Graylog can improve the index rotation as it's quite complicated. They need to work on that because it's quite cumbersome to manage the index rotation with all the logs. The filtering of logs before ingestion also needs a bit of work. This is because you have to write some code to avoid certain things before ingesting. As it doesn't support certain AIX versions, you need to upgrade the servers to accommodate it.
It would be helpful if they would work more on the documentation because it's not very clear and ideally I'd like to be able to do more myself, but would need some additional guidelines and material for that.
I would like to see a date and time in the Graylog Grok patterns so that I can save time when searching for a log. I like how the streams and the search query work, but adding a date and time will allow me to pull out a log in a milli-second.
Hi community members,
We know it's important to conduct a trial and/or proof of concept as part of the buying process.
Do you have any advice for our community about the best way to conduct a trial or PoC? How do you conduct a trial effectively?
Are there any mistakes to avoid? Read More »
Carl PhillipsAt the risk of sounding flippant, I personally believe that the best way to… more »