
Scalyr offers support for a variety of protocols and data sources to be aggregated together quite easily. The agent is quick and offers solid performance even under a lot of load. It also has a lot of plugins and can even accept custom-developed plugins.
The UI allows for the flexibility of searching on whatever fields are being input, which is convenient for mixed streams. The service handles a large amount of data very well and is very configurable on parsing, with a syntax that makes sense and is easy to use. It even has a built-in parsing tester that is extremely convenient. Everything in the UI also feels very snappy and quick compared to other services, even when generating massive graphs.
When there's issues with the service, they are well communicated and usually brief. Review collected by and hosted on G2.com.
Scalyr definitely feels like a new product, with rough edges and some limitations that I hope are going to be worked around soon.
Graph creation is difficult and a little limited, the syntax is strange. Alarms are similarly a little awkward to put together at first.
I've had trouble with the Docker integration when used with Swarm. It doesn't seem to work unless I tie it together manually using Syslog.
A few areas have a little bit of a confusing GUI flow, between JSON files and normal UI.
The aggregation of fields and their "most common occurrences" can be sometimes frustrating when I want to search for entries that have occurred very few times, but this can usually be worked around.
Support has sometimes been slow to respond or keep up on support requests.
Graphs are sometimes "spiky", due to a mismatch between log pickup periods and log display periods. If you see this, set your graphs to a bar with a 5-minute period or more. Review collected by and hosted on G2.com.