Stars
Forks
Watchers
Developer links
Graylog
Trusted by over 60,000 organizations worldwide with more than 8,100 GitHub stars since 2010, Graylog has established itself as one of the fastest paths from raw log data to operational visibility, delivering centralized log management, security analytics, and compliance auditing through a purpose-built web interface with sub-second search at scale. The platform ingests logs from virtually any source via syslog, GELF, Beats, raw TCP/UDP, HTTP, CEF, IPFIX, and Netflow protocols, processing each message through configurable pipelines that parse fields, apply transformations, enrich events with GeoIP data from MaxMind or IPinfo lookup tables, and route messages to appropriate streams based on content rules. OpenSearch handles full-text indexing and storage with dynamic shard sizing that automatically calculates appropriate sizes from available node memory, while MongoDB stores configuration metadata including user accounts, roles, dashboards, alert rules, and pipeline definitions. The alerting system integrates with Slack, PagerDuty, and email with customizable notification templates and Replay Search links for immediate investigation context. Version 7.0 introduced MCP server integration for connecting preferred LLMs to perform AI-assisted log analysis and automation, while version 7.1 added Sigma detection rule import from private GitHub, GitLab, and Bitbucket repositories for detection-as-code workflows. The Sidecar agent management system centrally configures and deploys Filebeat, Winlogbeat, and nxlog collectors across infrastructure from the Graylog web interface. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. SSPL licensed.
Benefits
- Sub-Second Full-Text Search
- Query billions of log entries instantly with OpenSearch-powered full-text indexing, field-level search, boolean operators, and saved search templates for repeatable investigations.
- Pipeline Processing Engine
- Parse, enrich, filter, and route log messages in real time with configurable pipeline rules that apply GeoIP lookups, field transformations, and stream routing before storage.
- Centralized Agent Management
- Deploy and configure Filebeat, Winlogbeat, and nxlog log collectors across your entire infrastructure from the Graylog web interface using the Sidecar management system.
- AI-Assisted Log Analysis
- Connect preferred LLMs via MCP server integration for AI-powered log summarization, anomaly explanation, and automated investigation workflows introduced in version 7.0.
Features
- Multi-Protocol Log Ingestion
- Collect logs via syslog, GELF, Beats, raw TCP/UDP, HTTP, CEF, IPFIX, and Netflow with automatic field extraction and structured message parsing.
- Customizable Dashboards
- Build real-time visualization dashboards with charts, histograms, and data tables using drag-and-drop widgets with configurable time ranges and drill-down support.
- Alerting and Notifications
- Define alert conditions based on log content, field values, and aggregation thresholds with notifications to Slack, PagerDuty, email, and custom HTTP endpoints.
- Content Packs
- Accelerate deployment with prebuilt configuration packages containing dashboards, inputs, extractors, and stream rules for popular applications and infrastructure.
- Sigma Rule Integration
- Import Sigma detection rules directly from private GitHub, GitLab, and Bitbucket repositories with version control for detection-as-code security workflows.