What is our primary use case?
My main use case for rsyslog server is that it's a logging system for Unix and Linux that collects, stores, and filters logs from various devices, which means I'm working with infrastructure, VMware, and security, something that has been around ever since Unix was established. I pull system logs to see what's going on in systems around the Unix environment and outside of it.
A quick specific example of how I use rsyslog server in my daily work is through centralized logging, where it collects data from Linux servers, Unix servers such as Solaris and AIX, network devices, firewalls, storage arrays, and VMware hosts, pulling logs from everything the Unix and Linux hosts are connected to. These days, it's also used considerably with security, similar to Splunk or Azure Sentinel, and definitely for compliance and audit retention for HIPAA and disaster recovery logs.
I have additional information about my main use case regarding how I use rsyslog server day to day, especially with disaster recovery, as I can track failover events and replication issues when working with tools such as Zerto, addressing kernel issues specifically related to the Unix and Linux servers themselves.
rsyslog server is commonly used for many things in my work, including disaster recovery event tracking, storage arrays such as Dell EMC, NetApp, Pure, and security compliance logging, as well as VMware ESXi host logging.
What is most valuable?
The best features that rsyslog server offers include the ability to filter, tag, and rewrite logs, with logs stored in databases and files, then forwarded to various destinations such as SIEM or files as needed. Of course, the client sends the logs.
Out of those features, I find myself relying most heavily on the logging capabilities it pulls from everything that is connected to Unix or Linux boxes, allowing me to see any particular issues or errors that may be occurring. The logs are stored in files or databases and they can be forwarded to me, even emailed directly.
rsyslog server has positively impacted my organization, particularly with disaster recovery logging, where alerts for failures allow me to see failover events and any replication issues, especially within managed healthcare environments. It can indeed be used for HIPAA, pulling data from the entire infrastructure including Unix and Linux servers, network devices, firewalls, and storage arrays.
Regarding how rsyslog server has improved efficiency and compliance, it provides insight into what's happening within the infrastructure as a high-performance systems log daemon receiving logs from the entirety of the network through UDP and TCP, writing to files, databases, or SIEM systems. It's user-friendly for Unix and Linux admins or engineers because it's been familiar for so long, and it certainly is not outdated.
What needs improvement?
rsyslog server is performing wonderfully now, especially with AI automation utilizing syslog data, similar to tools such as Juniper's Mist and Azure Monitor's AI insights. This classic tool integral to Unix and Linux systems is now harmonized with AI, predicting potential failures, triggering automated remediations, and reducing alert noise while correlating events across systems.
For how long have I used the solution?
I have been working with rsyslog server for well over fifteen years.
What do I think about the stability of the solution?
rsyslog server is absolutely stable, particularly when it runs on well-known Unix and Linux distributions, especially stable ones such as AIX, making the stability a given from the start as I'm receiving syslogs from reliable systems.
What do I think about the scalability of the solution?
I find rsyslog server to be highly scalable, capable of expanding alongside the infrastructure while pulling data from multiple areas including virtualization and storage arrays, as well as Unix and Linux servers and firewalls.
rsyslog server's scalability is exceptional, as it can be implemented across infrastructure setups, pulling data from virtualization, various storage arrays, Unix and Linux servers, and firewalls.
How are customer service and support?
Customer support largely depends on the Unix or Linux server provider; for example, Red Hat has notable support, and HP or IBM also offer reliable help.
Which solution did I use previously and why did I switch?
I did not evaluate other options before choosing rsyslog server because it automatically comes included with Unix and Linux servers.
How was the initial setup?
I have always looked at system logs within Unix and Linux because they come integrated with the OS, offering stability that makes it a default solution, even if other tools were available. Setting up a dedicated rsyslog server enhances that efficiency further.
What about the implementation team?
I currently do not have a business relationship with the vendor beyond being a customer; the syslog is inherently part of the Unix and Linux servers, which comes ready for use.
What was our ROI?
I have seen a return on investment by making use of syslogs, which helps predict anomalies in server environments and storage systems. For instance, alerts from tools such as Pure or Dell EMC, and reporting replication issues from Zerto or similar applications, always provide immediate notifications that are essential for IT operations.
What's my experience with pricing, setup cost, and licensing?
I did not purchase rsyslog server through the AWS Marketplace when I used it in a hybrid setup with AWS.
What other advice do I have?
I give rsyslog server a rating of ten out of ten. The reason is that long before we focused so heavily on cloud technologies, the Unix world had a robust system to look into the logs, revealing what's going on within those servers and databases. My experience with Unix systems shows that most Unix or Linux servers contain databases, marking it as an absolute ten in functionality; it's as relevant today as it ever was.
rsyslog server's AI capabilities depict it as a data pipeline feeding AI systems, working hand in hand with AI for anomaly detection, ops automation, and log analysis through the collected syslog data. This allows for AI model analysis of logs, detecting unusual patterns, suspicious firewall events, and potential disaster recovery replication anomalies or storage errors predicting failure. There is immense potential in processing those rsyslog events filtered through AI.
The accuracy of rsyslog server's output is very high, as is its reliability. This is due to its ability to pull crucial data from infrastructure and connected servers. When using AI-driven anomaly detection tools such as Azure Sentinel or Splunk's toolkit, I can pinpoint a variety of issues from replication lag and network anomalies to VMware host instability, maintaining a high level of stability and reliability through my use.
The fact that rsyslog server can pull from the entire infrastructure speaks volumes for its capabilities. Being a part of the Unix and Linux OS, I can easily log in and examine syslog logs, piping data to the screen or receiving it via email to monitor server activities. In terms of improvements, it has been extended to analyze Azure Sentinel pipelines or firewall logs, enhancing security compliance through a comprehensive look at various systems' logs.
I would advise others considering rsyslog server to realize that those who have Unix or Linux systems are already using it, as introducing AI utilization to pipe our syslogs offers significant operational advantages. It undeniably simplifies processes across IT.
To summarize my additional thoughts about rsyslog server, it acts as a centralized logging system utilized within Unix and Linux environments, collecting, filtering, and forwarding logs from multiple devices including storage, VMware, and cloud security for disaster recovery. Using AI enhances its functionality, allowing for smarter log filtering and management. My overall review rating for rsyslog server is ten out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?