[Wolves] Log Analysis tools

Andy Smith andy at strugglers.net
Fri Jul 11 17:30:29 UTC 2014


Hi Simon,

On Thu, Jul 10, 2014 at 05:26:24AM -0400, Simon Burke wrote:
> Does anyone have any preference when it comes to tools for Log analysis.
> Currently I have been scripting data into a MySQL DB and using SQL to
> get some meaningful data out, but considering we're talking nearly
> 1Gb of logs a day to process this is not the best solution.

I'm not familiar with Sawmill so perhaps there is some overlap, but
the most popular open source solution in this space is Logstash plus
Elasticsearch:

    http://www.elasticsearch.org/overview/logstash/

If you have money to burn then you could instead look at the
commercial solution Splunk:

    http://www.splunk.com/ (site currently in maintenance!)

but it is very very expensive.

Here's a pair of posts I found useful in the past:

    http://jasonwilder.com/blog/2012/01/03/centralized-logging/
    http://jasonwilder.com/blog/2013/11/19/fluentd-vs-logstash/

Cheers,
Andy

-- 
http://bitfolk.com/ -- No-nonsense VPS hosting



More information about the Wolves mailing list