Graylog 6: The Best Open Source Logging Tool Got Better!

Поділитися
Вставка
  • Опубліковано 31 січ 2025

КОМЕНТАРІ • 75

  • @RaidOwl
    @RaidOwl 8 місяців тому +29

    Tom makes me want to implement Graylog but my laziness overpowers it every time.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  8 місяців тому +12

      But docker males it so easy!

    • @manbash05
      @manbash05 8 місяців тому +1

      @@LAWRENCESYSTEMS Hi i always find dockers so confusing ..please have u got a tutorial ideo for graylog using docker?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  8 місяців тому +1

      @@manbash05 ua-cam.com/video/DwYwrADwCmg/v-deo.htmlsi=SpkU-URICLoobOLw

    • @barma1309
      @barma1309 5 місяців тому

      Literally me)))

  • @Joshko82
    @Joshko82 8 місяців тому

    Awesome video Tom. I truly appreciate all the efforts you put into creating high quality, focused and easy to understand content. Also looking especially to the non-paid version here makes sense, since many smaller companies do not have these big budgets!

  • @iamthenotbenamed365
    @iamthenotbenamed365 2 місяці тому +1

    Greetings Brother,
    We like say Thanks for your Continued Vids, Very Informative ...

  • @ehh54
    @ehh54 8 місяців тому +14

    Graylog is not open source it’s using the Server Side Public License its a source available license.
    If I am choosing software to use at work I always try to use projects where you can buy support for open source version. Getting rug pull is never fun have seen it so many times with closed source monitoring software.

  • @scratius
    @scratius 8 місяців тому +2

    Thanks for the review, Tom. Informative as always. Graylog is a wonderful tool.

  • @ashuggtube
    @ashuggtube 8 місяців тому +1

    Nice one Tom, thank you

  • @ManuelWhiskey-3UHF
    @ManuelWhiskey-3UHF 8 місяців тому +1

    Great video, thank you!

  • @kolt9307
    @kolt9307 8 місяців тому +14

    Moved from Graylog to Grafana Loki, never looked back. Damn elastic shards are just a pain

    • @tullyelliston6254
      @tullyelliston6254 8 місяців тому

      w/ the warm tier and the way index rotation/retention have changed, this actually a problem that 6.0 pretty much solved

    • @Kunalchander-c8j
      @Kunalchander-c8j 5 місяців тому +1

      Hi we were also using Grafana Loki earlier but we were only able to download 5000 log lines at a time . Is this the case with your team as well ?

    • @kolt9307
      @kolt9307 5 місяців тому +1

      @@Kunalchander-c8jfrom what I remember we set the max_entries_limit_per_query and max_global_streams_per_user to your desired size

    • @Kunalchander-c8j
      @Kunalchander-c8j 4 місяці тому

      In our case when we are querying high volume logs the Grafana interface starts lagging as hell. It was only stable upto 50k line of logs .

  • @pproba
    @pproba 8 місяців тому +1

    Thanks for the video. I would be very much interested in a comparison between the most popular log management solutions for homelabbers. Any chance you might be working on such a comparison in the future?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  8 місяців тому +1

      What other ones are there besides graylog? Wazuh is not really a log server and OpneSeaech and Elastic are overly manual compared to graylog.

    • @pproba
      @pproba 8 місяців тому +1

      @@LAWRENCESYSTEMS To be honest, I'm not even sure which ones are real alternatives. Reddit suggestions include splunk, vector+promtail+loki, datadog, elk, something+grafana, etc. Tbh even getting an overview for which free/cheap options for personal use exist is not easy.

  • @DPCTechnology
    @DPCTechnology 8 місяців тому +2

    Good stuff..

  • @omgoood
    @omgoood 6 місяців тому

    Thank you. How to split logs from different sources? I mean "Index pattern" analog in ELK.
    For example, I want to query all logs from index "dev-app", or "stage-app".

  • @nivideus
    @nivideus 8 місяців тому

    Great summary video! I was just looking at graylog, this is great timing. Lots of threads to explore, thank you.
    I am using proxmox to manage my NFS mounts which are passed to Docker like you are, but I struggle with the situation where the mount is there but empty if the NAS is unreachable for any reason, causing some services to regard data as "deleted" which can cause quite a bit of chaos.
    I'd like to store my logs remotely like you are, but I'm not sure about how this scenario will affect graylog.
    How do you handle this in your setup? Is there some way to guard against it or suspend containers that depend on the share?

  • @double_DD
    @double_DD 8 місяців тому

    are there any plans on testing and making a video of WAZUH SIEM? It would be very nice if you would do so.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  8 місяців тому +1

      I think enough people have already done a video on and I don't really use it therefore don't have anything more to add. Let me know if I am wrong.

    • @double_DD
      @double_DD 8 місяців тому

      @@LAWRENCESYSTEMS I agree with you there are many videos already out there, but the quality of those videos is questionable. On other hand, your videos are much more professional, providing more information and steps in proper order, with more clarity. In my opinion, Wazuh is much better than Graylog security wise. Also, it's lighter for hardware resources, and provides full unlocked features in free version (you can have paid subscription, but it's for support). You could do great job with video explaining how to tweak it, and configure it properly for security alerts, as it has many options, because your videos stand out in this ocean of low-quality videos.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  8 місяців тому +1

      @@double_DD Thanks, but for clarification is it that many of the videos are sponsored by Wazuh that brings up the question of their quality?

  • @muhammad-alani
    @muhammad-alani 4 місяці тому

    Hello Lawrence!
    How can I change the log colors, like: If the log is info: make it green, if is warning: make it orange, if it's error: make it red and etc.

  • @therus000
    @therus000 3 місяці тому

    Thank's for a nice video
    can anyone share a good extractor for a unifi UDM SE

  • @raughboy188
    @raughboy188 8 місяців тому +18

    Way to many paywalls for app that claims that they're open source. Open version is opensource it offers just logging and nothing more. Enterprise and securtiy also anything paid shouldn't even be in dashboard of open source version.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  8 місяців тому +14

      You have identified a problem that you have with the project, but not a solution. How do you propose they fund this project?

    • @MrAltairantares
      @MrAltairantares 8 місяців тому +10

      @@LAWRENCESYSTEMS I heard thoughts and prayers go pretty far.

    • @egenhoferj
      @egenhoferj 8 місяців тому +11

      Open-source does NOT mean free, its important to remember that.

    • @raughboy188
      @raughboy188 8 місяців тому +4

      @@LAWRENCESYSTEMS they can fund it by offering paid technical support along with extra services that will benefit enterprises not by making difference enterprises and non enterprise users. I've seen few others where you get everthing enterprise does but you don't get techical support if you use free version. Graylog open should reflect it's open source nature without offering demos of paid stuff. It should only have a button with link to enterprise version for more info and subscription. There are ways for them fund it but not by locking features behind paywall.

    • @raughboy188
      @raughboy188 8 місяців тому +1

      @@egenhoferj i know that. I know they need money for hardware,they need to earn money for living,monsy for software they use for development and so on. All i wanted to say how i don't like way some open source apps are funded. In open source world best way to fund development isn't locking up advanced features behind paywall it can instead be thruogh royalties like unreal engine does, it can be by offering techincal support,hosting server on your cloud for enterprise,basicaly anything but locking features behind paywall.

  • @mjacalan
    @mjacalan 2 місяці тому

    If you have an existing graylog (4.3) that still uses the Elasticsearch, can you directly mount the graylog data as a volume in your new install, and still see your old data in your new install?

  • @EViL3666
    @EViL3666 8 місяців тому

    I've long had a soft spot for Graylog... but alas, the Splunk dev license makes it too easy..

  • @demorez5
    @demorez5 3 місяці тому

    i could not set this up. everytime i start opensearch my system becomes unresponsive, floods the logs with some java errors and greylog never starts.

  • @ronaldabalza9713
    @ronaldabalza9713 8 місяців тому

    Hi Lawrence, how can I apply HTTPS or Let's Encrypt for a Docker Graylog instance? thanks

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  8 місяців тому

      Put a reverse proxy in front of it that supports Let's Encrypt. I use pfsense with HAProxy.

  • @DieterFrueh-cp1go
    @DieterFrueh-cp1go 8 місяців тому +1

    Vs grafana loki?

  • @KunalChander-b1j
    @KunalChander-b1j 7 місяців тому

    Can i get more than 2 lakh log lines at a time in gray cloud ??

  • @chhayminea7
    @chhayminea7 3 місяці тому

    How can I update from Graylog 5 to 6?

  • @WeathermanMark1
    @WeathermanMark1 8 місяців тому

    Unfortunately I'm running an older server for my virtual environment with CPUs that don't support MongoDB's AVX requirement. I wish MongoDB had a legacy switch for older hardware or we could use a different DB.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  8 місяців тому +1

      AVX enabled processors have been shipping since 2012 and the latest AVX-512 version since 2016. Might be time to consider upgrading.

    • @WeathermanMark1
      @WeathermanMark1 8 місяців тому +1

      @@LAWRENCESYSTEMS Yes, I'm still running (3) 4U Supermicro servers with (2) Xeon X5675 3Ghz CPUs, 300G ram, and 36 drive bays. I have been looking at some of the newer/used Supermicros with 512G DDR4, newer CPUs, etc. Just have not committed yet.

  • @theatlastech8792
    @theatlastech8792 8 місяців тому

    Will your Greylog update video still work to get onto this newest version?

  • @nitrogarbo1589
    @nitrogarbo1589 8 місяців тому

    What is the difference between Zabbix vs Graylog?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  8 місяців тому +2

      Zabbix is more of a monitoring tool, Graylog is a logging tool.

  • @lindhe
    @lindhe 8 місяців тому +1

    Last I looked at Graylog, I recall being deterred by them depending on some deprecated version of a database. Know what I'm talking about? Is that fixed now?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  8 місяців тому

      Look at the docker compose and see if something in there that makes you not want to use it.

  • @simons9167
    @simons9167 8 місяців тому

    The UI is similar to Wazah..

  • @bobstar4800
    @bobstar4800 8 місяців тому

    Was willing to use graylog but the lack of libraries for nodejs forced me to switch to Loki.

  • @sabir4094
    @sabir4094 8 місяців тому

    This is a great tool, but requirew a lot resources.

  • @oxxysaurus
    @oxxysaurus 8 місяців тому

    Followed the instructions exactly, on a new install (VM), didnt work. Tried again, didnt work. Might want to review the instructions mate.

  • @yeahmanitsmurph
    @yeahmanitsmurph 8 місяців тому +1

    Hardly the best logging tool especially when a lot of the main functionality is behind a paywall. When stacked up against the free tiers of Elastic, Splunk, OpenSearch or even solutions like Wazuh, Malcolm and S1EM, Graylog doesn’t even compete.

    • @MortenEghj
      @MortenEghj 8 місяців тому

      Do you have any links to such an comparison?

    • @yeahmanitsmurph
      @yeahmanitsmurph 8 місяців тому +3

      @@MortenEghj My opinion is based off my own evaluation of each. However, If you just want a product, ignore me and just pick whatever the UA-camr tells you. If you have any responsibility to critical work or to a customer base, identify what’s important for your organization and reach out to competing vendors, get their demonstration and decide which makes the most sense. If you’re just playing around in a homelab, install them and see for yourself.

    • @jasonperry6046
      @jasonperry6046 8 місяців тому

      What one do you recommend I look at first?
      Better yet, what type of person would you recommend each solution for?

  • @MarkConstable
    @MarkConstable 8 місяців тому

    Stopped watching at the first mention of docker.

    • @dyto2287
      @dyto2287 8 місяців тому +6

      If docker is to hard to for you then you should retire from IT bud.

    • @MarkConstable
      @MarkConstable 8 місяців тому +1

      @@dyto2287 I will do that, thanks for the advice.

    • @double_DD
      @double_DD 8 місяців тому

      @@dyto2287 and you are an idiot!!! So the WHOLE IT world is based only on docker, so if someone doesn't know how to use docker, he should retire from IT.... you dumbhead...

    • @samsampier7147
      @samsampier7147 8 місяців тому +1

      Graylog has installation docs for Ubuntu, Debian, Red Hat, and SUSE if you don't' want to use Docker. And manual if your distro is none of these.