Discover seamless log management through the official rsyslog solution. Experience robust AWS-integrated tools alongside a user-friendly Admin Interface. Benefit from expert support from Adiscon, the driving force behind rsyslog. Elevate your log management experience today.
Revolutionize your approach to working with rsyslog with unprecedented simplicity. Bid farewell to the complexities of tinkering with configuration files and deciphering intricate documentation. Our AWS Marketplace app redefines user experience, prioritizing seamless functionality while maintaining peak performance even on budget-friendly instance types. Our commitment is to ensure effortless setup, complemented by an integrated cloud formation file.
Upon installation, a harmonious orchestration begins: logs are effortlessly collected, superfluous noise is effortlessly sieved out, and a robust daily backup to S3 becomes an automatic routine. But this is just the beginning; should your needs evolve, our app offers a spectrum of enhanced configuration options to explore.
Our approach thrives on user engagement. Drawing from over two decades of innovation, we've molded our development journey based on invaluable user feedback, continuously integrating novel features that enrich the experience for all patrons.
At the heart of our offering lies our position as the pioneering architects of rsyslog. Our profound understanding, amassed through years of dedication, empowers us to fine-tune performance and functionalities. Beyond the app, our professional services extend our insights, shaped by engagements with a plethora of prominent organizations. Today, whether you're a burgeoning startup or a conglomerate giant, our wealth of knowledge is now conveniently available on AWS, providing you with robust and intuitive logging capabilities of the utmost caliber.
Highlights
Straight from the rsyslog developers. Special requests? We're here to tailor solutions for you.
Effortless, out-of-the-box log management, easily configured via a user-friendly interface.
Achieve cost savings through integrated cloud expenses and product support. Benefit from minimal system resource usage, thanks to our optimized configuration. Trust in our expertise to maximize your rsyslog experience
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 7 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for the rsyslog server based on the EC2 instance size you choose. The 21 dimensions are all instance types across two families, t2 and t3/t3a, running the same software. They range from nano and micro sizes up to 2xlarge. Larger instances give you more compute and memory capacity, so your hourly rate scales with the size you select. There are no tiers or feature differences between dimensions — pricing depends only on the instance you run. You can start and stop as needed, since billing is usage-based.
Top-of-mind questions for buyers
What software runs on each instance, and what does the rsyslog server do?
Each instance runs an rsyslog server, a log collection service. It receives log messages from syslog-capable devices and systems, then processes and stores them centrally. The software is identical across all instance types; only the compute and memory capacity of the underlying instance changes.
Am I charged when I stop or pause an instance?
Billing meters running instance-hours. When you stop or pause an instance, the hourly software charge stops accruing. Restarting resumes charges. Stopped instances may still incur underlying AWS storage fees for attached volumes, but the software licence meters running time only.
How do I choose between the t2, t3, and t3a instance families?
All three families run the same rsyslog server software. They differ in underlying compute architecture and hourly rate. Within each family, sizes range from nano up to 2xlarge, giving more CPU and memory as size increases. Pick the size that matches your expected log volume.
www.adiscon.com
Helpful?
Vendor refund policy
If you decide to cancel your subscription within the first 7 days after your purchase, Adiscon will not charge you for the application. You are entitled to a full refund during this period.
After the initial 7-day period, Adiscon does not offer refunds for subscription cancellations. However, you retain the freedom to terminate your application usage at any time.
Hourly Charging:
Please note that we utilize hourly charging for our services.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
"Revolutionize your approach to working with rsyslog with unprecedented simplicity. Bid farewell to the complexities of tinkering with configuration files and deciphering intricate documentation. Our AWS Marketplace app redefines user experience, prioritizing seamless functionality while maintaining peak performance even on budget-friendly instance types. Our commitment is to ensure effortless setup, complemented by an integrated cloud formation file.
Upon installation, a harmonious orchestration begins: logs are effortlessly collected, superfluous noise is effortlessly sieved out, and a robust daily backup to S3 becomes an automatic routine. But this is just the beginning; should your needs evolve, our app offers a spectrum of enhanced configuration options to explore.
Our approach thrives on user engagement. Drawing from over two decades of innovation, we've molded our development journey based on invaluable user feedback, continuously integrating novel features that enrich the experience for all patrons.
At the heart of our offering lies our position as the pioneering architects of rsyslog. Our profound understanding, amassed through years of dedication, empowers us to fine-tune performance and functionalities. Beyond the app, our professional services extend our insights, shaped by engagements with a plethora of prominent organizations. Today, whether you're a burgeoning startup or a conglomerate giant, our wealth of knowledge is now conveniently available on AWS, providing you with robust and intuitive logging capabilities of the utmost caliber."
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Version release notes
We are excited to announce the second public release of Rsyslog Server on AWS Marketplace. This version includes efficient logging, noise event filtering, and a streamlined web interface for system management. New features: Cloudwatch LogGroups, logfile compression, S3 log/config storage, enhanced CloudFormation support, and improved AWS region handling. Experience enhanced logging capabilities and simplified management with Rsyslog Server.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Automatic collection of logs with built-in noise filtering capabilities
Cloud Storage Integration
Automated daily backup of logs to Amazon S3
Configuration Management
User-friendly administrative interface for log management configuration without manual file editing
CloudFormation Support
Integrated CloudFormation template for streamlined deployment and infrastructure setup
Resource Optimization
Optimized performance on budget-friendly instance types with minimal system resource consumption
Anomaly Detection
Native anomaly detectors that identify credential compromise and data exfiltration patterns using AI-powered analysis.
Pre-built Security Alerts and Dashboards
68 pre-built alerts and 7 dashboards across 7 threat domains for immediate threat detection capabilities.
Cloud Log Collection
Native integration with AWS services including CloudTrail, CloudWatch, VPC Flow Logs, and Security Hub with selective retrieval and filtered input capabilities.
High-Performance Log Search
Ability to search and filter terabytes of log data in milliseconds for rapid troubleshooting and incident response.
Automated Investigation Workflows
Automated investigation workflows that build from asset risk thresholds with AI-assisted reporting for streamlined threat analysis.
Real-Time Anomaly Detection
Unsupervised machine learning models train on every metric at the edge, scoring anomalies in real time with no configuration required.
Network Topology and Traffic Analysis
Live topology maps built from LLDP, CDP, BGP, and OSPF protocols; NetFlow v5/v7/v9, IPFIX, and sFlow v5 analysis with top talkers and Sankey diagrams; SNMP device auto-discovery across 200+ vendor profiles with trap receiver decoding 150,000+ trap definitions from 800+ vendors.
Per-Second Metrics Collection
Collects and processes per-second granularity metrics across 850+ auto-discovered integrations covering operating systems, Kubernetes, databases, web servers, message brokers, and AWS services.
AI-Powered Root Cause Analysis
One-click AI investigation on every alert that returns root-cause hypothesis with supporting evidence; generates alert configurations from plain English descriptions and back-tests against historical data.
Edge-Based Data Processing
Metrics are stored and processed on infrastructure with only views streaming to cloud; supports eBPF and OpenTelemetry ingestion with approximately 5% CPU core and 150 MiB RAM resource utilization on typical production systems.
Centralized logging has transformed infrastructure monitoring and supports proactive recovery
Reviewed on Aug 03, 2026
Review from a verified AWS customer
What is our primary use case?
My main use case for rsyslog server is that it's a logging system for Unix and Linux that collects, stores, and filters logs from various devices, which means I'm working with infrastructure, VMware, and security, something that has been around ever since Unix was established. I pull system logs to see what's going on in systems around the Unix environment and outside of it.
A quick specific example of how I use rsyslog server in my daily work is through centralized logging, where it collects data from Linux servers, Unix servers such as Solaris and AIX, network devices, firewalls, storage arrays, and VMware hosts, pulling logs from everything the Unix and Linux hosts are connected to. These days, it's also used considerably with security, similar to Splunk or Azure Sentinel, and definitely for compliance and audit retention for HIPAA and disaster recovery logs.
I have additional information about my main use case regarding how I use rsyslog server day to day, especially with disaster recovery, as I can track failover events and replication issues when working with tools such as Zerto, addressing kernel issues specifically related to the Unix and Linux servers themselves.
rsyslog server is commonly used for many things in my work, including disaster recovery event tracking, storage arrays such as Dell EMC, NetApp, Pure, and security compliance logging, as well as VMware ESXi host logging.
What is most valuable?
The best features that rsyslog server offers include the ability to filter, tag, and rewrite logs, with logs stored in databases and files, then forwarded to various destinations such as SIEM or files as needed. Of course, the client sends the logs.
Out of those features, I find myself relying most heavily on the logging capabilities it pulls from everything that is connected to Unix or Linux boxes, allowing me to see any particular issues or errors that may be occurring. The logs are stored in files or databases and they can be forwarded to me, even emailed directly.
rsyslog server has positively impacted my organization, particularly with disaster recovery logging, where alerts for failures allow me to see failover events and any replication issues, especially within managed healthcare environments. It can indeed be used for HIPAA, pulling data from the entire infrastructure including Unix and Linux servers, network devices, firewalls, and storage arrays.
Regarding how rsyslog server has improved efficiency and compliance, it provides insight into what's happening within the infrastructure as a high-performance systems log daemon receiving logs from the entirety of the network through UDP and TCP, writing to files, databases, or SIEM systems. It's user-friendly for Unix and Linux admins or engineers because it's been familiar for so long, and it certainly is not outdated.
What needs improvement?
rsyslog server is performing wonderfully now, especially with AI automation utilizing syslog data, similar to tools such as Juniper's Mist and Azure Monitor's AI insights. This classic tool integral to Unix and Linux systems is now harmonized with AI, predicting potential failures, triggering automated remediations, and reducing alert noise while correlating events across systems.
For how long have I used the solution?
I have been working with rsyslog server for well over fifteen years.
What do I think about the stability of the solution?
rsyslog server is absolutely stable, particularly when it runs on well-known Unix and Linux distributions, especially stable ones such as AIX, making the stability a given from the start as I'm receiving syslogs from reliable systems.
What do I think about the scalability of the solution?
I find rsyslog server to be highly scalable, capable of expanding alongside the infrastructure while pulling data from multiple areas including virtualization and storage arrays, as well as Unix and Linux servers and firewalls.
rsyslog server's scalability is exceptional, as it can be implemented across infrastructure setups, pulling data from virtualization, various storage arrays, Unix and Linux servers, and firewalls.
How are customer service and support?
Customer support largely depends on the Unix or Linux server provider; for example, Red Hat has notable support, and HP or IBM also offer reliable help.
Which solution did I use previously and why did I switch?
I did not evaluate other options before choosing rsyslog server because it automatically comes included with Unix and Linux servers.
How was the initial setup?
I have always looked at system logs within Unix and Linux because they come integrated with the OS, offering stability that makes it a default solution, even if other tools were available. Setting up a dedicated rsyslog server enhances that efficiency further.
What about the implementation team?
I currently do not have a business relationship with the vendor beyond being a customer; the syslog is inherently part of the Unix and Linux servers, which comes ready for use.
What was our ROI?
I have seen a return on investment by making use of syslogs, which helps predict anomalies in server environments and storage systems. For instance, alerts from tools such as Pure or Dell EMC, and reporting replication issues from Zerto or similar applications, always provide immediate notifications that are essential for IT operations.
What's my experience with pricing, setup cost, and licensing?
I did not purchase rsyslog server through the AWS Marketplace when I used it in a hybrid setup with AWS.
What other advice do I have?
I give rsyslog server a rating of ten out of ten. The reason is that long before we focused so heavily on cloud technologies, the Unix world had a robust system to look into the logs, revealing what's going on within those servers and databases. My experience with Unix systems shows that most Unix or Linux servers contain databases, marking it as an absolute ten in functionality; it's as relevant today as it ever was.
rsyslog server's AI capabilities depict it as a data pipeline feeding AI systems, working hand in hand with AI for anomaly detection, ops automation, and log analysis through the collected syslog data. This allows for AI model analysis of logs, detecting unusual patterns, suspicious firewall events, and potential disaster recovery replication anomalies or storage errors predicting failure. There is immense potential in processing those rsyslog events filtered through AI.
The accuracy of rsyslog server's output is very high, as is its reliability. This is due to its ability to pull crucial data from infrastructure and connected servers. When using AI-driven anomaly detection tools such as Azure Sentinel or Splunk's toolkit, I can pinpoint a variety of issues from replication lag and network anomalies to VMware host instability, maintaining a high level of stability and reliability through my use.
The fact that rsyslog server can pull from the entire infrastructure speaks volumes for its capabilities. Being a part of the Unix and Linux OS, I can easily log in and examine syslog logs, piping data to the screen or receiving it via email to monitor server activities. In terms of improvements, it has been extended to analyze Azure Sentinel pipelines or firewall logs, enhancing security compliance through a comprehensive look at various systems' logs.
I would advise others considering rsyslog server to realize that those who have Unix or Linux systems are already using it, as introducing AI utilization to pipe our syslogs offers significant operational advantages. It undeniably simplifies processes across IT.
To summarize my additional thoughts about rsyslog server, it acts as a centralized logging system utilized within Unix and Linux environments, collecting, filtering, and forwarding logs from multiple devices including storage, VMware, and cloud security for disaster recovery. Using AI enhances its functionality, allowing for smarter log filtering and management. My overall review rating for rsyslog server is ten out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Ms Ms
Centralized logging has simplified daily syslog collection and routing across diverse servers
Reviewed on Jun 09, 2026
Review provided by PeerSpot
What is our primary use case?
My main use case for rsyslog server is syslogging. A quick, specific example of how I use it for logging is collecting any syslog from a Unix server, including syslogs from firewalls and routers.
What is most valuable?
The best feature rsyslog server offers is syslog recording. What I appreciate about the syslog recording feature is that it serves as the main and most important feature, recording syslogs and receiving syslogs from TCP or UDP, other UDP servers, and forwarding those logs to even other servers, allowing for daily syslog handling in any direction, TCP, UDP, local, or remote.
rsyslog server has had the usual impact on my organization; it does not matter to me if it is rsyslog server or another syslog server; it is just my preference, and I do not have specific reasons why it became this preference. There has been just personal preference in noticeable differences in reliability, performance, or troubleshooting since I have used rsyslog server compared to others.
What needs improvement?
rsyslog server can be improved; I wish it did something different or better, specifically regarding BRP.
For how long have I used the solution?
I have been using rsyslog server for more than five years.
What do I think about the stability of the solution?
rsyslog server is stable; it is more than stable enough for me.
What do I think about the scalability of the solution?
rsyslog server's scalability is good; it handles growing workloads well for me.
How are customer service and support?
I have never reached out to customer support.
Which solution did I use previously and why did I switch?
I previously used the old syslog from Debian GNU/Linux before choosing rsyslog server.
How was the initial setup?
I did not purchase rsyslog server through the AWS Marketplace. My experience with pricing, setup cost, and licensing is that I have never licensed rsyslog server, as it is open source, so the question does not make sense.
What was our ROI?
I have not seen a return on investment; it is just about functionality for me.
Which other solutions did I evaluate?
I did not evaluate other options before choosing rsyslog server. It was the next choice at hand.
What other advice do I have?
That is all for me regarding features, flexibility, or ease of use. I rate rsyslog server an eight on a scale of one to ten because I am mostly happy, but sometimes it does not work immediately, and I have to work with the logs to figure out what is happening. Regarding rsyslog server's AI capabilities, I think about its governance and security. I do not care for AI in rsyslog server ensuring its accuracy and reliability of output. I have no specific advice for others looking into using rsyslog server other than to follow the usual Google setup and be happy.
Our primary use case for rsyslog server is centralized log collection, long-term retention, and security monitoring. We also use it as an intermediate logging layer before forwarding logs to our CrowdStrike Falcon cloud platform for XDR and MDR analysis.
We built an automated pipeline where firewall devices send logs to rsyslog server, which then processes, stores, and forwards the logs to CrowdStrike Falcon. This helps us detect abnormal firewall activity, suspicious traffic, and security-related events in near real time.
The solution is also valuable for historical investigations because it allows us to retain logs locally for root cause analysis and back-dated event reviews.
How has it helped my organization?
rsyslog server has significantly improved our firewall visibility, centralized monitoring, and overall security operations. Before implementing centralized logging, visibility into inbound and outbound firewall activity was limited.
After integrating rsyslog into our environment, we gained better insight into traffic behavior, firewall policy usage, and potential security issues. This helped us improve firewall rules, reduce unnecessary open ports, strengthen outbound connectivity controls, and accelerate troubleshooting and forensic investigations.
What is most valuable?
The best features of rsyslog server are its support for both UDP and TCP log ingestion, flexible log routing, self-hosting capability, log rotation management, and reliable buffering and forwarding features.
These capabilities are essential in our environment because our firewalls generate a large volume of logs every day. Proper log rotation prevents files from becoming too large and difficult to analyze during investigations.
Another major advantage is the ability to offload buffering, retries, forwarding, and parsing from the firewall itself. This reduces firewall workload while ensuring logs are securely stored and available for future analysis.
What needs improvement?
One area that could be improved is native support for Docker and Kubernetes container logging. While integration is possible, forwarding container logs into XDR or MDR platforms often requires additional customization.
Simplified cloud-native integrations and easier container log management would make the solution more efficient for modern environments.
For how long have I used the solution?
I have been using rsyslog server for approximately two and a half years for centralized log collection, retention, and security analysis.
What do I think about the stability of the solution?
Yes, rsyslog server has been very stable in our environment. It handles large log volumes reliably without major operational issues. Restarting services, rotating logs, and maintaining long-term retention have all been straightforward and dependable.
What do I think about the scalability of the solution?
The scalability of rsyslog server has been excellent in our environment. It handles multiple gigabytes of firewall and infrastructure log data efficiently without performance issues, even as our logging requirements continue to grow.
How are customer service and support?
I have not needed to reach out for customer support concerning rsyslog server
Which solution did I use previously and why did I switch?
I did not use another centralized logging solution before rsyslog server. We implemented it based on organizational requirements, and it has proven to be reliable and highly effective for our environment.
How was the initial setup?
The initial setup was straightforward in our environment. We configured the firewall devices to forward web filtering, DNS filtering, and application filtering logs to the rsyslog server using the server’s IP address for centralized log ingestion.
On the rsyslog side, we created separate log collection files and routing rules so that firewall logs are stored independently for easier analysis and troubleshooting. We also implemented automated daily log rotation and compression of older log files for long-term retention and future forensic investigations.
What about the implementation team?
No, we handled the deployment and implementation internally without using an external integrator or consultant. The setup and configuration process was manageable with in-house Linux and firewall administration knowledge.
What was our ROI?
The initial setup was straightforward. We configured the firewall devices to forward web filtering, DNS filtering, and application filtering logs to the rsyslog server.
On the rsyslog side, we created separate log collection files and automated daily log rotation with compression of older logs for future investigations and retention management.
What's my experience with pricing, setup cost, and licensing?
Our experience with pricing and setup has been very positive because rsyslog is open-source and highly flexible. The deployment and maintenance costs were minimal compared to commercial logging platforms.
Which other solutions did I evaluate?
Before choosing rsyslog server, we evaluated Datadog. However, we preferred rsyslog because it provided a cost-effective and flexible self-hosted solution for centralized log collection and investigation without depending heavily on third-party licensing costs.
What other advice do I have?
I would rate rsyslog server 10 out of 10 for centralized logging, log forwarding, and long-term forensic analysis.
For organizations considering rsyslog server, I highly recommend it because it is stable, scalable, lightweight, and highly effective for firewall and infrastructure log management.
reviewer2843073
Logging has simplified daily troubleshooting and has improved monitoring for network devices
Reviewed on May 19, 2026
Review provided by PeerSpot
What is our primary use case?
The main purpose of rsyslog server is collecting logs from network devices and storing them on a server for monitoring.
What is most valuable?
The best feature of rsyslog server is easy configuration, which includes straightforward setup and quick monitoring of the logs.
The easy configuration and quick monitoring of rsyslog server help me in my day-to-day work as it saves my time and makes my troubleshooting easier. Once I configure the details in rsyslog.conf and restart rsyslog server, I can quickly access the information, which is very useful for troubleshooting purposes.
What needs improvement?
Based on my understanding, there are no pain points or negative aspects regarding rsyslog server; all aspects are positive.
For how long have I used the solution?
I have been using rsyslog server for more than six years.
What do I think about the stability of the solution?
rsyslog server is stable.
What do I think about the scalability of the solution?
The scalability of rsyslog server is good, as I can perform housekeeping and delete old log files that are generated and stored.
How are customer service and support?
I have not faced any issues with customer support and have not raised any support requests.
Which solution did I use previously and why did I switch?
I have not used any different solution for monitoring these network device logs; I am using only rsyslog server.
How was the initial setup?
I manually configured the rsyslog.conf on a server, and there is no licensing for rsyslog server. Splunk, in contrast, uses licensing based on daily data ingestion volume, which relates to the indexing count of the logs in Splunk.
Which other solutions did I evaluate?
I have not evaluated any other options, as rsyslog server is the only solution I use for monitoring logs from network devices.
What other advice do I have?
My advice for others looking into using rsyslog server is that it is easy to use and configure. Once the network device parameters are configured in rsyslog.conf, I can easily monitor the log files, which are useful for troubleshooting purposes. I would rate this product a 9 out of 10.
Siddesha Nc
Centralized logging has improved troubleshooting and supports fast audits across all servers
Reviewed on May 17, 2026
Review provided by PeerSpot
What is our primary use case?
My main use case for rsyslog server is resending logs to my log server from other servers, and I am redirecting logs from regular servers to one log server.
For resending logs using rsyslog server, I configure one server and enable it on the Ubuntu machine to which I redirect all servers' logs. I enable UDP and TCP for the logs in a firewall, and then on end machines such as servers, I go to rsyslog and enable it. After that, I configure the IPs from the client machine, meaning the server machine, to rsyslog server.
I use rsyslog server exclusively for this purpose.
What is most valuable?
In my opinion, the best features rsyslog server offers include the ability to send enormous logs from client OS to server devices, which I can fix with scripts. I can easily identify the host machine and what kind of logs it contains, whether it is an application log or operation log, and it sorts them based on how I write the script, allowing it to redirect and resend the logs.
These features make my day-to-day work easier and more efficient because whenever I find any failure or boot problems in a client machine, I can easily identify the issue. I can go to the log machine and check what kind of problem it is, whether it is a web server crash or a main server crash, and based on the logs and messages, I can easily identify and troubleshoot the issues. Furthermore, I can monitor and audit the logs as well, including SSH logins, and track who last logged in and who is currently logged in on the machines, as well as easily track any failed login attempts in case of suspicious activities.
rsyslog server has positively impacted my organization by providing centralized logging for our machines. I implemented it for the servers, database, application servers, and some network devices as well. I get day-to-day logs, which I can monitor easily and audit those devices, impacting our day-to-day productivity.
What needs improvement?
Currently, I use rsyslog server, but I think some features could be improved by going through other SIEM tools or IBM tools. I am using Splunk for this purpose; I have installed a Splunk agent in the client application, which allows me to redirect the same functionality I need in my daily operations.
For how long have I used the solution?
I have been using rsyslog server for more than a year.
What do I think about the stability of the solution?
rsyslog server is stable in my experience.
What do I think about the scalability of the solution?
Regarding scalability, rsyslog server can handle increased loads or more devices easily.
How are customer service and support?
Customer support for rsyslog server has not been needed since I maintain everything myself. If anything happens, I am responsible for finding and fixing the issues; therefore, there is no need to reach out for customer service.
Which solution did I use previously and why did I switch?
I did not previously use a different solution before rsyslog server; I have always been using rsyslog.
What was our ROI?
I have seen zero return on investment with rsyslog server as it is an open-source tool. I just download it and do scripting for the kind of logs I want, and it is very easy to configure without any associated costs.
What's my experience with pricing, setup cost, and licensing?
I am not getting any pricing, setup cost, or licensing related to rsyslog server; I am just using it as is.
Which other solutions did I evaluate?
Before choosing rsyslog server, I evaluated options such as Splunk and some SIEM tools such as Graylog or IBM QRadar, but those were licensed. I cannot use them without going through enterprise purchases, which are financially prohibitive.
What other advice do I have?
I can share specific outcomes regarding rsyslog server, as it has saved me time and improved my ability to respond to issues. Recently, I encountered a problem where my SSH server was down automatically, which caused some users to be unable to log in. From that log, I checked and found critical bugs in SSH, allowing me to troubleshoot the issue within a short amount of time.
My advice for others looking into using rsyslog server is that if someone wants to set up a local environment with a budget-friendly approach, they should choose rsyslog server. If they have ten to fifteen machines in their cloud or private cloud, they can use rsyslog server without issues, making it easier to improve their daily productivity. I would rate this product nine out of ten.