We are working with Splunk Enterprise Security. I use it in the company. I am only using this Splunk product.
Graylog
Graylog, Inc.External reviews
External reviews are not included in the AWS star rating for the product.
Log analysis has become clearer and faster but visualization and extensibility still need work
What is our primary use case?
What is most valuable?
It is easier to find some issues, and if I find some issues, then it is easier to resolve them. It is not so difficult.
We stopped using Graylog Enterprise because we found some issues with logs that came through, and they were too difficult to parse. We saw that it was better to use Splunk. It is better because it has an analysis algorithm and can also draw graphics with some help with this. To use Graylog Enterprise, we needed to import another system that collects and correlates the logs to see the statistics.
I did not find the alerting systems in Graylog Enterprise adequate to maintain operational efficiency. It was acceptable, but our company is developing, so we needed to improve and see different analysis and different ways to see the data. For this reason, we decided to buy a new SIEM platform where we could improve some additional features.
What needs improvement?
The problem was with the complexity and the cost to add extensions. We found this very expensive to buy another version with additional features.
I think that Graylog Enterprise does not have customizable dashboards. I did not see them in Graylog Enterprise because most of the time we used the open source free version, which is limited.
I think Graylog Enterprise should improve some things that they have in the paid version and perhaps provide users with a menu that gives examples of parsing logs and draws graphics so that people do not need to improve another system such as Grafana. This would be interesting.
When it comes to functionalities, I found the log management in Graylog Enterprise acceptable. It is very simple to use and to collect logs. It has support for different protocols and different ports, and the sidecar is easy to use. However, in visualization, I think it needs to be much better.
For how long have I used the solution?
I have been working with Graylog Enterprise for about two to three years.
How are customer service and support?
I never contacted technical support by Graylog Enterprise.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
We stopped work with Graylog Enterprise and now we use another SIEM platform. We do not use Graylog Enterprise anymore. We stopped using Graylog Enterprise and switched to Splunk about seven to eight months ago.
Which other solutions did I evaluate?
We also tried Wazuh and QRadar.
What other advice do I have?
We are now working with Splunk and Wazuh. We used Graylog Enterprise for log management. I did not utilize Graylog Enterprise's advanced search capabilities. When we installed and used Graylog Enterprise, it was sufficient. If I were to give a mark, it would be around seven to eight, or perhaps 7.5. We only used Graylog Enterprise for log management, and for this, I did not use anything. All that I did was manually follow the logs, take them manually, and do some parsing to see them in a better way. I think for this open source product with limited features, for a middle-sized company, it would be around nine, or perhaps even ten. I would rate this review a 7.5 overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized logs have streamlined deployment validation and simplified daily troubleshooting
What is our primary use case?
We have various environments, including UAT, SIT, Dev, and Production, with automated deployments. We refer to Graylog Enterprise to verify if deployments have completed, check their status if they have failed, and determine what version is currently running.
Some team members from the QA team are unable to see the exact version or the newer version. We use Graylog Enterprise to check if the deployment is done, identify what version has been deployed, and determine on what date the environment was updated.
We provide variables to fit in the relevant section and select the appropriate one, such as the environment and what we need to check. This is the main feature I appreciate about Graylog Enterprise. Whatever we select, such as the database name or environment name, all the information appears, including the date of the last deployment and related details.
Troubleshooting is straightforward with Graylog Enterprise. Whenever we encounter an issue, whether from the QA team or other team members, we use it to troubleshoot the specific problem and implement a fix.
During deployments, we fix issues as quickly as possible using Graylog Enterprise. When team members from the QA team inform us that something is not working or an environment is down, we access Graylog Enterprise to verify if the deployment has been completed and check exactly what version is running.
We receive approximately 15 to 16 daily requests, and we resolve them through Graylog Enterprise.
What is most valuable?
We have been using Graylog Enterprise for the last two years. Graylog Enterprise is deployed in our organization as a private cloud solution.
What needs improvement?
There are many other applications in the market that influenced my rating reduction.
Centralized logging has improved alerting and simplifies identifying issues across services
What is our primary use case?
Graylog Enterprise is the logging and management tool we initially used, but later we stopped using it and switched to Loki, Grafana Loki for the logs. Eventually, we moved back to Graylog Enterprise after approximately one year.
The main use case for Graylog Enterprise is that we primarily use it for our enterprise logs. We have around 11 services, so we use it to collect all of our logs in one location. We use it for both QA and production environments.
A specific example of how we use Graylog Enterprise in our environment is that we have multiple logins for our MDM solution, a mobile device management solution. Since it is an enterprise application, we generally use Graylog to retrieve the logs and determine if there is an error or any downtime. Graylog Enterprise has been very helpful in identifying issues and is also extremely valuable for handling high-volume log throughput. The cost-effectiveness of Graylog Enterprise has been particularly beneficial to us.
What is most valuable?
The standout features that make Graylog Enterprise valuable for my team are particularly helpful for Site Reliability Engineers, IT, and DevOps security, as it delivers excellent functionality without extreme cost. Its alerting system and notification capabilities really help us, as we use Slack to receive alerts from Graylog Enterprise. Additionally, the data management and the pipeline to transform and categorize the logs as they flow in are valuable. The best feature of Graylog Enterprise is its high-performance search engine that provides fast, flexible, and scalable analysis of machine data or pod data.
When there is any error, bug, or downtime, Graylog Enterprise sends us an alert to Slack, so we can immediately investigate and find what the issue is, whether it is with the pipeline or within a service. We can determine exactly what happened and why it is causing the downtime. If we need to spin up more pods or if it needs more memory or CPU usage, we take the appropriate initiative based on that assessment.
Graylog Enterprise has positively impacted my organization by significantly minimizing our workload and making it easier to identify any issues in a service. It features good custom dashboards, visualization, and good search capability as well.
What needs improvement?
I do not have any specific examples or numbers, such as time saved or incidents to share. Currently, I have no suggestions for how Graylog Enterprise can be improved, as there are no pain points or features I wish were better.
For how long have I used the solution?
I have been working in my current field for around 2.3 years.
What other advice do I have?
Graylog Enterprise is cost-effective, but when compared with Elasticsearch, it can be more costly. I chose a rating of nine out of ten because there is not much that I would change to make it a perfect ten for me. I suggest using Graylog Enterprise, as it really helps to maintain and use everything effectively, ensuring the sustainability and health of the pods. My overall review rating for Graylog Enterprise is nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Facilitates backend service monitoring with efficient log retrieval and API flexibility
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What was my experience with deployment of the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Neutral