Need some insights on syslog analyzers


 
Thread Tools Search this Thread
Operating Systems Linux Need some insights on syslog analyzers
# 1  
Old 07-27-2012
Need some insights on syslog analyzers

Hello there,

I am associated with one of the projects in a non-profit organization. We are currently in need of an open source syslog (rsyslog to be precise) analyzer which can do saved searches among other features.

One can have private or public saved searches. Private saved searches can only be accessed by a particular user of the log analyzer while public ones can be accessible by the world.

It's going to be used on the rsyslog server nodes which accumulate all kinds of syslogs from other highly loaded servers.

I currently tested with Adiscon LogAnalyzer 3.4.4 with MySQL backend, but, it does not do well while on load. One co-worker told me that they used it in another place and after 3-4 months they had to ditch it as it slow like hell. Plus, it does not do any saved searches (but, that's fine, we can manage do some php hacks).

How about logstash? Does anyone have any experience with this, or any better open source solution?
# 2  
Old 07-28-2012
Check out splunk.

Regards
Peasant.
# 3  
Old 07-30-2012
But, splunk is not Open Source, right? We are looking only for Open Source solutions.
# 4  
Old 07-31-2012
It's not under open source license.

But it's free to some extent (500 MB per day of indexing).
So if you have up to 500MB per day from any number of machines, splunk will be free.

You are not buying splunk, but how much data will splunk index per day.

And no, i'm not selling this software or nothing Smilie, just had the chance to implement it where i work, and folks who are using it are quite satisfied.
Login or Register to Ask a Question

Previous Thread | Next Thread

2 More Discussions You Might Find Interesting

1. AIX

Cannot send syslog event from AIX 6.1 to RHEL Syslog server

Hi everyone, I am trying to configure AIX 6.1 using syslogd to send syslog event to syslog server configured on RHEL. However, RHEL never receives the events. I have tried to redirect the syslog event on AIX to a local file and successful. Only forwarding to remote server fails. Firewall... (10 Replies)
Discussion started by: michael_hoang
10 Replies

2. Solaris

Which are the available entries to forward syslog in syslog.conf?

Hi Community Which are the available entries to forward syslog in syslog.conf i have put *.err;kern.debug;daemon.notice;mail.crit;user.alert;user.emerg;kern.notice;auth.notice;kern.warning @172.16.200.50 and it's not going through.giving error message like below: syslogd:... (2 Replies)
Discussion started by: bentech4u
2 Replies
Login or Register to Ask a Question