TrustRadius: an HG Insights company

Graylog Reviews & Insights

Score7.5 out of 10

30 Reviews and Ratings

Community insights

TrustRadius Insights for Graylog are summaries of user sentiment data from TrustRadius reviews and, when necessary, third party data sources.

Pros

Efficient log aggregation and intuitive dashboards: Multiple reviewers have praised Graylog for its efficient log aggregation pipeline, allowing users to easily collect and analyze logs from various sources. The clear and intuitive dashboards provided by Graylog were also highlighted as a positive aspect, making it easier for users to understand and monitor their logs effectively.

Powerful search options: Many reviewers have appreciated the powerful search capabilities offered by Graylog. Users mentioned that they can quickly search through large volumes of logs and easily find specific data without manual filtering. This feature enhances efficiency and saves time for users when troubleshooting or investigating issues.

Flexible configuration options: Users have commended Graylog for its flexibility in configuration. Some reviewers mentioned the ability to store everything on a single box, while others highlighted the option to scale out horizontally using a cluster of Elasticsearch nodes and MongoDB servers. This flexibility allows users to tailor their log management setup according to their specific needs and infrastructure requirements.

Graylog Reviews

1 Review
Small Businesses (1-50 employees)

Useful and free SIEM tool

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

Allows insight into logs from various systems and products that would otherwise be time consuming to access and identify. Dashboards can be customised to your preferences and Alerts/emails can be defined when specific events or patterns occur, which is not possible directly from the log source. Our use case is primarily security related looking at access/sign-in logs from various platforms and then sending alerts as required.

Pros

  • Ingesting various log sources
  • Dashboards - Customisable
  • Event alerts/emails

Cons

  • Support for more log sources
  • Event alerts/emails - Some cases where unable to separate data from multiple clients, and no easy fix
  • API - Limits results to 10,000 and can cause server to lockup on queries that exceed the limit

Likelihood to Recommend

Well suited for scenarios such as:
  • Detecting user OS logins, or user logins from unknown IPs etc.
  • Access attempts made on a firewall or other network infrastructure
  • Monitoring changes to Active Directory Groups
Less suited for scenarios where logs and alerts are time critical, eg.as soon as an event occurs an alert is generated and sent
Vetted Review
Graylog
3 years of experience