It seems to me Logstash provides what I want, but I sure as hell won't run 3 JVMs and a Redis instance to aggregate logs.
tl;dr How to handle log aggregation within a small-scale cluster without losing your sanity?
It seems to me Logstash provides what I want, but I sure as hell won't run 3 JVMs and a Redis instance to aggregate logs.
tl;dr How to handle log aggregation within a small-scale cluster without losing your sanity?
I have been running oklog for a customer successfully. You ought to deploy it like a regular (non-cloud-native) service though: When a server crashes, restore the oklog instance from backups, not spinning a new one.
In the past have created a server just with syslog. Adjust all your servers syslog configs to point to that one. Then log in and use grep.
Not fancy. But gets the job done with a single line config change in your syslog configs.
This re-enforces my idea that a purely terminal based business dashboard might be a cool product with a fairly large market. I've been eyeballing some of the go/ncurses work for this.
I've worked with ELK before and I'm not a fan, the usability is very low compared to Splunk. It's much cheaper though. At a previous employer we switch from Splunk to ELK and the number of searches we did on a daily basis dropped to almost zero. Before that almost every support "ticket" would start with a Splunk search.
You could also try out https://www.humio.com. I only seen it deploy by one customer, but it looks nice.