Syslog-ng is recognized for its proficiency in log extraction, storage, and secure TLS connections. Its efficient configuration and real-time monitoring integration make it a preferred option for large-scale log processing, ensuring compliance with regulatory standards.

| Product | Mindshare (%) |
|---|---|
| syslog-ng | 1.5% |
| Splunk Enterprise Security | 6.8% |
| Wazuh | 5.4% |
| Other | 86.3% |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| Wazuh | 3.7 | 5.4% | 81% | 50 interviewsAdd to research |
| Datadog | 4.3 | 4.0% | 97% | 208 interviewsAdd to research |
syslog-ng is open-source and free.
| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 1 |
| Large Enterprise | 3 |
| Company Size | Count |
|---|---|
| Small Business | 111 |
| Midsize Enterprise | 96 |
| Large Enterprise | 258 |
Syslog-ng offers powerful log management capabilities, accommodating complex search needs while maintaining simplicity with user-friendly documentation and real-time monitoring features. The C-style configuration enhances readability, allowing users to easily comprehend and implement changes. Designed for high performance, Syslog-ng scales effectively to handle extensive logging demands. Despite its strengths, areas for improvement include integration with protocols and filtering methods. Users advocate for better Kafka integration and a graphical configuration interface to simplify setup. While historical dissatisfaction led to custom patches, subsequent updates have addressed these concerns. Currently, users seek an advanced version to access premium functionalities.
What are the most important features of syslog-ng?Organizations frequently use syslog-ng for log aggregation, filtering, and regulatory compliance, serving as a crucial component in enterprise security audits and data regulation adherence in Brazil and Italy. By allowing logs to be stored in raw format, syslog-ng provides versatility in data manipulation and user activity tracking, making it user-friendly for installation, maintenance, and updates. Logs can be transmitted over TLS or plain text to central servers, supporting varied transmission needs.
Tecnocom, University of Victoria, University of Exeter, Datapath
| Author info | Rating | Review Summary |
|---|---|---|
| IT Infrastructure & Cloud Security Manager at Thux | 5.0 | I use syslog-ng to ensure compliance with Italian privacy laws by securely logging system administrator activity; it's easy to install, stable, and scalable, though I’d appreciate a GUI and look forward to exploring premium features. |
| Senior Software Engineer at Five9 | 5.0 | I've used syslog-ng for over 10 years due to its clear C-style configuration, excellent performance, and stability. It's easy to set up and highly effective for complex log processing without needing support. I highly recommend it. |
| Data center analyst at Atvos | 5.0 | We use syslog-ng primarily for compliance with Brazilian law enforcement, valuing its compound search capability for examining logs by time, user, or behavior. However, we see opportunities for improvement in observability and potential Kafka integration. |
| Solution Architect(Splunk- Log Management) at Tata Consultancy | 4.0 | The primary purpose of syslog-ng is to aggregate and filter logs for ingestion into Splunk. I value its separate configuration file feature, though I feel the filtering options could be improved to better fit varied logging needs. |
| Senior Director and Senior Systems Engineer (Dual Role), IT Infrastructure and Security at a financial services firm with 51-200 employees | 3.5 | I use syslog-ng to aggregate logs as a temporary replacement for a SIEM solution. It has useful built-in features for creating alerts, although it's not a true SIEM solution and requires expertise for effective use in SIEM scenarios. |
| Consultant at CITS - Centro Internacional de Tecnologia de Software | 4.0 | I use syslog-ng to automate task batches and scripts without a user interface. Its most valuable feature is log extraction and storage. However, there’s room for improvement, particularly in enhancing integration and protocol extensions. |
| CISO at LGPDNOW | 5.0 | I use syslog-ng for enterprise security audits to comply with data regulations like GDPR in Brazil. It simplifies log access and integrates for real-time monitoring, though finding knowledgeable users can be challenging due to configuration issues. |