Graylog

RATING:

4.6

(30)

About Graylog

Graylog elevates cybersecurity and IT operations through its comprehensive SIEM, Centralized Log Management, and API Security solutions. Graylog provides the edge in Threat Detection & Incident Response across diverse attack surfaces. The company’s unique blend of AI/ML, advanced analytics, and intuitive design makes cybersecurity smarter, not harder. Graylog is also ideal for troubleshooting daily IT performance and availability issues. Unlike competitors’ complex, costly setups, Graylog offers both power and affordability, simplifying the IT and security challenges. Founded in Hamburg, Germany, and now headquartered in Houston, Texas, Graylog solutions are deployed in more than 50,000 installations across 180 countries.
Graylog dashboard
Slide 1 of 6

Graylog Reviews

Overall Rating

4.6

Ratings Breakdown

Secondary Ratings

Ease-of-use

4

Customer Support

4.5

Value for money

4.5

Functionality

4.5

Most Helpful Reviews for Graylog

1 - 5 of 30 Reviews

User Profile

Chamroeunrith

Verified reviewer

Non-Profit Organization Management, 201-500 employees

Used weekly for more than 2 years

Review Source: Capterra
This review was submitted organically. No incentive was offered

OVERALL RATING:

5

EASE OF USE

5

VALUE FOR MONEY

5

CUSTOMER SUPPORT

5

FUNCTIONALITY

5

Reviewed September 2021

Graylog Enterprise Log for Business

prevously we using syslog server to centralize log, and when we have more server and network we can not put all those log into syslog server that store data in mysql, it perform slow search and not report correctly, i have try spend sometime to search and i found graylog, i try to setup a few day until success because its new related to elastic search, but finally i find out and keep using until now, its around 3 years already since i use graylog server to monitor all the network activity, monitoring server with nxlog agent, monitor cisco switch with syslog, linux with syslog, and can monitor the radius authentication log, each time users plug the network or connect wifi log generated and sent to graylog-server, and graylog server create alert message send by telegram to system admin.

PROS

- Graylog is very powerful log, i have search around 50million of record in 3second only, very powerful log because it integrated with elastic search that perform log search very fast. - Telegram alert notification is what i like, i create the rule to let it send notification to telegram so i know what is going on on the network/server log. - enterprise license are free for one year, and make sure your traffic log not hit to 5GB/day. - support various log protocol, nxlog from windows, syslog from linux, and other such as aws. but i use only nxlog and syslog only.

CONS

its perfect already but the dashboard not so nice, not so flexible on the reporting yet.

Reason for choosing Graylog

normal log search server support only syslog protocol, its not enough and not detail information. well, graylog is enterprise class, license cost is cheaper than other, fast search, support multi protocol of log, from windows server, linux, aws, and more protocol, but based on my experience and real work with graylog is we use graylog to store windows log, linux, cisco, mikrotik, fortigate, unifi router, dell server, dell SAN storage, and dell core swithc only. currently we have around 300 devices that sent log to graylog server, and log traffic around 3GB/day, but graylog can perform search the log information well even the database of graylog is 500GB for 6months, as we always archive the database when it increase to 500GB of log.

Reasons for switching to Graylog

syslog server when we have data store alot in mysql server it slow on search report, and not generate graph well.

Tim

Hospitality, 1,001-5,000 employees

Used daily for more than 2 years

Review Source: Capterra

OVERALL RATING:

5

EASE OF USE

5

VALUE FOR MONEY

5

CUSTOMER SUPPORT

5

FUNCTIONALITY

5

Reviewed November 2020

Great value to cost ratio for a solid log management solution

Graylog has been great to work with. Their sidecar implementations make client configuration and management very easy, and even with the free version, they provide reliable, albeit limited support (I’ve gotten good, live email replies to a couple of questions, versus only allowing you to access forums, etc).

PROS

Very low cost of ownership, particularly if you can get the Community (Free, Open-Source) version to meet your needs. I’ve implemented Graylog at multiple organizations for only the cost of hardware / storage.

CONS

Would love to have more plugins / content packs available in the Graylog Marketplace. With limited hands on a team for a smaller company, there’s often not enough time to write extractors and content packs.

Reason for choosing Graylog

Again, of note, we didn’t purchase. While there’d be added value to enterprise plugins and support, we are meeting our needs with the Community (F.O.S.S.) version.

Reasons for switching to Graylog

Cost associated with using the tool, based on data ingestion, was going to substantially increase our expenses to even maintain the solution as it stood. This was the case at multiple organizations, as well.

Vendor Response

Hi Tim, Thank you so much for taking time out to write us a review. Glad you are happy with Graylog & the cost savings you are seeing. We have recently launched "Illuminate" which has a lot of ready to use content packs. You can check it out here - https://www.graylog.org/illuminate/illuminate-authentication. You can sign up for our newsletter too to get updated when we launch new content packs - https://www.graylog.org/newsletter . Thanks again, Team Graylog

Replied November 2020

Rahul

Telecommunications, 10,000+ employees

Used daily for less than 2 years

Review Source: Capterra

OVERALL RATING:

3

EASE OF USE

3

VALUE FOR MONEY

3

CUSTOMER SUPPORT

1

FUNCTIONALITY

3

Reviewed December 2020

Graylog support

PROS

Its easy to use and deploy. We have installed it over centos and its easy to deploy and start working on.

CONS

The customer support structure needs to improve, we have been facing unknown issues for which rca was needed however there have been issues. The streams were showing running but they were struck. Also option should be there to easily search logs

Reason for choosing Graylog

Cost

User Profile

Adam "Abe"

Verified reviewer

Government Administration, 51-200 employees

Used daily for more than 2 years

Review Source: Capterra

OVERALL RATING:

5

EASE OF USE

4

VALUE FOR MONEY

5

CUSTOMER SUPPORT

5

FUNCTIONALITY

4

Reviewed July 2020

You can’t do better for building a Log Management Ecosystem

I’ve recommended it as a solution to many local governments during my conference presentations and they’ve listened.

PROS

Graylog is built on ElasticSearch and extends its functionality out into a great product with the System Administrator in mind. You stand up the platform, point logs at it and the rest is up to your internal processes. I also enjoy that the vast majority of intelligence and augmented data is built directly into the platform rather than an outside product. The community support forums are chock full of helpful folks.

CONS

For a long time the visualizations were quite lacking and we required additional tools to properly tell our data stories but this is improving drastically with each new release.

Reason for choosing Graylog

Cost and simplicity. Also, you can leverage any aspect of ElasticSearch that you desire as well making it a very versatile choice.

Remi

Verified reviewer

Information Technology and Services, 201-500 employees

Used weekly for more than 2 years

Review Source: Capterra

OVERALL RATING:

5

EASE OF USE

4

VALUE FOR MONEY

5

FUNCTIONALITY

4

Reviewed June 2020

Very strong on open source on-premise solution

Experience has been great, we started by using the free version, it has provided benefits early on to the dev teams to search through web logs without the need for downloading them and using a log parser application, or committing early to expensive paid tools. Since then we keep adding new sources and are looking at more enterprise features as usage grows.

PROS

Graylog has alot of flexibility and a mature feature set. We use it across all of our Windows as well as Linux servers. It has a strong community and alot of flexibility, does not impose restrictions on our applications, good documentation and generally receives regular updates and features.

CONS

I find some of the latest changes to the GUI (changes happen all the time with Graylog) are less user friendly - functionality to get count tables are still there but it is less dummy proof whereas before a novice user could click around in the side navigation and discover certain features. There are also less cloud offerings for Graylog so it fits more the on-premise model where you manage the graylog server/infrastructure.

Reason for choosing Graylog

We had a senior team member that had experience with Graylog.