TrustRadius: an HG Insights company

Graylog

Score8.8 out of 10

33 Reviews and Ratings

What is Graylog?

Graylog, headquartered in Houston, offers their eponymous platform for centralized log management that helps users find meaning in data faster so as to take action immediately. Graylog is available via Enterprise and Cloud plans, but also has a Small Business Plan, and an Open (free) plan with limited features.

Graylog is the one console you must have

Use Cases and Deployment Scope

We use Graylog to centralize and organize log data from our many applications running in our environment. Applications running in different operational systems and technologies can be very tricky to analyze their behavior, and that's where Graylog comes with its magic! We built fully functional and customizable dashboards, which makes our job easier, and fast to find, accurate, and act on several bad working applications in our environment.

Pros

  • Very fast process of hugh amounts of information
  • Easy to built dashboards with rich visual display
  • Intuitive filter string auto-complete
  • Alerts based on differents scenarios and triggers

Cons

  • Native plugins for more windows applications
  • Alerts integrations with third part applications
  • Cluster an high availability management

Return on Investment

  • Positive: easy to deploy
  • Positive: rich data display in graphs and big numbers
  • Negative: uses a lot of disk space

Usability

Alternatives Considered

Prometheus, Grafana and Zabbix

Other Software Used

NGINX, Portainer, Grafana, Zabbix, SolarWinds Pingdom, SolarWinds Serv-U, Hyper-V

An invaluable tool to collect store and search logs

Use Cases and Deployment Scope

We are an ecommerce agency and, with multiple clients and multiple environments per client, having a centralized platform to collect log makes our life a lot easier. Instead of waiting for a developer or devops worker to check for issues, project managers can check the log themselves and then forward tasks quickly.

Pros

  • Log collection
  • Storage management
  • Log statistics

Cons

  • Configuration can be hard to understand
  • More quickly and easy ways to search for data
  • Auto-categorization of log entries would be excellent

Return on Investment

  • Saves time of devops personal
  • Allow quickier response time on issues
  • More precise task attribution by project managers

Usability

Alternatives Considered

blackfire.io and Sentry

Other Software Used

blackfire.io, New Relic, Termius

Graylog can compete against the big boys.

Pros

  • Log Aggregation pipeline
  • Dashboards

Cons

  • Pricing for Enterprise is a bit unrealistic.
  • Archiving should be a standard feature in the community edition.

Return on Investment

  • Full return on investment for the free version.
  • Paid features aren't fully justifiable at the enterprise cost.

Alternatives Considered

IBM QRadar, Splunk Enterprise Security, AlienVault OSSIM and AlienVault USM

Other Software Used

Palo Alto Networks Next-Generation Firewalls - PA Series, Palo Alto Networks GlobalProtect Mobile Security Manager, Palo Alto Networks URL Filtering PAN-DB

Useful and free SIEM tool

Use Cases and Deployment Scope

Allows insight into logs from various systems and products that would otherwise be time consuming to access and identify. Dashboards can be customised to your preferences and Alerts/emails can be defined when specific events or patterns occur, which is not possible directly from the log source. Our use case is primarily security related looking at access/sign-in logs from various platforms and then sending alerts as required.

Pros

  • Ingesting various log sources
  • Dashboards - Customisable
  • Event alerts/emails

Cons

  • Support for more log sources
  • Event alerts/emails - Some cases where unable to separate data from multiple clients, and no easy fix
  • API - Limits results to 10,000 and can cause server to lockup on queries that exceed the limit

Most Important Features

  • Multiple log sources
  • Customisable Dashboards
  • Event alerts/emails

Return on Investment

  • Able to offer monitoring services to new and existing clients to increase revenue
  • Staff have increased billing percentage
  • Potential to expand security services

Other Software Used

M‑Files, Microsoft Azure Active Directory, Windows Server

Clean, robust and intuitive central logging

Use Cases and Deployment Scope

We have more than 60 applications, ranging from websites, Winforms, windows services, API's and console executables. All of them need to log their tracing and/or error information to a central location. It needs to be central because you don't want to search for this location, especially when you only have 5 minutes to solve a problem. We used to have a dedicated database for logging, but this does not eliminate the time lost searching for "the" logs. Also, [the] configuration used to be a manual and self-made business that wasn't always clear. Graylog is a dedicated logging solution that comes "out of the box" and is made accessible through a well-known plugin architecture (log4net if you're developing with the .NET framework).

Pros

  • Nice search interface and powerful search options
  • JSON extractor to "extract" variables and values from JSON input.
  • Clear and intuitive dashboards

Cons

  • In the front end, the search "tricks" could have been made a little easier to find. There seems to be some kind of "search language" where you can use keywords like "AND" and "OR," etc. (much like SQL language). But it's totally unclear what does work and what doesn't. If you don't know that it's there, you'll never find it. Of course, after you do know it, you can find many examples online on how to use it.
  • The backend is not for the inexperienced. Graylog is based on elastic search and MongoDB. And it's Linux. This means that Graylog is actually 3 applications that you need to configure in a Linux environment. This means that you need quite some experience to get this running. Fortunately, though, things are kept as simple as possible. What I mean is that at first, the task seems daunting, but then you'll find that there's not much to it after all.
  • We've had multiple occasions that disk size was full or indexes went larger than allowed. When this happens, the systems can become corrupt. The solution is to just delete the indexes, but it took quite some time to find this out.
  • We disabled "Automatic updates" on the Linux server because unattended updates always lead to problems. This is not a real problem, or solely related to Graylog, but worth mentioning. Updates are best handled manually.

Most Important Features

  • Central (the fact that it's central), one place to log them all
  • Multiple ways to log, one I already mentioned (log4net)
  • AD support
  • The fact that it's free

Return on Investment

  • Negative: None. There is no negative impact by using Graylog.
  • Speed of solving bugs. Logging is so accessible and easy to search that we spend a lot less time [searching] for specific errors.
  • Better health of applications. Since monitoring the logs is so easy, it's very easy to keep an eye on the tracing to see if things are going smoothly and according to plan.

Alternatives Considered

Azure Monitor

Other Software Used

Azure API Management, Azure Blob Storage, Azure Data Factory