Skip to main content
TrustRadius
Graylog

Graylog

Overview

What is Graylog?

Graylog, headquartered in Houston, offers their eponymous platform for centralized log management that helps users find meaning in data faster so as to take action immediately. Graylog is available via Enterprise and Cloud plans, but also has a Small Business…

Read more
Recent Reviews

TrustRadius Insights

Graylog has proven to be a valuable solution for users in various industries, offering a range of use cases that address common challenges …
Continue reading

Graylog, Free Vs. Paid

9 out of 10
April 29, 2020
Incentivized
Graylog is currently implemented for use across the entire organization at each deployment that I have provisioned. However, Graylog is …
Continue reading

Level Up Your Logging

7 out of 10
June 30, 2019
Incentivized
Graylog is used to aggregate logs and SNMP traps from our network devices and Linux servers. We not only aggregate and store logs but …
Continue reading

Graylog is GREAT

9 out of 10
December 05, 2018
Incentivized
We use Graylog to view all of our system logs in one place. We use this software to back up our logs so in the event we need to review …
Continue reading
Read all reviews
Return to navigation

Product Demos

Demo GrayLog 2 with Laravel5 app

YouTube

Demo GrayLog 2 with Rails app

YouTube

Send Syslog from MuleSoft RTF to GrayLog

YouTube

Graylog Security

YouTube
Return to navigation

Product Details

What is Graylog?

Graylog Video

Tour of Graylog v4.0

Graylog Technical Details

Deployment TypesOn-premise, Software as a Service (SaaS), Cloud, or Web-Based
Operating SystemsWindows, Linux, ,
Mobile ApplicationNo

Frequently Asked Questions

Graylog, headquartered in Houston, offers their eponymous platform for centralized log management that helps users find meaning in data faster so as to take action immediately. Graylog is available via Enterprise and Cloud plans, but also has a Small Business Plan, and an Open (free) plan with limited features.

Splunk Enterprise, Datadog, and Logz.io are common alternatives for Graylog.

Reviewers rate Support Rating highest, with a score of 3.6.

The most common users of Graylog are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(29)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Graylog has proven to be a valuable solution for users in various industries, offering a range of use cases that address common challenges in log management and security monitoring. Users have successfully utilized Graylog as a centralized log aggregator and SEIM, enabling them to collect logs from multiple applications and sources in one central location. This has greatly simplified the process of tracking and tracing errors, saving valuable time when troubleshooting problems across their systems.

With Graylog's well-known plugin architecture, such as log4net for .NET developers, users have found it easy to integrate and utilize the platform. Additionally, Graylog's ability to extract values from logs and customize dashboards has enhanced its usability and provided users with greater searchability. By defining alerts for specific events or patterns, they are able to promptly identify and address potential issues.

Another significant use case for Graylog is its value in security-related tasks. Users have successfully employed Graylog to analyze access sign-in logs from various platforms and receive alerts when necessary. Additionally, its capability to collect messages from network devices like switches, routers, and wifi controllers has allowed users to group and visualize important information through graphs. This feature has proven particularly useful for monitoring critical events and ensuring prompt action.

The cost-effectiveness of Graylog combined with its customization options has contributed to its widespread adoption within organizations. Users across different teams are able to tailor the platform to their specific needs, making it a valuable tool for both log management and security monitoring purposes. From capturing NAT translations for DMCA-related notifications to serving as an internal syslog server, Graylog provides an efficient and accessible solution for aggregating logs and organizing them in a searchable manner.

Efficient log aggregation and intuitive dashboards: Multiple reviewers have praised Graylog for its efficient log aggregation pipeline, allowing users to easily collect and analyze logs from various sources. The clear and intuitive dashboards provided by Graylog were also highlighted as a positive aspect, making it easier for users to understand and monitor their logs effectively.

Powerful search options: Many reviewers have appreciated the powerful search capabilities offered by Graylog. Users mentioned that they can quickly search through large volumes of logs and easily find specific data without manual filtering. This feature enhances efficiency and saves time for users when troubleshooting or investigating issues.

Flexible configuration options: Users have commended Graylog for its flexibility in configuration. Some reviewers mentioned the ability to store everything on a single box, while others highlighted the option to scale out horizontally using a cluster of Elasticsearch nodes and MongoDB servers. This flexibility allows users to tailor their log management setup according to their specific needs and infrastructure requirements.

Unrealistic Pricing: Some users have expressed dissatisfaction with the pricing of the Enterprise version, considering it unrealistic for their needs.

Lack of Intuitive Configuration: Several reviewers have mentioned that configuring Graylog's backend, which relies on Elasticsearch and MongoDB, can be challenging for inexperienced users. It requires Linux knowledge and configuring three separate applications.

Difficulties in Log Management: Users have encountered difficulties in rotating indexes and managing log retention. They feel that there is no built-in feature to auto-delete logs or accurately estimate storage space needed, making log management a challenging task.

Users highly recommend Graylog for its efficiency in collecting information and managing records, emphasizing that it is suitable for any department and helps save time and increase productivity. It is particularly recommended for organizations dealing with large amounts of data.

Graylog is praised for fulfilling users' expectations at a low price point. It offers many useful features, making it a highly recommended logging and monitoring tool. Users find it easy to access and install, making it one of the best tools for log analysis and understanding product details at runtime.

Graylog is considered a good software for collecting records and analyzing data efficiently. It is particularly recommended for companies looking to monitor threats and analyze data effectively. Users appreciate its high functionality, optimal performance, and ability to handle large amounts of different data. Moreover, it generates confidence in its users while offering an economical price for its services.

Overall, users recommend carefully evaluating data requirements, having a solid understanding of Linux and the basics of MongoDB and Elasticsearch before using Graylog, as well as configuring a retention profile to avoid storage issues. It is also advised to research the competition before deciding on a logging solution and consider the deployment and system requirements before using Graylog.

Attribute Ratings

Reviews

(1-3 of 3)
Companies can't remove reviews or game the system. Here's why
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Graylog is currently implemented for use across the entire organization at each deployment that I have provisioned. However, Graylog is only referenced by myself, or Information Systems Staff. Graylog currently mainly addresses two separate needs for us. First, it allows the capture of NAT translations for DMCA related notifications for subscribers. Secondly, it addresses the need for an internal syslog server.
  • The free edition is extraordinarily powerful.
  • Log searching is quick.
  • The web interface is sleek, and the install is relatively quick.
  • Rotating the indexes are hard! It is also easy to brick your deployment. Purchase support, but it's so ludicrously expensive, that I'd go with a different vendor.
  • Community support dances around questions and points to documentation, which is there, but is not always accurate.
  • Searching logs uses logic that is not always easy to use.
  • There is not a good way to size how much space you need for a given log retention. It also does not tolerate running out of space using a smart feature or such to auto delete. The heap can also overflow.
  • It uses MangoDB instead of a different database.
  • The OVA is not approved for production use.
  • It is resource intensive.
If you just need a logging server that will most likely work, and won't break the bank. This is it, you can stop looking. Period.
  • Graylog has allowed our clients to successfully log NAT translations and comply with the DMCA, protecting us in terms of Safe Harbor.
  • Graylog allows us to have a central server for syslog, which saves time rather than checking each machine, or figuring out events if we experience a unresponsive failure, lowering downtime.
  • We have also spent a lot of time learning Graylog, which was a considerable investment. However, it is now starting to pay its dividends.
We use the free edition, because it is free and open source. We evaluated numerous other products, but we decided to go down the Graylog track because of initial costs. While the competition (Splunk, AlienVault, etc.) are very good products and come highly recommended, it simply was not in the budget to choose one of those products at this time. I have many clients who have used both, and decided to go with AlienVault, however.
Community support does not give simple straightforward answers; simply search up Graylog Issues and look at some of the responses on the forums. The documentation is your only hope if you are on the free version, as you can NOT purchase only support. The few times I have worked with Graylog Enterprise support they were great though.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We currently use Graylog as a log aggregator and some light weight SEIM. However, we haven't had the cycles to use the other features of it. Presently solves our centralized log collection problem.
  • Log Aggregation pipeline
  • Dashboards
  • Pricing for Enterprise is a bit unrealistic.
  • Archiving should be a standard feature in the community edition.
Graylog is suited for all environments. Its easy setup and use is great for small businesses. Its flexibility for configuration of ingested logs is excellent for medium to large scale, and its ingest capability is great for super-sized. One size fits all for Graylog. It's a great competitor to QRadar and Splunk, and even AlienVault USM/OSSIM
  • Full return on investment for the free version.
  • Paid features aren't fully justifiable at the enterprise cost.
In terms of log aggregation, the free product fully stacks up with the competitors listed. Full control over the data ingests for flexible configuration. Graylog even better on that front than AlienVault USM because you cannot configure the variable mapping. We haven't used the threat exchange stuff or correlation. But with regex searches, we have created function dashboards that show threat theater pictures of our network based on logs from our firewall.
From a product perspective, it's an 8.
I am still unhappy with the pricing model for the enterprise. Graylog competes against the likes of IBM and Splunk, but your still the new kid on the block. To price Graylog enterprise at 50k for 20GB ingest an unrealistic data. It would require multiple facets of Graylog to be stood up and only forward pruned logs to the paid version.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use Graylog to collect messages from a variety of different systems like network switch and routers to wifi controllers. We use Graylog to group and create graphs to show specific information. We also use Graylog to send messages to us to alert of certain activities. Graylog is widely used in our office because it is cost-effective and the ability to be tweak for each team.
  • The ability to add and remove information to the messages. This makes it so you can customize each message and get the information you really want.
  • Being able to search for different criteria allows finding the exact data you want without having to manually filter the data.
  • Searching tends to be quick and is able to process large amounts of data quickly so you don't have to wait forever for your data.
  • The graphs and visualizations are limited on the dashboard if there were more options it would be better for different kinds of data.
Graylog can collect messages and group them, so if you want to get alerted when there is an abnormal amount of particular messages, Graylog can do that. Graylog can be used to analyze traffic, and if traffic over a certain level and is sustained for an amount of time, it can send the information of which mac addresses are causing the traffic influx.
  • Graylog is just less expensive than some other options which meant it fit into our budget otherwise we might not be able to justify a higher cost.
  • Being able to track issues that we normally couldn't track using other tools is a bonus to help us know of any issues we have and can fix before an outage or failure that could potentially cost money.
  • We have had to spend more time than I would like to understand and customize Graylog which has taken time away from other tasks and projects.
Graylog does what other similar products that cost more do, but the more expansive one typically has more features or are multiple products wrapped in one. We went with Graylog because it does everything we need it too, and the price was less than other and fit into our budget. If cost were not an issue, I would probably go with a product that had more features and could do more just in case we might use them in the future.
They have good online documentation. I haven't had to use their support much, which is a good thing I would assume since most everything they do is the standard way to do it. When I have used their support is was the online documentation; it seems to be well supported by Graylog and the community. Every issue I had, I was able to resolve using their documentation or the forums with questions on their website.
Return to navigation