ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Best Syslog Server?

    IT Discussion
    6
    12
    1.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Alex Sage
      last edited by

      What your favorite Syslog Server?

      1 Reply Last reply Reply Quote 0
      • A
        Alex Sage
        last edited by

        Is ELK a Syslog Server?

        DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403 @Alex Sage
          last edited by

          @aaronstuder said:

          Is ELK a Syslog Server?

          http://operational.io/elk-for-network-operations/

          1 Reply Last reply Reply Quote 3
          • scottalanmillerS
            scottalanmiller @Alex Sage
            last edited by

            @aaronstuder said:

            Is ELK a Syslog Server?

            Yes, and more.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller
              last edited by

              ELK and ELG (Graylog2) would be my favourites for self hosting. Splunk is great but super expensive beyond a trivially small use case. Logg.ly is awesome if you are going to pay for someone to host it for you.

              1 Reply Last reply Reply Quote 1
              • crustachioC
                crustachio
                last edited by

                I'm muddling through this myself. My week in a nutshell:

                Everyone loves ELK! I should love ELK! ELK!

                I hate ELK.

                Graylog! It's a Splunk killer! Easy! Pretty! Graylog!

                I hate Graylog.

                Everyone still loves ELK! I should still love ELK! ELK?

                I still hate ELK.

                Icinga! Opsview! Fluentd! AlienVault/OSSIM! ELK!?

                Wait. Why am I doing this? I just need syslog. Add parsing/searching/dashboards later.

                I love syslog-ng!

                /week

                Moral of this story:

                Define your needs before diving down the logging rabbit hole. As nice as ELK, etc, can be, they take a lot of work and planning to produce the polished niceness that you see on display all over the webs. I promise that writing filters, learning grok, and parsing complex non-RFC-compliant-syslog is not something that can be done in an afternoon. Instead of jumping to the end of the line, start at the beginning (solid syslog server) and add layers as needed. Lord knows every one of these tools can be weaved in with the others later.

                1 Reply Last reply Reply Quote 2
                • scottalanmillerS
                  scottalanmiller
                  last edited by

                  What did you end up trying out?

                  1 Reply Last reply Reply Quote 0
                  • S
                    StorageNinja Vendor
                    last edited by

                    But are your logs sexy?

                    http://www.sexilog.fr

                    LogInsight is also my "jam" in logs. You don't even need to learn regex...

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @StorageNinja
                      last edited by

                      @John-Nicholson said in Best Syslog Server?:

                      But are your logs sexy?

                      http://www.sexilog.fr

                      LogInsight is also my "jam" in logs. You don't even need to learn regex...

                      Awesome find. I want to play with that now. It's ELK(R) with some additional stuff on top. Very cool.

                      1 Reply Last reply Reply Quote 0
                      • stacksofplatesS
                        stacksofplates
                        last edited by

                        I had an ELK server set up. I switched to Graylog. You don't need a specific forwarder, rsyslog just works. And you can get a pre-built VM to use. Kibana is an awesome tool, but just takes so much time to learn.

                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                        • S
                          StorageNinja Vendor
                          last edited by

                          Custom forwarders have advantages (super fast source filtering, compression and TLS support, custom meta tags, lower CPU) was my Experiance with LI.

                          Note, outside of maybe sumologic everyone with custom agents allows you to use legacy syslog.

                          1 Reply Last reply Reply Quote -1
                          • scottalanmillerS
                            scottalanmiller @stacksofplates
                            last edited by

                            @stacksofplates said in Best Syslog Server?:

                            I had an ELK server set up. I switched to Graylog. You don't need a specific forwarder, rsyslog just works. And you can get a pre-built VM to use. Kibana is an awesome tool, but just takes so much time to learn.

                            I prefer the agents. Much easier and more powerful.

                            1 Reply Last reply Reply Quote 0
                            • 1 / 1
                            • First post
                              Last post