We make this stuff harder by rebuilding functionality on top of systems that already have the functionality.
We make this stuff harder by rebuilding functionality on top of systems that already have the functionality.
The json that syslog wraps data in is actually using the same syslog protocol - nothing is chaging here. It's encapsulated within the same protocol. The only reason to unwrap json is when you need to start structuring your data for BI views, your milage may vary. The key is that these two are de-coupled.
Because you work on a basic level networking / storage layers its very easy to reason and build reliable pipelines according to your needs. As you say — you can't beat that.
PS: The pain starts when you need to deal with multiline logs like java stack traces but then you just work with devs to log everything into json.
Edit: split comment, more info
If there is log storm coming from misconfigured app depending on your traffic levels the sink servers should give you a lot of space for an on-call engineer to be notified that something is off and adjust / rate limit / drop accordingly.
Edit: udated with more info