ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Comparing ELK and GrayLog

    Scheduled Pinned Locked Moved IT Discussion
    elkgraylogelasticsearchlogstashkibanalogginglog managementopen source
    30 Posts 5 Posters 13.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      flaxking
      last edited by

      We've been planning for Prometheus + Grafana for metrics, so if we open up Elastic Stack as on option, we will have to see if we want to use it for metrics instead.

      It doesn't help in the initial decision making that these products can all be combined in all kinds of ways, but I suppose it will help in the future if we need something different without having redo the entire setup to meet a new business need.

      1 Reply Last reply Reply Quote 0
      • F
        flaxking
        last edited by

        And what does everyone think of packetbeat? My gut feeling is that it would be a bad idea.

        1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @flaxking
          last edited by

          @flaxking said in Comparing ELK and GrayLog:

          I'm getting the feeling that if you want a real Enterprise setup with the Elastic Stack, eventually you will end up having to pay $$

          Above 5GB/day, yes.

          1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @flaxking
            last edited by

            @flaxking said in Comparing ELK and GrayLog:

            I'm getting the feeling that if you want a real Enterprise setup with the Elastic Stack, eventually you will end up having to pay $$

            I think the open source version pretty much does what you need.

            F 1 Reply Last reply Reply Quote 0
            • F
              flaxking @scottalanmiller
              last edited by

              @scottalanmiller said in Comparing ELK and GrayLog:

              @flaxking said in Comparing ELK and GrayLog:

              I'm getting the feeling that if you want a real Enterprise setup with the Elastic Stack, eventually you will end up having to pay $$

              I think the open source version pretty much does what you need.

              We need Ops to have access and then Devs to have access only to data from the project they are on the team for.

              I suppose we could try to put additional authentication in front of elasticsearch, and then just have multiple Kibana instances all with different access to elasticsearch. Failing that, we would be looking at separate ELK deployments per project - which could be an option, but might kind of suck for Ops

              scottalanmillerS 2 Replies Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @flaxking
                last edited by

                @flaxking said in Comparing ELK and GrayLog:

                @scottalanmiller said in Comparing ELK and GrayLog:

                @flaxking said in Comparing ELK and GrayLog:

                I'm getting the feeling that if you want a real Enterprise setup with the Elastic Stack, eventually you will end up having to pay $$

                I think the open source version pretty much does what you need.

                We need Ops to have access and then Devs to have access only to data from the project they are on the team for.

                Doesn't the free open source GrayLog do that for you as it is?

                F 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @flaxking
                  last edited by

                  @flaxking said in Comparing ELK and GrayLog:

                  I suppose we could try to put additional authentication in front of elasticsearch, and then just have multiple Kibana instances all with different access to elasticsearch. Failing that, we would be looking at separate ELK deployments per project - which could be an option, but might kind of suck for Ops

                  Right, this is why ELK doesn't do what you want, but Graylog does. That's exact why Graylog is the general recommendation here, ELK requires a lot of add ons or the enterprise version that you pay for to get basic functionality. But Graylog does it all for free.

                  1 Reply Last reply Reply Quote 0
                  • F
                    flaxking @scottalanmiller
                    last edited by

                    @scottalanmiller said in Comparing ELK and GrayLog:

                    @flaxking said in Comparing ELK and GrayLog:

                    @scottalanmiller said in Comparing ELK and GrayLog:

                    @flaxking said in Comparing ELK and GrayLog:

                    I'm getting the feeling that if you want a real Enterprise setup with the Elastic Stack, eventually you will end up having to pay $$

                    I think the open source version pretty much does what you need.

                    We need Ops to have access and then Devs to have access only to data from the project they are on the team for.

                    Doesn't the free open source GrayLog do that for you as it is?

                    Yeah, which is why I'm leaning towards GrayLog

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @flaxking
                      last edited by scottalanmiller

                      @flaxking said in Comparing ELK and GrayLog:

                      @scottalanmiller said in Comparing ELK and GrayLog:

                      @flaxking said in Comparing ELK and GrayLog:

                      @scottalanmiller said in Comparing ELK and GrayLog:

                      @flaxking said in Comparing ELK and GrayLog:

                      I'm getting the feeling that if you want a real Enterprise setup with the Elastic Stack, eventually you will end up having to pay $$

                      I think the open source version pretty much does what you need.

                      We need Ops to have access and then Devs to have access only to data from the project they are on the team for.

                      Doesn't the free open source GrayLog do that for you as it is?

                      Yeah, which is why I'm leaning towards GrayLog

                      Oh, I misunderstood your comment about needing to pay for the Elastic stack. Because Graylog is an Elastic stack as wel. ELK and Graylog are competing Elastic stacks.

                      F 1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller
                        last edited by

                        Yes, the ELK stack you must pay to get it working in an enterprise way, that's for certain.

                        1 Reply Last reply Reply Quote 0
                        • F
                          flaxking @scottalanmiller
                          last edited by

                          @scottalanmiller said in Comparing ELK and GrayLog:

                          @flaxking said in Comparing ELK and GrayLog:

                          @scottalanmiller said in Comparing ELK and GrayLog:

                          @flaxking said in Comparing ELK and GrayLog:

                          @scottalanmiller said in Comparing ELK and GrayLog:

                          @flaxking said in Comparing ELK and GrayLog:

                          I'm getting the feeling that if you want a real Enterprise setup with the Elastic Stack, eventually you will end up having to pay $$

                          I think the open source version pretty much does what you need.

                          We need Ops to have access and then Devs to have access only to data from the project they are on the team for.

                          Doesn't the free open source GrayLog do that for you as it is?

                          Yeah, which is why I'm leaning towards GrayLog

                          Oh, I misunderstood your comment about needing to pay for the Elastic stack. Because Graylog is an Elastic stack as wel. ELK and Graylog are competing Elastic stacks.

                          ELK + Beats is now rebranded as "The Elastic Stack"
                          Strategic marketing decision

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @flaxking
                            last edited by

                            @flaxking said in Comparing ELK and GrayLog:

                            @scottalanmiller said in Comparing ELK and GrayLog:

                            @flaxking said in Comparing ELK and GrayLog:

                            @scottalanmiller said in Comparing ELK and GrayLog:

                            @flaxking said in Comparing ELK and GrayLog:

                            @scottalanmiller said in Comparing ELK and GrayLog:

                            @flaxking said in Comparing ELK and GrayLog:

                            I'm getting the feeling that if you want a real Enterprise setup with the Elastic Stack, eventually you will end up having to pay $$

                            I think the open source version pretty much does what you need.

                            We need Ops to have access and then Devs to have access only to data from the project they are on the team for.

                            Doesn't the free open source GrayLog do that for you as it is?

                            Yeah, which is why I'm leaning towards GrayLog

                            Oh, I misunderstood your comment about needing to pay for the Elastic stack. Because Graylog is an Elastic stack as wel. ELK and Graylog are competing Elastic stacks.

                            ELK + Beats is now rebranded as "The Elastic Stack"
                            Strategic marketing decision

                            Oh man, that's confusing.

                            1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller
                              last edited by

                              Because Graylog has been an Elastic Stack for a really long time now, as has ELK. Rebranding something new as something that already exists is a mess.

                              F 1 Reply Last reply Reply Quote 0
                              • F
                                flaxking @scottalanmiller
                                last edited by

                                @scottalanmiller said in Comparing ELK and GrayLog:

                                Because Graylog has been an Elastic Stack for a really long time now, as has ELK. Rebranding something new as something that already exists is a mess.

                                And I'm sure there are lots of custom elastic stacks out there

                                scottalanmillerS 1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @flaxking
                                  last edited by

                                  @flaxking said in Comparing ELK and GrayLog:

                                  @scottalanmiller said in Comparing ELK and GrayLog:

                                  Because Graylog has been an Elastic Stack for a really long time now, as has ELK. Rebranding something new as something that already exists is a mess.

                                  And I'm sure there are lots of custom elastic stacks out there

                                  That, too.

                                  1 Reply Last reply Reply Quote 0
                                  • 1
                                    1337
                                    last edited by 1337

                                    Having not used either - what's the main purpose of ELK and GrayLog?

                                    Is it just to have a central place to view logs from everything?

                                    Is it an overlap in functionality or complement to monitoring solutions like zabbix?

                                    scottalanmillerS F 4 Replies Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @1337
                                      last edited by

                                      @Pete-S said in Comparing ELK and GrayLog:

                                      Having not used either - what's the main purpose of ELK and GrayLog?

                                      Comparing to yet other products is easiest.... Splunk, Loggly, LogRhythm

                                      1 Reply Last reply Reply Quote 1
                                      • scottalanmillerS
                                        scottalanmiller @1337
                                        last edited by

                                        @Pete-S said in Comparing ELK and GrayLog:

                                        Is it just to have a central place to view logs from everything?

                                        Yes, but fast, protected, sometimes visually, with deep search. It's like log viewing on steroids.

                                        1 Reply Last reply Reply Quote 1
                                        • scottalanmillerS
                                          scottalanmiller @1337
                                          last edited by

                                          @Pete-S said in Comparing ELK and GrayLog:

                                          Is it an overlap in functionality or complement to monitoring solutions like zabbix?

                                          Complimentary.

                                          1 Reply Last reply Reply Quote 1
                                          • F
                                            flaxking @1337
                                            last edited by

                                            @Pete-S said in Comparing ELK and GrayLog:

                                            Having not used either - what's the main purpose of ELK and GrayLog?

                                            Is it just to have a central place to view logs from everything?

                                            Is it an overlap in functionality or complement to monitoring solutions like zabbix?

                                            ELK can be used for all kinds of data analytics, GrayLog's focuses just on logs

                                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post