NXLog Agent 6.15 Adds RHEL 5 and CentOS 5 Support for Legacy Log Collection
News | 18.08.2026
NXLog: Some of the most critical systems in enterprise infrastructure are also among the oldest. Organizations in energy, manufacturing, government, and other regulated industries may still operate systems based on Red Hat Enterprise Linux 5 or CentOS 5 because upgrading the operating system is not technically or operationally feasible. These systems continue to generate security and operational logs, but collecting that data can be difficult when modern log management agents no longer support the underlying platform.
With NXLog Agent 6.15, RHEL 5 and CentOS 5 are now officially supported platforms. Organizations can install NXLog Agent on these legacy systems, collect and forward their logs, and manage the agents centrally through NXLog Platform alongside modern Windows and Linux endpoints.
At a Glance
- NXLog Agent 6.15 adds official support for Red Hat Enterprise Linux 5 and CentOS 5.
- Legacy systems can remain part of the organization's centralized logging and security monitoring strategy.
- NXLog Agent provides local log collection, parsing, processing, and forwarding from supported legacy systems.
- The same NXLog configuration language can be used across legacy and modern Linux environments.
- RHEL 5 and CentOS 5 hosts can be managed through NXLog Platform alongside other agents in the fleet.
- Legacy log collection helps close compliance and security visibility gaps without requiring an operating system upgrade.
Why RHEL 5 Still Matters in 2026
Red Hat ended standard support for RHEL 5 in 2017. Despite this, RHEL 5 and CentOS 5 systems can still be found in production environments. Their continued use is often driven by technical, regulatory, or operational requirements rather than a lack of modernization efforts.
Compliance-Frozen Environments
In regulated industries, changing a validated system configuration can require extensive re-certification, additional audits, testing, and planned downtime. For some organizations, upgrading the operating system is therefore not a straightforward infrastructure change.
OT and Industrial Control Systems
Industrial equipment and operational technology can depend on software that was certified for a specific operating system version. Upgrading the underlying OS may invalidate the certification or cause critical applications to stop working. As a result, legacy operating systems can remain tied to production equipment for many years.
Hardware and Software Dependencies
Some legacy applications depend on older kernels, libraries, drivers, or hardware. Replacing the operating system may therefore require replacing the application, hardware, and surrounding processes as well.
These environments can also have particularly strict security and logging requirements. The systems that are hardest to upgrade are often the systems that organizations cannot afford to leave outside their monitoring and compliance infrastructure.
What NXLog Agent 6.15 Adds
NXLog Agent 6.15 officially adds Red Hat Enterprise Linux 5 and CentOS 5 to its supported platforms. The release addresses a practical requirement for organizations that need centralized logging from systems that cannot easily be upgraded.
Installation follows the familiar Linux deployment model. On a supported 64-bit x86_64 RHEL 5 or CentOS 5 system, administrators can install the NXLog Agent RPM without relying on custom compatibility layers or manually built software packages.
Because RHEL 5 predates many libraries and dependencies used by modern applications, the NXLog Agent build for these platforms is specifically designed for legacy environments. It provides a focused set of modules covering common logging and forwarding requirements rather than the complete module catalog available on current operating systems.
Depending on the supported configuration, organizations can use NXLog Agent for:
- Local log collection from files, syslog, and other supported system sources.
- Log parsing and processing before events are forwarded to downstream systems.
- Centralized forwarding to NXLog Platform, a SIEM, or another supported destination.
- Consistent configuration using the same NXLog configuration language used across the rest of the Linux environment.
For the latest platform and module availability, organizations should refer to the official NXLog documentation for RHEL installation.
One Logging Approach Across Legacy and Modern Systems
One of the key benefits of adding legacy operating systems to the supported platform list is the ability to integrate them into the same logging architecture as newer systems.
Instead of maintaining separate scripts, custom collectors, or dedicated syslog relays for unsupported hosts, organizations can use NXLog Agent to establish a consistent collection and forwarding layer.
A typical architecture can look like this:
| Infrastructure | Collection | Central Management | Destination |
|---|---|---|---|
| RHEL 5 / CentOS 5 | NXLog Agent 6.15 | NXLog Platform | SIEM / Storage |
| Modern Linux | NXLog Agent | NXLog Platform | SIEM / Storage |
| Windows | NXLog Agent | NXLog Platform | SIEM / Storage |
This approach allows security and infrastructure teams to maintain a single telemetry pipeline instead of creating separate processes for legacy systems.
Managing Legacy Systems with NXLog Platform
Once a legacy RHEL 5 or CentOS 5 host is enrolled in NXLog Platform, it can be managed alongside other agents in the environment.
This central management model can help reduce the operational burden associated with legacy infrastructure. Instead of repeatedly connecting to individual servers through SSH, administrators can use centralized management to monitor and configure agents across the fleet.
From the central platform, teams can:
- Monitor agent status and connectivity.
- Review event activity and performance information.
- Deploy logging configurations remotely.
- Apply consistent collection policies across multiple operating systems.
- Manage legacy systems alongside current Windows and Linux endpoints.
The result is that the operating system version becomes an implementation detail rather than a reason for excluding the system from centralized visibility.
Closing the Logging Gap on Legacy Infrastructure
Legacy systems can create significant challenges for security operations. They may be difficult to patch, isolated from the rest of the infrastructure, dependent on outdated applications, or subject to strict change-control procedures. None of these factors eliminates the need to monitor them.
Compliance Coverage
Regulatory and internal security requirements generally do not disappear simply because a server runs an older operating system. Centralized log collection helps organizations maintain the evidence required for security monitoring, incident investigation, and compliance processes.
Security Visibility
Systems that cannot be regularly upgraded can represent an increased security risk. Logs provide an important source of evidence for identifying configuration changes, authentication activity, system errors, and suspicious behavior.
A Single Telemetry Pipeline
Supporting legacy operating systems through the same logging platform can reduce dependence on custom scripts, isolated collectors, and manually maintained forwarding mechanisms.
Legacy Systems and Modern Security Operations
Modern SOC teams increasingly depend on centralized telemetry to detect threats and investigate incidents. Leaving older systems outside the logging architecture creates a visibility gap that can affect the entire security monitoring process.
NXLog Agent 6.15 helps address this problem by extending centralized log collection to RHEL 5 and CentOS 5 environments. Organizations can continue operating systems that cannot yet be upgraded while still integrating their logs into a modern security monitoring architecture.
| Challenge | Traditional Approach | NXLog Agent 6.15 Approach |
|---|---|---|
| Legacy OS support | Custom scripts or unsupported agents | Official NXLog Agent support |
| Log collection | Separate collectors and relays | NXLog Agent |
| Configuration | Manually maintained configurations | Centralized NXLog configuration |
| Security monitoring | Potential visibility gaps | Integration with centralized SIEM and logging infrastructure |
| Fleet management | Individual host administration | Central management through NXLog Platform |
Conclusion
Legacy operating systems are not necessarily temporary problems. In manufacturing, energy, government, healthcare, and other regulated environments, some systems may remain operational for years because upgrading them is technically, financially, or operationally impractical.
That should not mean accepting a permanent logging blind spot.
With NXLog Agent 6.15, organizations can bring RHEL 5 and CentOS 5 systems into the same centralized logging architecture as modern infrastructure. Logs can be collected locally, processed and forwarded to the required destinations, while NXLog Platform provides centralized visibility and management.
As an official NXLog distributor, Softprom can help organizations evaluate NXLog Agent and NXLog Platform for environments that combine modern infrastructure with legacy and hard-to-upgrade systems.