Centralized data for post mortem to detect the next calamity before it happens
Use Cases and Deployment Scope
We use Loggly as a syslog digest. Normally it is an after-the-fact tool for outages and anomalies. Syslog is an invaluable tool when troubleshooting outages and errors. As we experience outages we go back and sift through Loggly to see what the messages looked like at the event time and create alerts based on them to catch the problems in advance the next time. As a secondary method of catching issues before they become problems, we monitor the gross volume of messages daily. When they spike on a given day we know that something is up and go and find the offending source. <b>Many times we catch the problem before it causes a customer impact event.</b>
Pros
- syslog digest
- alerts based on syslog contents
- sanity check on number of daily log events
- post mortem on outages
Cons
- the interface could be more intuitive
- repetitive syslog dialog could either be highlighted or ignored by user choice
- when a source spikes it's name could be included in the volume alert email
Return on Investment
- decrease diagnosis time
- increase security
- aids with preemptive alerts
- forensics at the finger tip
- exposes syslog to the entire team
Other Software Used
Windows Server, Ubuntu Linux, N-able N-central







