Overview

Product video
Graylog Security is SIEM Without Compromise Graylog Security combines SIEM, analytics, investigation, and anomaly detection in a single solution so analysts can detect and respond to threats faster while reducing risks from insider and credential-based attacks.
Graylog Operations is Log Management Done Right Graylog Operations delivers fast, scalable centralized log management that turns raw data into clear visibility. IT, Network, and DevOps teams quickly identify and resolve issues that impact performance and business continuity.
Why Customers Choose Graylog
GREAT ANALYST EXPERIENCE: Integrated search, dashboards, and alerts make data exploration simple and productive. New AI-driven dashboard summaries, thresholds, and annotations highlight what matters most.
SPEED & SCALE: Search terabytes in milliseconds without proprietary query languages, keeping investigations fast and efficient.
CLOUD OR ON-PREM: Full functionality in either deployment with predictable TCO and deployment flexibility.
COMPREHENSIVE: Everything mid-sized enterprises need for SIEM and threat hunting in one product without add-ons or hidden costs.
OPEN PLATFORM: Open-source heritage and seamless integrations with REST API, forwarders, and AWS OpenSearch.
AWS SECURITY LAKE INTEGRATION: Fine-grained controls for previewing, filtering, and retrieving logs ensure cost-effective access to the right cloud data while reducing unnecessary storage and license costs.
Highlights
- Gain meaningful insights and answers from your event log data so your IT, DevOps, and Security professionals can identify performance and cyber issues faster, make informed decisions quicker, and improve key metrics like Mean-Time-to-Detect (MTTD) and Mean-Time-To-Respond (MTTR).
- Lightning-fast search and filter capabilities allow you to parse terabytes of log data in seconds for faster troubleshooting.
- Increase productivity with powerful automation capabilities.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Graylog Security Unit | Graylog Security | $0.001 |
Graylog Operations Unit | Graylog Operations | $0.001 |
Vendor refund policy
As defined in EULA
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
The mission of Graylog Support is to build competence, capability, and confidence in Graylog within our broad base of Customers and Partners. Your successful adoption and acceleration of Graylog as a solution within your business is a fundamental driver behind what we do and how we do it. Experience our first-class support at https://www.graylog.org/technical-support/ .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Centralized log monitoring has improved visibility and now needs richer visuals and smoother upgrades
What is our primary use case?
I remember using Graylog Enterprise in the past at a software house where we used it for logging. During that time, we were using Graylog Enterprise as a log aggregator, collecting logs from multiple systems and then exporting and visualizing them within Graylog.
We had multiple Linux-based machines, and we were trying to capture the logs from the systems and export them into Graylog so that they could be centrally visualized. Graylog Enterprise was deployed on-premises in a private cloud.
What is most valuable?
In my experience, if I compare Graylog Enterprise with the ELK stack, I can see that Graylog is way easier to set up and has a great, good-looking UI. These are the things where I could see Graylog as a lightweight tool with more flexibility in terms of setting it up compared to alternatives such as ELK.
In the case of Elasticsearch, multiple separate components are needed. However, in the case of Graylog Enterprise, there was only one binary that we used to install on the machines.
Graylog Enterprise has positively impacted my organization by enhancing visibility through improved monitoring capabilities and getting logs from all the machines, which contributed to enhanced visibility and monitoring. We had over 500 virtual machines, and monitoring the logs by going to each virtual machine was tedious in the past. With Graylog, all the logs from those 500 machines were centralized in one Graylog Enterprise system. From there, it was very easy to query the logs and see the patterns, and thus the monitoring was significantly enhanced.
With Graylog Enterprise, monitoring improved by up to 80 percent because of having all the logs centralized. Users or engineers would not have to SSH on each node to see the logs, meaning monitoring or visibility got improved by 80 percent or more.
What needs improvement?
The documentation for Graylog Enterprise can be improved, as this has been a pain point.
I think the visualization aspect of Graylog Enterprise can be made more rich, similar to what we have in Grafana . If upgrades could be made more smooth, as we encountered fragile upgrades while doing upgrades in the past, then I think that could be great.
For how long have I used the solution?
I used Graylog Enterprise in the past for one year.
What do I think about the stability of the solution?
Graylog Enterprise is stable.
How are customer service and support?
The customer support for Graylog Enterprise was good and responsive.
Which solution did I use previously and why did I switch?
I previously used Splunk and ELK as well, but they were with a different employer. It was never a situation where Graylog Enterprise was introduced as a replacement for other tools; the employer I was talking about was primarily using it.
What's my experience with pricing, setup cost, and licensing?
I am not sure about the pricing, setup cost, and licensing because that was dealt with by a different team that handled the licensing and procurement.
Which other solutions did I evaluate?
No options were evaluated before choosing Graylog Enterprise.
What other advice do I have?
I would say it depends on the scenario. If you have logs and want to have an easier setup, then Graylog Enterprise is the best choice. However, if you go towards a more complex architecture, then you could use other options such as ELK or Splunk. Graylog Enterprise, as far as logging is concerned, in terms of a small-scale setup and ease of use, is the best choice to go with. My overall rating for Graylog Enterprise is 7 out of 10 because of its flexibility and lightweight nature.
The advice I would give to others looking into using Graylog Enterprise is to ensure that the data they are collecting is actually in a proper format so that it can be viewed more clearly within Graylog Enterprise's interface, focusing on the formatting of the data.
Log analysis has become clearer and faster but visualization and extensibility still need work
What is our primary use case?
We are working with Splunk Enterprise Security . I use it in the company. I am only using this Splunk product.
What is most valuable?
It is easier to find some issues, and if I find some issues, then it is easier to resolve them. It is not so difficult.
We stopped using Graylog Enterprise because we found some issues with logs that came through, and they were too difficult to parse. We saw that it was better to use Splunk. It is better because it has an analysis algorithm and can also draw graphics with some help with this. To use Graylog Enterprise , we needed to import another system that collects and correlates the logs to see the statistics.
I did not find the alerting systems in Graylog Enterprise adequate to maintain operational efficiency. It was acceptable, but our company is developing, so we needed to improve and see different analysis and different ways to see the data. For this reason, we decided to buy a new SIEM platform where we could improve some additional features.
What needs improvement?
The problem was with the complexity and the cost to add extensions. We found this very expensive to buy another version with additional features.
I think that Graylog Enterprise does not have customizable dashboards. I did not see them in Graylog Enterprise because most of the time we used the open source free version, which is limited.
I think Graylog Enterprise should improve some things that they have in the paid version and perhaps provide users with a menu that gives examples of parsing logs and draws graphics so that people do not need to improve another system such as Grafana . This would be interesting.
When it comes to functionalities, I found the log management in Graylog Enterprise acceptable. It is very simple to use and to collect logs. It has support for different protocols and different ports, and the sidecar is easy to use. However, in visualization, I think it needs to be much better.
For how long have I used the solution?
I have been working with Graylog Enterprise for about two to three years.
How are customer service and support?
I never contacted technical support by Graylog Enterprise.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
We stopped work with Graylog Enterprise and now we use another SIEM platform. We do not use Graylog Enterprise anymore. We stopped using Graylog Enterprise and switched to Splunk about seven to eight months ago.
Which other solutions did I evaluate?
We also tried Wazuh and QRadar.
What other advice do I have?
We are now working with Splunk and Wazuh . We used Graylog Enterprise for log management. I did not utilize Graylog Enterprise's advanced search capabilities. When we installed and used Graylog Enterprise, it was sufficient. If I were to give a mark, it would be around seven to eight, or perhaps 7.5. We only used Graylog Enterprise for log management, and for this, I did not use anything. All that I did was manually follow the logs, take them manually, and do some parsing to see them in a better way. I think for this open source product with limited features, for a middle-sized company, it would be around nine, or perhaps even ten. I would rate this review a 7.5 overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized logs have streamlined deployment validation and simplified daily troubleshooting
What is our primary use case?
We have various environments, including UAT, SIT, Dev, and Production, with automated deployments. We refer to Graylog Enterprise to verify if deployments have completed, check their status if they have failed, and determine what version is currently running.
Some team members from the QA team are unable to see the exact version or the newer version. We use Graylog Enterprise to check if the deployment is done, identify what version has been deployed, and determine on what date the environment was updated.
We provide variables to fit in the relevant section and select the appropriate one, such as the environment and what we need to check. This is the main feature I appreciate about Graylog Enterprise. Whatever we select, such as the database name or environment name, all the information appears, including the date of the last deployment and related details.
Troubleshooting is straightforward with Graylog Enterprise. Whenever we encounter an issue, whether from the QA team or other team members, we use it to troubleshoot the specific problem and implement a fix.
During deployments, we fix issues as quickly as possible using Graylog Enterprise. When team members from the QA team inform us that something is not working or an environment is down, we access Graylog Enterprise to verify if the deployment has been completed and check exactly what version is running.
We receive approximately 15 to 16 daily requests, and we resolve them through Graylog Enterprise.
What is most valuable?
We have been using Graylog Enterprise for the last two years. Graylog Enterprise is deployed in our organization as a private cloud solution.
What needs improvement?
There are many other applications in the market that influenced my rating reduction.
Centralized logging has improved alerting and simplifies identifying issues across services
What is our primary use case?
Graylog Enterprise is the logging and management tool we initially used, but later we stopped using it and switched to Loki, Grafana Loki