Blog post

Cool Vendor Pick: Graylog

By Jonah Kowall | January 27, 2015 | 34 Comments


There has been a lot of interest over the last 12 months in products based on open source for monitoring and management. In the area of log analysis, Elasticsearch has been a player which has strengthened with the growing investments in the space. The awareness has been greatly increased in the past year. While the popular Kibana frontend to Elasticsearch has been the main GUI. These two projects are paired with Logstash for ingest, combined these make up the ELK stack. There is another great open source project to take a look at. The focus of this weeks write-up is on this alternative to ELK.

The company behind Graylog is Torch out of Hamburg Germany ( they do consulting around the product. The open source site is the project is an ElasticSearch based product, but unlike Kibana it also has additional features:

  • Take inputs directly into the Graylog server processes
  • Output from the server to multiple backends based on output plugins, right now the main one is for ElasticSearch
  • Alerting based on matching or other criteria are integrated into the Graylog project along with a stream processing capability

The supported data comes in the form of plugins which include syslog or GELF (Graylog Extended Log Format) or other plugins. GELF allows for several enhancement from typical syslog.

  • No length limitations for messages (syslog is 1024 bytes)
  • Data types (string, number)
  • Variation in syslog implementation
  • Compression via gzip or zlib

The nice thing is that you don’t need to do any extractions once the messages have been added via GELF. They have 72 such plugins including many GELF libraries (See:

On the site you can sign up for a self-service trial of the software, I did this in early November, there has been another release since then. These screenshots may be a little out of date:




There can be multiple backend nodes connected to the frontend. There is some good management within the GUI of the connections. The main dashboard when you login shows you information about the cluster, components, and the status. There is a query box.



Some other administrative views. Many of the log management tools, especially in open source neglect the day to day maintenance and administration. Being a systems and operations person myself I always dig into the internals needed for day to day administration. Graylog has a lot of what’s been missing across open source ElasticSearch management tools. Some additional views:





They have a data generator in the demo so you’ll see there are plenty of events in the data store.



Here is a query for smtp in the last 30 minutes.



You can also see inside the queries being sent to ElasticSearch, here are the JSON objects being passed to the engine:


Value breakdowns of the results quickly



Graylog has the notion of stream as illustrated below



What these are is a way to pass realtime rules against the data coming into the Graylog server before they are committed to elasticsearch, this real time processing provides a differentiator to Kibana based systems






Some sample sinks of what you can do with a proper eventing system, such as alerting:


The requisite dashboarding for any monitoring tool. Everyone loves dashboards, users are always asking for more dashboards, and they clearly do sell monitoring products. The value they provide are typically pretty limited. If the actual analytics in our software were better the computer would be doing the analysis versus a user looking at graphical displays of data. I digress…


You cannot share the same backend between Kibana/Logstash and Graylog since they use a different schema for the log data in ElasticSearch. Hence you’ll have to make a decision which tool you want to use when setting up ElasicSearch. Please leave comments or questions below on @jkowall on Twitter.


Leave a Comment


  • Arie says:

    Nice review Jonah,

    It is a great tool in our systems management environment. What makes this great is the ease of use of this toolset. We started using it to collect monitoring data (nagios/check_mk) into it, to get better insight in what is happening in time. The smart configurable stream alerts are very useful to send out alerts. Another thing we do is collect windows eventlogs with nxlog in GELF format.

    It is possible to look at the data in ES with Kibana-V3, to make (management)-dashboards to present statistical views and search thru the data, and find this correlating events that matter.

    The next thing is to get logfile data into it so we have everything in one place to look at known and unknown issues that arise on us, sold problems or detect them before they arise.

  • As I see it, the huge roadblock to progress is still the digital marketing talent shortage. Most companies have a limited ‘talent puddle’ of skilled practitioners that are able to work on progressive market development strategies. Meanwhile, the majority of their old-school marketers have not attempted to learn the required new skills — so marketing organizations are dominated by staff that view the world through their legacy media-buyer mindset. To them, digital marketing merely means buying Google Ads or advertising placements on Facebook and LinkedIn. What can a CMO do when 80+ of their current team are not skilled for today’s demands? Clearly, it’s a big ongoing challenge.

  • xem phim sex says:

    Thank So Much For Sharing

  • It is a great tool in our systems management environment. What makes this great is the ease of

  • It is a great tool in our systems management environment. What makes this great is the

  • video says:

    It is a great tool in our systems management environment.

  • Great content quality! lookout our website too, thank you.

  • مشاهده، بررسی و خرید انواع دستگاه و صندلی ماساژور در وبسایت آی‌رست ♥

  • Helpful contents! thanks for announcing.

  • ahankoob says:

    thanks for sharing

  • مشاوره کودک، یکی از خدمات بسیار مهم در روانشناسی می باشد؛ که بر روی کودکان و نوجوانان تمرکز دارد. مشاوران کودک به به درمان اختلالات رفتاری و گفتاری دوران کودکی کمک می کنند. طبق گفته بسیاری از مشاوران کودک، یکی از شایع ترین مشکلات والدین در طول دوران رشد کودکان و نوجوانان لجبازی می باشد. اگر فرزند شما دچار حواس پرتی، عدم تمرکز، پرخاشگری، عصبانیت و… شده است؛ می توانید برای درمان چنین مشکلاتی از مشاوره روانشناسی کودک و نوجوان در سایت ویکی روان کمک بگیرید.

  • betonaloka says:

    Very accurate and professional

  • Pilonidal cysts sometimes drain and disappear on their own pilonidal cyst is an abnormal pocket in the skin that usually contains hair and skin debris

  • this این یک سیستم عالی است که من هم میتوانم روی سرور اختصاصی خود آن را اجرا کنم و از امکانات فوق العاد آن استفاده کنم

  • این یک سیستم عالی است که من هم میتوانم روی سرور اختصاصی خود آن را اجرا کنم و از امکانات فوق العاد آن استفاده کنم

  • قفسه بندی پالت راک یا قفسه پالت راک یکی از رایج ترین انواع قفسه بندی ثابت و فلزی در انبارهای بزرگ صنعتی می باشد که نگهداری از محصولات سنگین را در انبارهای بزرگ به راحت ترین شیوه ممکن فراهم می سازد. قفسه بندی پالت راک با قرار دادن محصولات سنگین در پالت های مسطح که به صورت طبقاتی روی هم قرار گرفته اند، باعث میشود از فضای داخلی انبارها بیشترین استفاده را برده و دسترسی و جا به جایی محصولات در قفسه های مختلف براحتی انجام شود.

  • It is a great tool in our systems management environment.

  • Treatment methods for anal fissures or fissures vary depending on the severity of the signs and symptoms and the condition of the disease. This disease is also referred to as anal ulcer complication, which has the same treatment methods, symptoms and cause as fissures. thanks cliniczarei

  • Much of the information about HPV (human papillomavirus) is for women, because having the virus in women increases the risk of cervical cancer. But genital warts in men can also have serious problems.

  • That is wonderful I find it
    thank u so much

  • چگونه یک مبلمان اداری مدرن و مناسب انتخاب کنیم؟

    انتخاب مبلمان اداری مدرن و مناسب، یکی از مهم ترین چالش های دکوراسیون داخلی ادارات، لابی، اتاق پذیرش، اتاق انتظار و… است. شما برای خرید مبلمان اداری مناسب باید به نکات مهمی توجه نمایید. انتخاب مبلمان اداری مناسب موضوعی پیچیده و مهم است که باید نکاتی در مورد آن دانست. شک نکنید با خواندن مطالب این مقاله، بسیاری از اعتقادات نادرست شما در مورد انتخاب مبلمان اداری از بین خواهد رفت و زیبایی را در فاکتورهای دیگری خواهید دید. در این مقاله شما را در انتخاب مبلمان اداری مناسب راهنمایی خواهیم کرد.

    مهم ترین و اصلی ترین موضوع در انتخاب مبلمان اداری مناسب، دارا بودن کیفیت بالا و استحکام مناسب است. هم از لحاظ اقتصادی و هم از لحاظ منطقی، انتخاب مبلمان اداری با کیفیت و بادوام می تواند بهترین گزینه باشد. سعی کنید قیمت مبلمان اداری را با کیفیت آن مقایسه کنید و همیشه کیفیت را در دکوراسیون داخلی ارجع تر از قیمت بدانید.
    شاید از خود بپرسید که چرا کیفیت تا این اندازه در مبلمان اداری مهم است؟ در پاسخ باید بگوییم: از آنجایی که اغلب کارکنان و مراجعین به ادارات، مدت زیادی را صرف این محل می کنند، یقینا این مدت را در حالت نشسته روی مبلمان سپری خواهند کرد. بنابراین تنها کیفیت بالای مبلمان اداره می تواند پاسخگوی این مدت زمان طولانی نشستن افراد باشد.
    در انتخاب مبلمان اداری، تنها کیفیت مبلمان ارباب رجوع ملاک نیست. انتخاب مبلمان با کیفیت برای مدیران و کارکنان اداره نیز از مهم ترین موضوعات است که تاثیر مستقیم در افزایش بهره وری کارکنان برای اداره دارد. برای مثال اگر کارمند یک اداره در نشستن پشت میز مدیریت خود راحت نباشد، کارایی او کاهش خواهد یافته و ارباب رجوع راهنمایی نخواهند شد.