What is our primary use case?
Graylog Enterprise serves as my main centralized log management solution. In our environment, we have many systems that generate logs, including servers, applications, network devices, and security tools. Instead of checking each system separately, we send all those logs into Graylog so we have one place to monitor and investigate what is happening.
A common use case is troubleshooting. For instance, if an application is failing or users are reporting problems, we use Graylog to search through the logs and find the exact error, when it started, and which system is affected. This is beneficial because it helps us identify the root cause much faster.
We also use Graylog Enterprise for security monitoring, which helps us identify activities such as repeated failed logins. Sometimes it helps us identify unusual user behavior or suspicious connections, and we create alerts to respond quickly in case something important happens.
Another area is reporting and compliance. Graylog Enterprise stores historical logs so when we want to review past activities for audits or provide evidence of what happened during an incident, we can review the historical logs.
What is most valuable?
Graylog Enterprise offers many amazing features, with some standing out for me. The first one is centralized log management, which brings logs from different systems into one platform, saving us time as we don't have to check multiple servers or tools to identify the issue. The second feature I value most is the powerful search, which allows us to quickly search through large amounts of log data, especially using different filters such as usernames, IP addresses, and applications. This is excellent as it helps troubleshooting and investigation become much faster.
The third feature I value most is the alerting capability. We can create alerts for important events, such as login attempts, system errors, and any suspicious activity. This way, we can get alerted and respond before the issue escalates.
We rely on several features every day, but real-time alerting is our main feature because it helps us send alerts in case there is any system error or suspicious activity so we can respond very fast before it affects our IT environment.
Graylog Enterprise has impacted our organization positively in many ways. For example, investigating issues before using it often required checking different systems individually, which could take more time. With Graylog Enterprise, we have one central platform to review and analyze logs from different sources. It has also helped us respond rapidly to both technical and security issues because we can quickly search events and identify the root cause to understand what happened.
While I cannot provide an exact number, Graylog Enterprise has reduced our investigation time by around 80%. For example, for security events such as failed login attempts and detecting unusual system behavior that we previously required to check manually, we can now complete those tasks within a minute.
What needs improvement?
One improvement I want to see in Graylog Enterprise is artificial intelligence to help us automatically identify unusual patterns and suggest possible causes. I also want to see more ready-made dashboards and alert templates for common security use cases to help us gain value from the platform faster after deployment. Lastly, I want to see improvements in handling very large volumes of data, especially after searching, and a more user-friendly log management system, particularly in large environments.
I give Graylog Enterprise a 9 out of 10 because it has a limitation of a steep learning curve for new users due to the many configuration options. It takes considerable time to become comfortable with creating searches, dashboards, and alerts. Additionally, in very large environments with large volumes of logs, it requires careful planning, and its data retention is quite limited.
For how long have I used the solution?
I have been using Graylog Enterprise for 14 months.
What do I think about the stability of the solution?
Graylog Enterprise is very stable.
What do I think about the scalability of the solution?
Graylog Enterprise is also scalable.
How are customer service and support?
The customer support for Graylog Enterprise is very good, and they are responsive and knowledgeable. I also appreciate that Graylog Enterprise provides good documentation, community resources, and technical guides, which help us solve common issues and learn more about the platform without needing to consult the support team.
What was our ROI?
We have seen a return on investment because since we started using Graylog Enterprise, we can find information much faster, within minutes, thanks to all logs being available in one place. This reduces investigation time to minutes or seconds, helping us resolve issues quicker and thereby reducing downtime for critical systems.
What's my experience with pricing, setup cost, and licensing?
I find the pricing, setup cost, and licensing of Graylog Enterprise to be somewhat expensive. However, it is cost-effective compared to other larger platforms. The pricing depends on factors such as the amount of data collected, the number of users, the features desired, and the size of the environment. One thing we consider is that log management costs can grow as the organization needs more data, so proper planning around data retention and identifying which logs are most important is crucial for managing costs.
Which other solutions did I evaluate?
Before choosing Graylog Enterprise, we evaluated other log management systems, including platforms such as IBM QRadar and Elastic Security. We compared them based on areas such as log collection capabilities, search performance, alerting, dashboards, integration, and overall cost. We concluded that Graylog Enterprise is not expensive compared to the other platforms we evaluated and also has a solid log management system.
What other advice do I have?
My advice for others looking into using Graylog Enterprise is to plan which systems and logs are most valuable to collect because collecting everything without proper planning can increase costs and make analysis more difficult. I would also recommend setting up clear dashboards, alerts, and retention policies from the beginning, not in the middle, to help your team and the organization focus on important events instead of being overwhelmed by too many. I rate this product a 9 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure