I really like Graylog for several reasons. It is easy to set up and manage, which I really appreciate because it makes it quickly operational. The interface is simple and efficient, with filters that allow you to easily find the necessary logs. The ability to easily add new servers by configuring Graylog as the log destination is a plus, as the logs are immediately forwarded. I also appreciate the volume-based licensing which allows us to only pay for what we need, and it encourages us to optimize our logs if necessary to not exceed the limit. Finally, switching from Rsyslog to Graylog has been beneficial because Graylog is better in terms of display and management, and the initial installation was super easy and fast. Review collected by and hosted on G2.com.
In the future, perhaps integrate an AI agent that will fetch the desired logs for us with a simple prompt, like 'Fetch me the unauthorized access logs on server X'. Just that, an AI agent that helps the user display specific information like 'Show me the logs of denied access by all my servers that start with PRV'. Review collected by and hosted on G2.com.