News

NXLog Agent 6.15 Adds RHEL 5 and CentOS 5 Support for Legacy Log Collection

News | 18.08.2026

NXLog: Some of the most critical systems in enterprise infrastructure are also among the oldest. Organizations in energy, manufacturing, government, and other regulated industries may still operate systems based on Red Hat Enterprise Linux 5 or CentOS 5 because upgrading the operating system is not technically or operationally feasible. These systems continue to generate security and operational logs, but collecting that data can be difficult when modern log management agents no longer support the underlying platform.

With NXLog Agent 6.15, RHEL 5 and CentOS 5 are now officially supported platforms. Organizations can install NXLog Agent on these legacy systems, collect and forward their logs, and manage the agents centrally through NXLog Platform alongside modern Windows and Linux endpoints.

At a Glance

  • NXLog Agent 6.15 adds official support for Red Hat Enterprise Linux 5 and CentOS 5.
  • Legacy systems can remain part of the organization's centralized logging and security monitoring strategy.
  • NXLog Agent provides local log collection, parsing, processing, and forwarding from supported legacy systems.
  • The same NXLog configuration language can be used across legacy and modern Linux environments.
  • RHEL 5 and CentOS 5 hosts can be managed through NXLog Platform alongside other agents in the fleet.
  • Legacy log collection helps close compliance and security visibility gaps without requiring an operating system upgrade.

Why RHEL 5 Still Matters in 2026

Red Hat ended standard support for RHEL 5 in 2017. Despite this, RHEL 5 and CentOS 5 systems can still be found in production environments. Their continued use is often driven by technical, regulatory, or operational requirements rather than a lack of modernization efforts.

Compliance-Frozen Environments

In regulated industries, changing a validated system configuration can require extensive re-certification, additional audits, testing, and planned downtime. For some organizations, upgrading the operating system is therefore not a straightforward infrastructure change.

OT and Industrial Control Systems

Industrial equipment and operational technology can depend on software that was certified for a specific operating system version. Upgrading the underlying OS may invalidate the certification or cause critical applications to stop working. As a result, legacy operating systems can remain tied to production equipment for many years.

Hardware and Software Dependencies

Some legacy applications depend on older kernels, libraries, drivers, or hardware. Replacing the operating system may therefore require replacing the application, hardware, and surrounding processes as well.

These environments can also have particularly strict security and logging requirements. The systems that are hardest to upgrade are often the systems that organizations cannot afford to leave outside their monitoring and compliance infrastructure.

What NXLog Agent 6.15 Adds

NXLog Agent 6.15 officially adds Red Hat Enterprise Linux 5 and CentOS 5 to its supported platforms. The release addresses a practical requirement for organizations that need centralized logging from systems that cannot easily be upgraded.

Installation follows the familiar Linux deployment model. On a supported 64-bit x86_64 RHEL 5 or CentOS 5 system, administrators can install the NXLog Agent RPM without relying on custom compatibility layers or manually built software packages.

Because RHEL 5 predates many libraries and dependencies used by modern applications, the NXLog Agent build for these platforms is specifically designed for legacy environments. It provides a focused set of modules covering common logging and forwarding requirements rather than the complete module catalog available on current operating systems.

Depending on the supported configuration, organizations can use NXLog Agent for:

  • Local log collection from files, syslog, and other supported system sources.
  • Log parsing and processing before events are forwarded to downstream systems.
  • Centralized forwarding to NXLog Platform, a SIEM, or another supported destination.
  • Consistent configuration using the same NXLog configuration language used across the rest of the Linux environment.

For the latest platform and module availability, organizations should refer to the official NXLog documentation for RHEL installation.

One Logging Approach Across Legacy and Modern Systems

One of the key benefits of adding legacy operating systems to the supported platform list is the ability to integrate them into the same logging architecture as newer systems.

Instead of maintaining separate scripts, custom collectors, or dedicated syslog relays for unsupported hosts, organizations can use NXLog Agent to establish a consistent collection and forwarding layer.

A typical architecture can look like this:

Infrastructure Collection Central Management Destination
RHEL 5 / CentOS 5 NXLog Agent 6.15 NXLog Platform SIEM / Storage
Modern Linux NXLog Agent NXLog Platform SIEM / Storage
Windows NXLog Agent NXLog Platform SIEM / Storage

This approach allows security and infrastructure teams to maintain a single telemetry pipeline instead of creating separate processes for legacy systems.

Managing Legacy Systems with NXLog Platform

Once a legacy RHEL 5 or CentOS 5 host is enrolled in NXLog Platform, it can be managed alongside other agents in the environment.

This central management model can help reduce the operational burden associated with legacy infrastructure. Instead of repeatedly connecting to individual servers through SSH, administrators can use centralized management to monitor and configure agents across the fleet.

From the central platform, teams can:

  • Monitor agent status and connectivity.
  • Review event activity and performance information.
  • Deploy logging configurations remotely.
  • Apply consistent collection policies across multiple operating systems.
  • Manage legacy systems alongside current Windows and Linux endpoints.

The result is that the operating system version becomes an implementation detail rather than a reason for excluding the system from centralized visibility.

Closing the Logging Gap on Legacy Infrastructure

Legacy systems can create significant challenges for security operations. They may be difficult to patch, isolated from the rest of the infrastructure, dependent on outdated applications, or subject to strict change-control procedures. None of these factors eliminates the need to monitor them.

Compliance Coverage

Regulatory and internal security requirements generally do not disappear simply because a server runs an older operating system. Centralized log collection helps organizations maintain the evidence required for security monitoring, incident investigation, and compliance processes.

Security Visibility

Systems that cannot be regularly upgraded can represent an increased security risk. Logs provide an important source of evidence for identifying configuration changes, authentication activity, system errors, and suspicious behavior.

A Single Telemetry Pipeline

Supporting legacy operating systems through the same logging platform can reduce dependence on custom scripts, isolated collectors, and manually maintained forwarding mechanisms.

Legacy Systems and Modern Security Operations

Modern SOC teams increasingly depend on centralized telemetry to detect threats and investigate incidents. Leaving older systems outside the logging architecture creates a visibility gap that can affect the entire security monitoring process.

NXLog Agent 6.15 helps address this problem by extending centralized log collection to RHEL 5 and CentOS 5 environments. Organizations can continue operating systems that cannot yet be upgraded while still integrating their logs into a modern security monitoring architecture.

Challenge Traditional Approach NXLog Agent 6.15 Approach
Legacy OS support Custom scripts or unsupported agents Official NXLog Agent support
Log collection Separate collectors and relays NXLog Agent
Configuration Manually maintained configurations Centralized NXLog configuration
Security monitoring Potential visibility gaps Integration with centralized SIEM and logging infrastructure
Fleet management Individual host administration Central management through NXLog Platform

Conclusion

Legacy operating systems are not necessarily temporary problems. In manufacturing, energy, government, healthcare, and other regulated environments, some systems may remain operational for years because upgrading them is technically, financially, or operationally impractical.

That should not mean accepting a permanent logging blind spot.

With NXLog Agent 6.15, organizations can bring RHEL 5 and CentOS 5 systems into the same centralized logging architecture as modern infrastructure. Logs can be collected locally, processed and forwarded to the required destinations, while NXLog Platform provides centralized visibility and management.

As an official NXLog distributor, Softprom can help organizations evaluate NXLog Agent and NXLog Platform for environments that combine modern infrastructure with legacy and hard-to-upgrade systems.