The Syslog Server for Windows
Centralize, filter, forward and archive syslog messages from every device on your network — on the Windows server you already run.
Syslog Watcher is the actively-developed Windows syslog server trusted by 23,000+ sysadmins in 89 countries. Set up in five minutes. Meet PCI, HIPAA, SOX and GDPR retention requirements. Slash your SIEM ingest bill by filtering at the source.
- Windows 7–11
- Windows Server 2012–2025
- Full features for 30 days
Used by teams at organizations including:
All logos, trademarks, and registered trademarks are the property of their respective owners.
Built for Windows sysadmins, top to bottom
Everything you need to centralize syslog without standing up a Linux box, a Docker host, or a cloud bill.
High-performance receiver
Multithreaded UDP, TCP and TLS receivers backed by a SQLite-tuned store: 35,000+ writes/sec and 250,000+ reads/sec — plenty of headroom for production traffic.
Filter at the source
Granular rule engine to drop, route, transform or alert on messages before they hit your SIEM. Pay only for the logs you keep.
Forward to any SIEM
Splunk, Sentinel, Elastic, Graylog, QRadar, Datadog — over UDP, TCP, TLS. One Windows server, all your destinations.
Compliance-ready archive
Encrypted-at-rest archive with retention policies for PCI DSS, HIPAA, SOX and GDPR.
Alerts & reports
Trigger email alerts on complex filter rules using patterns, severity levels, originators, and message fields. Built-in syslog reports for analysis and audits.
Lightning-fast search
Indexed full-text search across millions of messages to find a needle in 90 days of logs.
Works with everything you already run
If it speaks syslog, Syslog Watcher receives it. Out of the box.
Network gear
Cisco · Fortinet · Palo Alto · SonicWall · Meraki · Ubiquiti · MikroTik · Sophos · Juniper · Aruba · Extreme
Servers & endpoints
Linux syslog/journald · Windows Event Log · ESXi · VMware vCenter · Proxmox · TrueNAS · Synology · QNAP
Forwards to
Splunk · Microsoft Sentinel · Elastic / ELK · Graylog · Datadog · Sumo Logic · QRadar · Generic UDP / TCP / TLS
Runs on
Windows 7, 8, 10, 11 · Windows Server 2012, 2016, 2019, 2022, 2025 · Bare-metal, VM, or cloud Windows instance
Why teams switch to Syslog Watcher
A snapshot of how Syslog Watcher compares to common alternatives.
| Capability | Syslog Watcher | Free / Legacy Alternatives | Cloud SIEM (per-GB ingest) |
|---|---|---|---|
| Built for Windows | Yes | Varies | Cloud-only |
| Active development | Yes — 19 years & counting | Limited | Yes |
| Modern UI | Yes | Dated | Yes |
| Filter before forwarding | Granular rule engine | Basic | After ingest (you pay first) |
| Syslog over TLS | Yes | Limited | Yes |
| PCI / HIPAA / SOX / GDPR archive | Encrypted | No | Yes (at cloud price) |
| Alerts & reports | Built in | Basic | Yes |
| Licensing model | Perpetual with 1, 3 or 5-yr Maintenance | Free, but you build it | Per-GB ingest pricing |
| Data stays on your network | Yes | Yes | No |
Straightforward pricing
Perpetual license plus your choice of 1, 3 or 5 years of maintenance (updates & technical support). No subscription. 30-day money-back guarantee.
Professional
For small IT teams and single-admin shops.
- 50 syslog originators
- 500,000 messages / hour
- All features (TLS, archive, SIEM forwarding)
- 1 year of updates & technical support
- SKU:
SW-PRO-1
Enterprise
For mid-sized environments and growing MSPs.
- 250 syslog originators
- 5,000,000 messages / hour
- All features (TLS, archive, SIEM forwarding)
- 1 year of updates & technical support
- SKU:
SW-ENT-1
Ultimate
For large environments and datacenters.
- Unlimited syslog originators
- Unlimited messages / hour
- All features (TLS, archive, SIEM forwarding)
- 1 year of updates & technical support
- SKU:
SW-ULT-1
Multi-year maintenance is discounted: Professional 3 yr $495 / 5 yr $735 · Enterprise 3 yr $775 / 5 yr $1,155 · Ultimate 3 yr $1,175 / 5 yr $1,755.
30-day money-back guarantee. Non-profit, volume and MSP pricing on request — email sales@ezfive.com. Secure checkout by PayPro Global.
What customers say
Syslog Watcher is a great product and it's a pleasure to work with a company that is so responsive.
The support I received for my question was really EXCELLENT… period! I was also impressed by the quality of the service provided.
It works beautifully, perfect for what I'm using it for. Uncluttered and well laid out, took me almost no time to figure out how to set up & use.
Common questions
- Professional — $245 (1 yr maintenance) · 50 syslog originators · 500,000 messages/hour
- Enterprise — $385 (1 yr maintenance) · 250 originators · 5,000,000 messages/hour
- Ultimate — $585 (1 yr maintenance) · unlimited originators · unlimited messages/hour
Windows client: 7, 8, 10, 11.
Runs equally well on bare metal, a Hyper-V / VMware / Proxmox virtual machine, or a cloud Windows instance on AWS, Azure or GCP.
Support: email support@ezfive.com, open a ticket at support.ezfive.com, or consult the full User Guide. Technical support is included with active maintenance.
Try Syslog Watcher free for 30 days
Full features. No credit card. Installs in five minutes on Windows 7–11 or Server 2012–2025.
Trusted by 23,000+ sysadmins in 89 countries · 19 years on the market