ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Best Syslog Server?

    Scheduled Pinned Locked Moved IT Discussion
    12 Posts 6 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403 @Alex Sage
      last edited by

      @aaronstuder said:

      Is ELK a Syslog Server?

      http://operational.io/elk-for-network-operations/

      1 Reply Last reply Reply Quote 3
      • scottalanmillerS
        scottalanmiller @Alex Sage
        last edited by

        @aaronstuder said:

        Is ELK a Syslog Server?

        Yes, and more.

        1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          ELK and ELG (Graylog2) would be my favourites for self hosting. Splunk is great but super expensive beyond a trivially small use case. Logg.ly is awesome if you are going to pay for someone to host it for you.

          1 Reply Last reply Reply Quote 1
          • crustachioC
            crustachio
            last edited by

            I'm muddling through this myself. My week in a nutshell:

            Everyone loves ELK! I should love ELK! ELK!

            I hate ELK.

            Graylog! It's a Splunk killer! Easy! Pretty! Graylog!

            I hate Graylog.

            Everyone still loves ELK! I should still love ELK! ELK?

            I still hate ELK.

            Icinga! Opsview! Fluentd! AlienVault/OSSIM! ELK!?

            Wait. Why am I doing this? I just need syslog. Add parsing/searching/dashboards later.

            I love syslog-ng!

            /week

            Moral of this story:

            Define your needs before diving down the logging rabbit hole. As nice as ELK, etc, can be, they take a lot of work and planning to produce the polished niceness that you see on display all over the webs. I promise that writing filters, learning grok, and parsing complex non-RFC-compliant-syslog is not something that can be done in an afternoon. Instead of jumping to the end of the line, start at the beginning (solid syslog server) and add layers as needed. Lord knows every one of these tools can be weaved in with the others later.

            1 Reply Last reply Reply Quote 2
            • scottalanmillerS
              scottalanmiller
              last edited by

              What did you end up trying out?

              1 Reply Last reply Reply Quote 0
              • S
                StorageNinja Vendor
                last edited by

                But are your logs sexy?

                http://www.sexilog.fr

                LogInsight is also my "jam" in logs. You don't even need to learn regex...

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @StorageNinja
                  last edited by

                  @John-Nicholson said in Best Syslog Server?:

                  But are your logs sexy?

                  http://www.sexilog.fr

                  LogInsight is also my "jam" in logs. You don't even need to learn regex...

                  Awesome find. I want to play with that now. It's ELK(R) with some additional stuff on top. Very cool.

                  1 Reply Last reply Reply Quote 0
                  • stacksofplatesS
                    stacksofplates
                    last edited by

                    I had an ELK server set up. I switched to Graylog. You don't need a specific forwarder, rsyslog just works. And you can get a pre-built VM to use. Kibana is an awesome tool, but just takes so much time to learn.

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • S
                      StorageNinja Vendor
                      last edited by

                      Custom forwarders have advantages (super fast source filtering, compression and TLS support, custom meta tags, lower CPU) was my Experiance with LI.

                      Note, outside of maybe sumologic everyone with custom agents allows you to use legacy syslog.

                      1 Reply Last reply Reply Quote -1
                      • scottalanmillerS
                        scottalanmiller @stacksofplates
                        last edited by

                        @stacksofplates said in Best Syslog Server?:

                        I had an ELK server set up. I switched to Graylog. You don't need a specific forwarder, rsyslog just works. And you can get a pre-built VM to use. Kibana is an awesome tool, but just takes so much time to learn.

                        I prefer the agents. Much easier and more powerful.

                        1 Reply Last reply Reply Quote 0
                        • 1 / 1
                        • First post
                          Last post