time window + threshold + device scope, trigger history, and a live preview before saving.

Archive

"How do I see last year's logs?" Device × day summary, one-click day/hour restore, signed package download and export.

Parser Studio

Ready-made parsers (FortiGate, Windows, IIS, MSSQL, JSON, CSV…) and defining your own: select a field from a sample log with the mouse and the pattern builds itself.

Collect Logs From Any Source

Almost every system on your network can talk to izLog — most without installing anything on the device.

Firewall & Network

FortiGate, Palo Alto, Cisco ASA, pfSense, switches/routers — Syslog (UDP/TCP/TLS). The device sends to izLog; no install needed.

Windows & Active Directory

Event logs pulled agentlessly via WinRM; a lightweight agent (one command) for file integrity and user activity.

IIS Web Server

IIS access logs pulled agentlessly over SMB, or collected via the agent.

Linux Servers

An agent for SSH logins, commands and access control; nginx/apache/app file logs can also be pulled over SSH.

Databases

MSSQL, PostgreSQL, MySQL log tables and MSSQL audit (.sqlaudit) files — izLog connects read-only and never skips records thanks to a cursor.

Applications & Custom

Direct ingestion from applications and custom sources over REST/HTTP.

Migration From Old Systems

Historical logs from Elastic, Graylog or QRadar are imported with their original dates.

The device wizard lets you pick the product; the port, format and defaults come ready. For agent-based setups a one-line command is generated.

Why the Archive Is Court-Grade Evidence

The combination of signing, timestamping and immutable storage turns your logs from merely "kept records" into records whose integrity can be proven and that carry legal weight.

Open Format (JSONL + zstd)

Compressed, portable package — a fraction of the live copy's size, independent of the search engine.

SHA-256 Chain

If package content changes even slightly, the chain breaks and it is detected.

Ed25519 Digital Signature

Proves mathematically that the package was produced by izLog.

RFC 3161 Timestamp

"This content existed on this date" — independent third-party time attestation.

Object Lock

No one — not even an admin — can delete or alter it before retention expires.

Handover to Auditors

Restore the relevant day/hour, download the package with its signature, and hand it to an auditor or court as-is.

Compliance & Audit Readiness

Retain access and transaction records for the required period with provable integrity; document who accessed what, and when.

Log Retention

Keep access and transaction records for the legally required period, with integrity provable via timestamps.

Data Protection

Keep access trails to personal data with an audit log; document who performed the access and when.

ISO 27001

Centralize, protect and make event records traceable — ready for information security management requirements.

PCI-DSS

Keep payment-environment access and audit records immutable and review-ready.

Installation & Self-Management

No manual intervention on the customer server — the system installs, monitors and repairs itself.

One-Command Install

After the service is defined, a single command on the server: components install, disks are prepared (live and archive disks must be separate), and the system comes up.

Self-Updating

New versions update automatically; packages are verified with SHA-256. Agents self-update too and can be forced from the panel.

Automatic Rollback

If an update fails its health check, the system automatically returns to the working previous version — minimizing downtime risk.

Continuous Health Monitoring

A supervisor checks components every 30 seconds, restarts failures and watches disks; disk expansion is done from the panel.

Enterprise Robustness

Designed for high-volume, mission-critical environments; the live disk and archive disk are always separate.

Durable Backbone

Kafka / Redpanda transport buffer; even if processing slows, logs are not lost.

Scalable Search

Automatic rollover via index lifecycle management on OpenSearch; expired live data is dropped preserving integrity.

Open-Format Archive

JSONL + zstd; independent of the search engine, portable, long-lived and evidence-grade.

Secure Secret Management

Passwords and tokens are stored encrypted with AES-256-GCM and never returned to the panel; settings/audit data in PostgreSQL.

Let us build your centralized log infrastructure

Talk to our team for an izLog deployment and pricing sized to your needs and event volume (EPS). We support you with installation, source integration and retention policies.

Frequently Asked Questions

Will I lose logs if the search server goes down?

No. Logs are first written to the durable transport buffer. Even if the search layer (OpenSearch) fails completely, collection and archiving keep running; once it recovers, the buffered logs are indexed.

Are last year's logs still there?

The live retention window may have expired; the record stays in the archive. From the Archive page you restore the relevant day or hour range with one click and review it in normal search. The right design: a short live window plus the full legal period in the archive.

How do I prove a log was not tampered with?

Download the archive package with its signature and timestamp. It carries a SHA-256 chain, an Ed25519 signature and an RFC 3161 timestamp; if content changes, chain verification fails. Object Lock prevents any change during retention.

It does not recognize our application's log format.

Define fields from a sample log in Parser Studio — select a value with the mouse and click "Make Field". Until then the log is not lost; it is stored raw and remains searchable.

We want each user to see only their own servers' logs.

Assign each user their "visible devices" on the Users page. The restriction is enforced server-side; out-of-scope queries return empty and cannot be bypassed from the UI.

If the license expires, do we lose our logs?

No. Collection continues and data stays in place; only viewing in the panel is disabled. The moment the license is renewed, all history becomes accessible again.