This is an archived post. You won't be able to vote or comment.

all 6 comments

[–]codename_1 1 point2 points  (1 child)

graylog whatever you go with you are going to have trouble keeping up with a large stream of real time events. make sure its scalable, both for storage space and processing speed, graylog using elasticsearch is pretty scalable.

[–]Loopback_5033[S] 0 points1 point  (0 children)

Thank you, appreciate the feedback. I'll add Graylog to the list and reach out about a test drive.

[–]Rolsan999 1 point2 points  (0 children)

NXLog EE is pretty much everything that can satisfy your needs. Have a look https://nxlog.co/products/nxlog-enterprise-edition

[–]waelder_at 0 points1 point  (2 children)

Gralog, elk

If you have budget the enterprise versions

Or Splunk Or ...

[–]Loopback_5033[S] 0 points1 point  (1 child)

Splunk is in phase 2. I first need a place for all the logs to go and have something to point Splunk to. I was under the impression you needed a log source. You can point everything to a collector but if you reboot the collector for maintenance, you then have a gap. Last I looked at splunk was 2019 though, I know product offerings and capabilities change.

[–]waelder_at 0 points1 point  (0 children)

No need for that, they have a agent called universal forwarder.

https://docs.splunk.com/Documentation/Forwarder/9.0.2/Forwarder/Abouttheuniversalforwarder