Bootstrap Based UI for Logstash (Open Source Splunk)
rashidkpc.github.com
rashidkpc.github.com
Jordan had never seen (or to my knowledge has yet to see) splunk at all. I don't know about Pete. Myself, I haven't used Splunk since trying a very early release once in the very first days of it.
Point being, Logstash doesn't call itself an "open source splunk". In fact I've considered adding an output to SplunkStorm to Logstash.
Do I think Logstash is better? Yep. Do I know people who swear by Splunk? Yep. Competition is healthy.
LogStash is a log management system, which is one application of Splunk. (There are a lot of players in this space.) And, much like Splunk, it seems to be well-fit for users who prefer to get down to the nuts and bolts. I haven't tried it yet, but I don't have a need for real LM or IT search these days, when I do - it'll be in my list of things to set up and try. I like what I've seen, but I don't see much IT search or automation here.
Disclaimer: I was the architect of a closed-source competitor to Splunk in the log management space.
I'm certainly not the first to make this comparison.
Huh? The front page of http://logstash.net/ suggests that one of the primary uses!
"logstash is a tool for managing events and logs. You can use it to collect logs, parse them, and store them for later use (like, for searching). Speaking of searching, logstash comes with a web interface for searching and drilling into all of your logs.
All your logs from all over your infrastructure in one place - with searching and graphing. Since we can easily parse text-based logs, you can query for more precise things like, all 404 http errors, nagios critical alerts in hard state, or mail server faults - all without accidentally finding logs with the word ‘404’ or ‘critical’ in the wrong place."
Logstash does come with a simple web interface, and kibana is a slightly better but still simple interface being ported into logstash. Again this is geared towards getting people up and running quickly, and at the end of the day it's just a pretty curl wrapper for elasticsearch.
You can also use logstash without elasticsearch/kibana, which we do for a good bit of our logs. I think logstash intentionally blurs the lines of what it is or isn't so people don't get caught up in trying to figure out how to get it running. Give it a try and see for yourself exactly what it is or isn't.
Be warned though that logstash is not mature software, get on the mailing list and read the github page.
Now if only the rails logging system wasn't so tightly integrated and string-happy.
The kibana ui is, afaik, being ported to ruby atm.
No knock against author intended.
What something is built with doesn't matter, that it works matters.
Graylog2, though, had problems with it's original implementation based on capped containers in MongoDB. It has since moved to ElasticSearch.
There are both gelf inputs and outputs for Logstash so you can send your logs to Logstash as if they were going to Graylog2 and do additional munging and still send them out to Graylog2 from there.
I was planning to setup Logstash next week so your input would really help. Thanks!
The Graylog2 web interface is pretty awesome and it has some neat stuff built in. Logstash ships with a fairly spartan web interface though we're going to replace it with a ruby port of Kibana in the future.
Logstash can accept data from GELF senders (via the gelf input plugin I wrote) or send to gelf receivers (like Graylog2).
Graylog2 is awesome, don't get me wrong. I just had to bail on it when it was still on MongoDB because I couldn't justify the cost of instances needed to get a MongoDB instance that could hold more than 4 hours of data.