Graylog Review
Enables us to set up streams and error/anomaly searches across hundreds of containers

Primary Use Case

Use for log aggregation, alerting, and monitoring in a container environment

Valuable Features

  • Searching errors
  • Alerting through Slack and OpsGenie using their plugins.

We run a containerized microservices environment. Being able to set up streams and search for errors and anomalies across hundreds of containers is why a log aggregation platform like Graylog is valuable to us. 

Allowing us to set up alerts and integrate with platforms we already use, such as Slack and OpsGenie to alert users of these errors proactively, is also a very useful feature. 

Room for Improvement

Elasticsearch recommendations for tuning could be better. Graylog doesn't have direct support for running the system inside of Kubernetes, so it can be challenging to fill in the gaps and set up containers in a way that is both performant and stable.

We ran into problems with Elasticsearch throwing a circuit-breaking exception due to field data size being too large. It turned out that the heap size directly impacted this size in a high-throughput environment, causing unexplained instability in Graylog. We were able to troubleshoot on the Elasticsearch size, but we should have been able to reference some minimum requirements for Graylog to know that our settings weren't sufficient.

Otherwise, the documentation is great and there are a lot of options for configuration. Since container orchestration systems are popular and Graylog fits the niche well, perhaps they could officially support running in docker containers on Kubernetes as a StatefulSet as a use case. That way, the declarative nature of Kubernetes config files would document their best-case deployment scenario.

Use of Solution

One to three years.

Stability Issues

Yes, with Elasticsearch.

Scalability Issues

No issues with scalability.

Customer Service and Technical Support

Never used.

Previous Solutions

Splunk, Logstash, and Elasticsearch.

Initial Setup

Set up in Kubernetes; not complex once the configuration is right.

Pricing, Setup Cost and Licensing

We use the free version.

Other Solutions Considered

Splunk, Logstash, and Elasticsearch.

Other Advice

Make sure your Elasticsearch cluster is sized right, memory-wise.

Disclosure: I am a real user, and this review is based on my own experience and opinions.

Add a Comment

Why do you like it?

Sign Up with Email