TroutTrout

Filter logs at the edge with 3 to 13x less CPU.

Trout Impeller processes logs at the edge, so your SIEM ingests less. Its image is 91% smaller than Logstash, so it runs where Logstash cannot. HUN-REN SZTAKI validated the results independently.

Last updated:

The problem

Filtering at the edge keeps SIEM costs down.

Every device you add makes your SIEM cost more to run, store and process. In OT environments, thousands of machines send syslog at high rates, so the cost climbs fast.

Impeller parses, filters and pre-processes logs at the edge. Less data, and simpler data, reaches your central systems. It runs where Logstash is too heavy: edge gateways, remote OT plants, containerized microservices and small appliances.

Test architecture

The test compared both tools head to head.

The test environment simulated a realistic distributed pipeline using Docker containers orchestrated via Docker Compose. Loggen generated realistic syslog traffic at controlled rates to progressively increase load. Both Impeller and Logstash ran equivalent processing pipelines. A rsyslog sink received and discarded processed events, which isolated pipeline performance from storage effects.

Tests systematically varied three parameters: operation mode (forward-all vs. parsing & filtering), load volume (5,000 to 25,000 events/s), and resource allocation (small: 0.5 CPU core, 500MB RAM vs. large: 4 CPU cores, 4GB RAM). Each scenario included JVM warm-up and pipeline flush phases to ensure accurate measurement.

Performance results

Independent assessment by HUN-REN SZTAKI, January 2026. EU SOCCER Project, Grant #101127847.

Image size91% smaller
Impeller80 MB
Logstash890 MB
Startup time4–19× faster
Impeller2 seconds
Logstash8–39 seconds
CPU time per event3–13× lower
Impeller0.06–0.13 ms
Logstash0.43–1.73 ms

Impeller used fewer resources than Logstash in all 8 test scenarios. The 91% reduction in image size (80MB vs. 890MB) makes it deployable in edge and OT environments where storage is limited. CPU consumption was 3-13x lower than Logstash, with filtering operations at 0.06-0.13ms per event compared to Logstash's 0.43-1.73ms. In practice, this means lower infrastructure costs and less load on the systems being monitored.

Footprint

The 80 MB image fits on edge devices.

91% smaller than Logstash. Deploys on edge gateways, OT appliances, and resource-constrained environments where traditional log processors can't fit.

Speed

It starts in 2 seconds.

4-19x faster startup than Logstash (which needs 8-39 seconds). Important for containerized environments, auto-scaling, and edge deployments where services restart often.

Efficiency

It uses 3–13× less CPU per event.

0.06-0.13 ms per event vs. Logstash's 0.43-1.73 ms. Lower infrastructure costs and less load on the systems being monitored.

Full report

Download the validation report.

The complete independent assessment by HUN-REN SZTAKI: methodology, all 8 test scenarios, detailed results, event handling analysis, and deployment recommendations.

Done

Impeller ships inside Access Gate.

Impeller is the event processing engine inside Trout Access Gate. Every Access Gate deployment includes Impeller for edge-level log filtering, parsing, and SIEM forwarding. No additional setup required.

Learn about Access Gate

The test ran within the EU SOCCER project.

This assessment was conducted as part of the EU-funded SOCCER project (Grant #101127847) by HUN-REN SZTAKI, Department of Network Security and Internet Technologies. Report date: January 2026.

Questions

Common questions about Impeller and the report.

91%

Smaller image footprint vs. Logstash

Impeller is Trout Software's edge log processing engine. It parses, filters and pre-processes log data at the source, before it reaches your SIEM. Less data, and simpler data, goes to your central systems.

The independent performance assessment was conducted by HUN-REN SZTAKI (Institute for Computer Science and Control), Department of Network Security and Internet Technologies, as part of the EU-funded SOCCER Project (Grant Agreement #101127847). Report date: January 2026.

Eight test scenarios evaluated Impeller across varying workloads and resource constraints, comparing it directly against Logstash as the industry-standard baseline. Tests varied operation mode (forward-all vs. parsing & filtering), load volume (5,000 to 25,000 events/s), and resource allocation (0.5 to 4 CPU cores, 500MB to 4GB RAM). The test environment simulated a realistic distributed pipeline using Docker containers orchestrated via Docker Compose.

No. Impeller sits upstream of your SIEM. It reduces the volume of data your SIEM needs to ingest by filtering and enriching logs at the edge. This lowers SIEM licensing costs, storage requirements, and processing overhead. Impeller integrates via standard rsyslog forwarding.

Impeller uses a queue-based processing model that acts as a built-in protection mechanism. When processing capacity is exceeded, the queue absorbs bursts up to its limit. Past that limit, overflow caps the impact of misconfigured or compromised devices that flood the pipeline with logs. That keeps one noisy device from taking down your log pipeline. For production deployment, HUN-REN SZTAKI recommends implementing TCP-based backpressure to provide flow control.