Skip to content
ShieldLensProan Elevian.io product
operational/v2.4.0 · build a8e1c4
firewall telemetry platform

Mission control for your firewall infrastructure.

Real-time telemetry, threat intelligence and compliance evidence across 18 firewall vendors — from a single self-hosted platform. No cloud. No per-device fees.

DEPLOYMENTself-hosted · air-gap capable
DATA RESIDENCY100% on your hardware
TIME TO VALUE≤ 60 seconds
VENDORS · 18FortiGate · Palo Alto · Sophos · Cisco FTD · Juniper SRX · Check Point · +12
shieldlens / operations
LIVE
Packets / sec
12,847
Bandwidth Mbps
782
Blocked / 5m
421
Threat score
94.7

Live attack origins

last 60 min · global
21 sources
CRITHIGHMED

Live event stream

all firewalls
10 / sec
15:42:08CRITFortiGate-200F 185.234.x.x · SSH brute-force · 42 attempts
15:42:05HIGHPalo Alto PA-440 App-ID:web-browsing · port-scan DNAT 7660
15:41:57MEDSophos XGS 3100 198.51.100.4 · RDP probe from BR · blocked
15:41:42INFOCisco FTD FPR-2110 AccessControlRule reload · Ecom team
15:41:31HIGHCheck Point Q6200 IPS sig 4501022 · SQLi attempt on /admin
15:41:18OKHuawei USG6610E Heartbeat · uptime 71d 04h
15:41:02MEDJuniper SRX340 91.214.x.x · suspicious geo IR → :3389
15:40:48CRITF5 BIG-IP i4800 APM auth fail burst · 12 users locked
15:40:31HIGHBarracuda F800 CVE-2024-4577 PHP probe · 104.21.x.x
15:40:14INFOshieldlens PCI-DSS daily report generated
15:42:08CRITFortiGate-200F 185.234.x.x · SSH brute-force · 42 attempts
15:42:05HIGHPalo Alto PA-440 App-ID:web-browsing · port-scan DNAT 7660
15:41:57MEDSophos XGS 3100 198.51.100.4 · RDP probe from BR · blocked
15:41:42INFOCisco FTD FPR-2110 AccessControlRule reload · Ecom team
15:41:31HIGHCheck Point Q6200 IPS sig 4501022 · SQLi attempt on /admin
15:41:18OKHuawei USG6610E Heartbeat · uptime 71d 04h
15:41:02MEDJuniper SRX340 91.214.x.x · suspicious geo IR → :3389
15:40:48CRITF5 BIG-IP i4800 APM auth fail burst · 12 users locked
15:40:31HIGHBarracuda F800 CVE-2024-4577 PHP probe · 104.21.x.x
15:40:14INFOshieldlens PCI-DSS daily report generated

Events by severity

last 24h
4,983
Critical12
High47
Medium184
Low612
Info4,128

Connected firewalls

8 vendors · 16 devices
16 ONLINE
FortiGate-200F4
4,128 rps
Palo Alto PA-4402
2,147 rps
Sophos XGS 31002
1,924 rps
Cisco FTD FPR-21101
1,681 rps
Huawei USG6610E2
1,842 rps
Check Point Q62001
314 rps
F5 BIG-IP i48001
892 rps
MikroTik CCR20043
1,247 rps
● syslog 1514
telemetry · live
OKFortiGate-200F · heartbeat · uptime 71d 04hCRITPalo Alto PA-440 · 185.234.x.x · SSH brute-force · 42 hitsHIGHSophos XGS 3100 · IPS sig 51422 · SQLi on /adminINFOshieldlens · PCI-DSS 4.0 daily report generatedMEDCisco FTD FPR-2110 · port-scan DNAT 7660 from CNOK16 firewalls online · 8 vendors · 0 collectorsHIGHHuawei USG6610E · 45.143.x.x · CVE-2024-4577 PHP probeCRITCheck Point Quantum 6200 ↔ Juniper SRX · VPN tunnel downINFOF5 BIG-IP i4800 · APM session opened · fatima.kMEDMikroTik CCR2004 · L2TP auth burst from BROKWatchGuard Firebox M390 · App Control rule reloadINFOBarracuda CloudGen · syslog stream resumedOKFortiGate-200F · heartbeat · uptime 71d 04hCRITPalo Alto PA-440 · 185.234.x.x · SSH brute-force · 42 hitsHIGHSophos XGS 3100 · IPS sig 51422 · SQLi on /adminINFOshieldlens · PCI-DSS 4.0 daily report generatedMEDCisco FTD FPR-2110 · port-scan DNAT 7660 from CNOK16 firewalls online · 8 vendors · 0 collectorsHIGHHuawei USG6610E · 45.143.x.x · CVE-2024-4577 PHP probeCRITCheck Point Quantum 6200 ↔ Juniper SRX · VPN tunnel downINFOF5 BIG-IP i4800 · APM session opened · fatima.kMEDMikroTik CCR2004 · L2TP auth burst from BROKWatchGuard Firebox M390 · App Control rule reloadINFOBarracuda CloudGen · syslog stream resumed
18

Firewall vendors

auto-detected

9

Compliance frameworks

built-in PDFs

240+

API endpoints

full REST

60s

Time to first dashboard

from install

> market_reality

The firewall analytics market is broken.

Every existing tool forces you to pick a poison: expensive, cloud-locked, or single-vendor. We built ShieldLens because that tradeoff shouldn't exist.

> the_competition

What everyone else makes you accept

  • Cost $395+ per device per year

    ManageEngine Firewall Analyzer

  • Lock you into the cloud

    Cisco Umbrella, Cato Networks

  • Only support one vendor's firewall

    FortiAnalyzer, Panorama

  • Take days of setup and tuning

    Splunk, Graylog

> shieldlens_pro

How we do it differently

  • $99–$1,200 per year — not per device

  • Runs 100% offline on your own server

  • Auto-detects 18 different firewall brands

  • Live dashboard in 60 seconds of pointing syslog

> capabilities

Six capabilities. Each one a category killer.

No 47-tab dashboard. No bloated suite. Every screen earns its place by answering a question a network or security engineer actually asks.

01 / fleet

One platform. 18 firewall vendors. Auto-detected from the first packet.

Mix FortiGate, Palo Alto, Cisco ASA/FTD, Sophos, SonicWall, Check Point, Juniper, MikroTik, WatchGuard, Barracuda, Huawei, Zyxel, F5 — and 5 more — on one syslog port. ShieldLens fingerprints the wire format and reshapes the dashboard to that vendor's capabilities.

  • Auto-detect on the first log line — no per-vendor collector
  • Per-device dashboards adapt to vendor capability
  • Mixed-vendor MSSP / multi-tenant rollup
  • Single UDP/TCP port (1514) for everything
fleet · all 18 vendors supported13 ACTIVE
FortiGate4
Palo Alto2
Sophos2
Cisco FTD1
Cisco ASA2
Huawei USG2
Check Point1
Juniper SRX1
SonicWall1
MikroTik3
F5 BIG-IP1
Barracuda1
WatchGuard1
Zyxel
Meraki
pfSense
OPNsense
Ubiquiti
02 / context

Raw policy IDs become readable names. Across every panel.

Upload your running config and watch cryptic IDs — policy 8847, port12, addr_grp_44 — turn into 'Ecom team internet', 'WAN-PrimaryISP', 'Branch VLANs' on every chart, report and log line in the platform.

  • Resolves policy IDs, interface aliases, NAT pools, address objects
  • Reload-on-change · no service restart
  • Built-in parsers for FortiGate, PAN-OS, IOS, Sophos
  • One-click context drawer on every event
context engine · resolutionsLIVE
policy_id: 8847Internet access (Ecom team)
iface: port12WAN-PrimaryISP
addr_grp_44Branch VLAN — Karachi-DC
nat_pool_3Outbound NAT (Sales)
policy_id: 9120DC → Branch site-to-site VPN
03 / exposure

Discover every NAT, VIP and DNAT your perimeter exposes.

Continuously inventories every inbound rule across every connected firewall. See which IPs are scanning your exposed services, from where, and how often — without writing a single query.

  • Auto-discovered services list — across all firewalls
  • Per-service geo-attack heatmap
  • Suspicious-country / suspicious-port correlations
  • Zero configuration — finds them all
published services · exposure map21 SOURCES
serviceportnameriskorigins
203.0.113.18:7660DASHCAM-194CN, RU, IR
198.51.100.4:3389RDP-bastion67BR
192.0.2.10:443ecom-web22global
203.0.113.42:22ops-jump81US, NL, IN
04 / response

Risk-scored attackers. One-click block-list export.

Aggregates every attack source into a deduplicated, risk-scored list. Acknowledge a threat once and it stops screaming — delta tracking surfaces only new attackers since your last login.

  • Risk score combines volume, severity, geo and target
  • One-click export to FortiGate / PAN / ASA block-lists
  • Acknowledge + comment trail for SOC handoff
  • Delta view — only NEW threats since last shift
smart block list · risk-scored2 NEW
185.234.x.x94412
NEW
203.0.113.1888287
NEW
45.143.x.x76154
ACK
91.214.x.x6192
ACK
export readyFORTIGATE · PAN · ASA
05 / compliance

PCI, ISO, SOC 2, HIPAA, GDPR, NIST, CIS, NIS 2 — built-in.

Audit-ready PDFs in a single click. Every finding ships with vendor-specific hardening steps so your team has a remediation playbook the moment your auditor flags an issue.

  • PCI-DSS 4.0 firewall control mapping (Req 1, 10, 11)
  • ISO 27001:2022 Annex A.13 evidence pack
  • SOC 2 CC6.6 + CC7.2 monitoring artifacts
  • Branded cover page with your logo + auditor name
compliance · 9 frameworks readyPDF · 1-CLICK
PCI-DSS 4.0
Req 1, 10, 11
PASS
ISO 27001:2022
Annex A.13
PASS
SOC 2
CC6.6, CC7.2
PASS
HIPAA
§164.312(b)
PASS
GDPR Art. 32
Security of processing
PASS
NIST CSF 2.0
PR, DE.CM
PASS
CIS Controls v8
13.x firewall
PASS
NIS 2
Art. 21 measures
PASS
06 / sovereignty

Air-gap deployable. No telemetry. No license phone-home.

Every component runs inside your perimeter. License keys are validated locally. Updates ship as offline-signed bundles. Verify the no-outbound-calls promise with tcpdump — we encourage it.

  • No outbound network calls of any kind
  • Offline-signed license validation
  • Updates delivered as signed .pkg / .exe bundles
  • Verified by tcpdump — we publish the command
$ tcpdump -i any host shieldlens.local0 OUT

root@host:~# tcpdump -i any host shieldlens.local

tcpdump: verbose output suppressed, listening on any, link-type LINUX_SLL

14:01:00.123 IP 10.20.3.1.51422 > shieldlens.1514: UDP, length 412

14:01:00.215 IP 10.20.4.1.51422 > shieldlens.1514: UDP, length 388

14:01:00.302 IP 10.20.3.4.51422 > shieldlens.1514: UDP, length 504

^C 0 outbound packets · 0 connections initiated by shieldlens

VERIFIEDno telemetry · no phone-home · no surprises

> deployment

Four commands. One minute. No agents.

No collectors. No vendor SDKs. No services to provision. Just syslog — the protocol every firewall already speaks.

step 01

Install

shieldlens.exe on Windows, pip wheel on Linux, or our Docker image.

$ pip install shieldlens-pro
step 02

Point syslog

Send every firewall's syslog to <your-ip>:1514 — one port for all.

fw # config log syslogd setting → server <ip> port 1514
step 03

Auto-detect

ShieldLens fingerprints the vendor in under a second.

✓ FortiGate-200F · ✓ PA-440 · ✓ USG6610E
step 04

Operate

Open your browser. The console is already populated.

→ http://localhost:8080 — live in 58s
shieldlens · deploy log
LIVE IN 58s

$ shieldlens start

[15:42:01] listening on UDP/TCP 1514 · web on :8080

[15:42:08] packet from 10.20.3.1FortiGate-200F detected

[15:42:09] packet from 10.20.3.4Palo Alto PA-440 detected

[15:42:10] packet from 10.20.3.7Sophos XGS 3100 detected

[15:42:11] packet from 10.20.4.1Huawei USG6610E detected

[15:42:12] packet from 10.20.4.5Cisco FTD FPR-2110 detected

[15:42:14] packet from 10.20.5.1Check Point Quantum 6200 detected

[15:42:15] packet from 10.20.5.8F5 BIG-IP i4800 detected

[15:42:17] packet from 10.20.6.1MikroTik CCR2004 detected

[15:42:58] dashboard live → http://localhost:8080 ✓

> adaptive_console

One platform. Reshapes itself per vendor.

ShieldLens reads each vendor's capability matrix and rebuilds the console accordingly — so you always see meaningful telemetry, never a "no data" tile. Pick a vendor below to see exactly which fields ShieldLens surfaces.

shieldlens · FortiGate
FortiOS 7.4 · FortiGate-200F

Top users (FSSO)

ahmed.r · sales-laptop-04 · fatima.k

UTM events

1,284 IPS · 412 AV · 88 web filter

App-ID hits

youtube · github · sap.s4hana · zoom

Bandwidth

782 Mbps avg · 1.2 Gbps peak

Active sessions

14,210 · 2.1M today

Health (logid 40704)

CPU 28% · Mem 41% · Disk 22%

> vendor_matrix

All 18 vendors. Every capability. One parser stack.

ShieldLens ingests syslog from every major firewall on the market — and tells you exactly which fields it gets from each one. No marketing fluff. Hover any cell to see the parse rule.

capabilities · 18 of 18 vendors
fullpartialnone
vendortierformatAPPUSERBYTESVPNDHCPRULEHEALTH
Fortinet FortiGate
FortiGate-200F
T1key=value · CEF
Palo Alto Networks
PA-440
T1CSV · CEF · LEEF
Sophos XG / XGS
XGS 3100
T1key=value
Cisco Firepower / FTD
FPR-2110
T1Cisco · key=value
Juniper SRX
SRX340
T1BSD · RFC 5424 structured
Check Point
Quantum 6200
T2Syslog · CEF · LEEF · JSON
SonicWall
TZ670
T2Enhanced k=v · CEF
Huawei USG
USG6610E
T2Custom key=value
Barracuda CloudGen
F800
T2BSD syslog
Cisco ASA
ASA 5520
T2Cisco proprietary
WatchGuard Firebox
Firebox M390
T3Custom · LEEF
F5 BIG-IP
BIG-IP i4800
T3BSD · HSL k=v · CEF
Zyxel USG / ATP
USG FLEX 500
T3VRPT · CEF
MikroTik RouterOS
CCR2004
T3BSD · CEF (7.18+)
Cisco Meraki MX
MX85
T4Custom space-delim
pfSense
pfSense+ on Netgate 6100
T4filterlog CSV · BSD
OPNsense
OPNsense 24.x
T4filterlog CSV · BSD
Ubiquiti EdgeRouter / UniFi
UniFi UDM-Pro
T4BSD · CEF (UniFi 9+)
showing 18 vendors
T1
Tier 1 · Full NGFW
FortiGate · Palo Alto · Sophos · Cisco FTD · Juniper SRX
T2
Tier 2 · Strong
Check Point · SonicWall · Huawei USG · Barracuda · Cisco ASA
T3
Tier 3 · Limited
WatchGuard · F5 BIG-IP · Zyxel · MikroTik
T4
Tier 4 · Basic
Meraki · pfSense · OPNsense · Ubiquiti

> pricing

One annual fee. Not per device.

Pick a tier by device count. All tiers ship with every feature. Cancel any time — your install keeps working forever.

Trial

Freefor 30 days

Unlimited features

Evaluation

  • All Enterprise features unlocked
  • 30 days, no credit card needed
  • Local data — never uploaded
  • Convert to a paid tier any time
Download

Essentials

$99per year

Up to 2 devices

Single-site offices

  • All 6 core features
  • Email alerts
  • 9 compliance reports
  • Community support
Buy now
Most popular

Standard

$250per year

Up to 5 devices

Small business

  • Everything in Essentials
  • Push alerts (Pushover/Telegram)
  • Smart Context Engine
  • Published Services Intelligence
  • Email support
Buy now

Professional

$500per year

Up to 10 devices

Multi-site business

  • Everything in Standard
  • LDAP / Active Directory
  • Full REST API (240+ endpoints)
  • Multi-site rollup dashboard
  • Branded PDF reports
Buy now

Enterprise

$1,200per year

Up to 25 devices

Large organisations

  • Everything in Professional
  • MSSP multi-tenant mode
  • Priority email + WhatsApp support
  • Custom report templates
  • Hardening consultation included
Contact sales

All prices in USD. Local taxes may apply. Larger fleets? Talk to sales.

> benchmark

Stack ranked against the alternatives

Real prices. Real feature scope. Real platform limits. Every cell below is verifiable on the vendor's own site.

FeatureShieldLens ProManageEngineSplunkFortiAnalyzerGraylogSolarWinds
Price per year (10 devices)$500$3,950+$15,000+$2,400+$0 (free) / $9,000 ent.$3,495+
Multi-vendor support18 vendors10 vendorsMany (paid apps)FortiGate onlyGeneric syslog12 vendors
Runs 100% offlineYesYesYes (enterprise)YesYesYes
Per-device licensingNo (tier-based)$395/deviceBy data volumeBy deviceBy data volumeBy node
Time to first dashboard60 seconds1–2 days1+ week2–4 hours1–2 days3–5 hours
Smart Context EngineYesNoCustom buildPartialNoNo
Published Services discoveryAutoManualCustomManualNoManual
PCI-DSS 4.0 reportsBuilt-inBuilt-inPaid appPartialCustom buildBuilt-in
ISO 27001:2022 evidenceBuilt-inGenericPaid appNoCustomPartial
Smart Block List export1-clickNoCustomManualNoNo
REST API240+ endpointsLimitedFullLimitedFullYes
Air-gap deployableYesYesYesYesYesYes
Hardware footprint2 vCPU / 4 GB8 vCPU / 16 GB12 vCPU / 32 GBAppliance8 vCPU / 16 GB8 vCPU / 16 GB
MSSP multi-tenantEnterprise tierAdd-onEnterpriseLimitedOperationsAdd-on
Zero telemetryVerifiedNoNoMixedNoNo

> compliance

Audit-ready evidence, on demand.

Generate auditor-grade PDFs for nine frameworks in one click. Every finding ships with vendor-specific hardening steps, so your team has a remediation playbook the moment something gets flagged.

compliance matrix · all built-in9 / 9 READY

global

PCI-DSS 4.0

Payment Card Industry Data Security Standard v4.0

Req 1, 10, 11PDF ready

global

ISO 27001:2022

ISO/IEC Information Security Management

Annex A.13PDF ready

US

SOC 2

Service Organization Control 2 — Type II

CC6.6, CC7.2PDF ready

US

HIPAA

Health Insurance Portability and Accountability Act

§164.312(b)PDF ready

EU

GDPR Art. 32

EU General Data Protection Regulation

Security of processingPDF ready

global

NIST CSF 2.0

NIST Cybersecurity Framework 2.0

PR, DE.CMPDF ready

global

CIS Controls v8

Center for Internet Security Controls v8

13.x — FirewallsPDF ready

EU

NIS 2

EU Network and Information Security Directive 2

Art. 21PDF ready

any

Security Audit

Generic security audit report template

Custom controlsPDF ready

Air-gap deployable

Verified zero outbound calls. License keys signed locally. Run on isolated networks.

Zero telemetry

We have no idea how you use the product. There is no usage data to leak — we never collected any.

Your data, your server

SQLite or PostgreSQL — your choice. Backups are just files. No vendor lock-in. Ever.

> questions

Operator questions

Twelve questions network and security engineers ask before they install. If there's a thirteenth we haven't answered, the contact page is at the bottom.

> the_company

ShieldLens is an Elevian.io product.

Elevian.io ships self-hosted SaaS for network, security and ops engineers. ShieldLens Pro is the first of 11 products — every one of them follows the same three rules.

  • Self-hosted by default
  • Zero telemetry — verified
  • Per-tier pricing, not per-device
  • Built for engineers, by engineers
elevian.io / products2 of 11 live
01
ShieldLens Proyou are here

Self-hosted firewall analytics · 18 vendors

Live
02
TrackCost.ai

AI API cost observability for engineering teams

Live

9 more products in development

Network ops · observability · security · cost · MSP tooling — same self-hosted DNA

2026

> deploy_when_ready

Stop paying per device.
Start seeing everything.

30-day trial. No credit card. Self-hosted. Convert to a paid tier any time — your data, dashboards and reports stay exactly where you left them.

ShieldLens Pro · an Elevian.io product · self-hosted · zero telemetry · v2.4.0