Enhancing Data Understanding
Rocco Gagliardi
This article looks at the open-source log file tool Graylog. It is not a technical comparison against other tools, is just to fire some reasons to support my – changed – preference of Graylog over ELK. We are taking here about the free versions.
Since many years I’m a – relative – big fan of ELK, basically because Logstash and Kibana. Since I wrote and maintained my own log parsing and presentation engine, I really appreciate Logstash, in regards of performance, modularity, flexibility. I also appreciate the Kibana visualization features.
Where I’m falling from love with ELK, is the lacks of authentication/authorization features and the absence of a unified management user interface for all components.
Graylog uses a different approach. The WebUI covers many functionality – from the status of ES indexes up to input, parsing, filter and presentation – making the experience more comfortable; sure, for some advanced tuning, console intervention is needed, but for normal usage, the WebUI provides all functionality necessary to get, parse, manipulate, and present the data.
Graylog excels in many areas:
The dashboard part, even if very well integrated and useful, lacks many features and visualizations contained in Kibana (like aggregations).
Additionally, security settings must be configured separately, also with some terminal effort.
Graylog, even if not perfect, is – at the moment – the best open-source tool to start with, if there is a need of log management. It is packaged for major Linux distributions, has VM ready for use and also Docker images are available.
It still requires some time to learn the architecture, and in case of problems you could spend days if you never touched Elasticsearch or other log tools. But if you have some experience, you can easily setup a complex environment for complex log analysis in a couple of hours.
Our experts will get in contact with you!
Rocco Gagliardi
Rocco Gagliardi
Rocco Gagliardi
Rocco Gagliardi
Our experts will get in contact with you!