Overview
Graylog Security is SIEM Done Right Not your typical SIEM, Graylog Security combines the key features and capabilities of SIEM, security analytics, incident investigation, and anomaly detection to your IT security analysts monitor, detect, and respond to potential cyber incidents faster while mitigating risks caused by insider threats and credential-based attacks.
Graylog Operations is Log Management Done Right Graylog Operations offers a fast and scalable centralized log management solution that uses your data to provide increased visibility into day-to-day operations so your IT, Network, and DevOps professionals can quickly identify the challenges that negatively impact performance and business continuity.
Graylog is a unique and innovative solution that helps organizations monitor, investigate, hunt for, and respond to security and operations threats more effectively. What sets Graylog apart from other SIEM and log management solutions is its unparalleled ability to explore data, not just write structured queries. Here are the top 5 reasons why our customers love Graylog:
-
GREAT ANALYST EXPERIENCE: Graylog's integrated approach to search, dashboards, alerts, and reports makes it incredibly easy to explore data, even when they don't know exactly what they need when they start. We emphasize sharing and reuse to maximize analyst productivity and job satisfaction.
-
ARCHITECTED FOR SPEED & SCALE: Graylog can search terabytes of data in milliseconds. Combined with our great analyst experience, this means finding cybersecurity threats, causes, and consequences quickly without requiring analysts to learn a proprietary query language.
-
LOW TCO IN CLOUD OR ON-PREM: Graylog offers customers full functionality in both cloud and on-premises deployments. This way, they can choose the approach that provides the best balance of TCO and risk for them.
-
COMPREHENSIVE, NOT OVERWHELMING: Graylog combines everything a mid-sized enterprise needs from a SIEM and threat hunting tool in a single offering without the cost, complexity, or add-ons they don't.
-
OPEN & FLEXIBLE PLATFORM: Graylog's open-source heritage, REST API, data forwarders, and use of AWS OpenSearch makes it easy to integrate into the rest of a SOC tech stack, unlike other SIEMs that charge or make it hard to get data back out.
For customized pricing, please contact us at https://go2.graylog.org/aws-contact-usÂ
Highlights
- Gain meaningful insights and answers from your event log data so your IT, DevOps, and Security professionals can identify performance and cyber issues faster, make informed decisions quicker, and improve key metrics like Mean-Time-to-Detect (MTTD) and Mean-Time-To-Respond (MTTR).
- Lightning-fast search and filter capabilities allow you to parse terabytes of log data in seconds for faster troubleshooting.
- Increase productivity with powerful automation capabilities.
Details
Unlock automation with AI agent solutions

Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
---|---|---|
Graylog Security Unit | Graylog Security | $0.001 |
Graylog Operations Unit | Graylog Operations | $0.001 |
Vendor refund policy
As defined in EULA
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
The mission of Graylog Support is to build competence, capability, and confidence in Graylog within our broad base of Customers and Partners. Your successful adoption and acceleration of Graylog as a solution within your business is a fundamental driver behind what we do and how we do it. Experience our first-class support at https://www.graylog.org/technical-support/Â .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products



Customer reviews
Robust event correlation enhances operations, yet integration scope can broaden for seamless data handling
What is our primary use case?
We describe our customers' usual use cases for Graylog as one where we use it for event correlation. We take typical IT events, and we also use it for security event correlation as well. So, both security and general IT.
We use Graylog internally in our company.
What is most valuable?
The features and capabilities of Graylog that we have found most valuable are related to its basis on open search, which was ElasticSearch. We appreciate being able to integrate custom feeds and do custom parsers, and to be able to do some of the correlation on it. That all works effectively.
The Graylog features that have proven to be most beneficial for our data analysis in particular are that we tend to use it as a big data store, so we have the correlation rules that, if something matches under certain conditions, it raises an alarm. We use it for investigating problems and problem management. We throw all the information at it, we have it alerting for certain conditions, but generally we use it for deep diving into issues as needed.
What needs improvement?
The area in Graylog that needs to be improved or enhanced would be the integrations. It would be useful to have more parsers and filters for different types of systems, which is growing, but we still find many systems that there aren't any, and we have to create our own. Having a library of parsers would help. Mainly, it's about integrations: being able to parse different sources and output to different systems easier.
For how long have I used the solution?
I have been working with Graylog for about 8 years or so. That is quite a while.
What do I think about the stability of the solution?
I rate the stability of Graylog as very stable, probably a nine out of ten.
What do I think about the scalability of the solution?
On a scale from 1 to 10, where 10 is the highest level of scalability, I would rate Graylog's scalability as an eight. I think Graylog itself is scalable, but where it needs improvement is around the underlying features of open search, particularly concerning data logs and things. More up-to-date documentation on how to do high ingestion and high search scenarios, including recommendations for configuration and deployment, would be useful.
How are customer service and support?
Regarding technical support for Graylog, I can't comment much because I've not had to use it. Even though we have the enterprise products, we've not needed to use technical support because we've been using Graylog for many years and can fix most problems ourselves. There are some sizing documents online, but they were a few years out of date when we looked a few months back.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Graylog, we had a customer running IBM QRadar , which is a big security logging platform. We used other products such as RSyslog, Kiwi Syslog, which is Windows-based, and Syslog-ng, among others.
The decision to switch to Graylog was influenced by my appreciation of its user interface. It separates out the ingestion from the backend. For instance, if Graylog is running and you take the backend down, you don't lose events. In contrast, with RSyslog, if you turn it off, you can't do backend-frontend maintenance, which is an advantage Graylog offers. It also handles clustering nicely, making it easy to scale up quickly.
How was the initial setup?
I would rate my experience with the initial setup of Graylog on a scale of 1 to 10 as probably about a five. If someone has never used Linux before, it would be very difficult, but if you're familiar with Linux and the day-to-day things behind the scenes, it's quite straightforward. The guides online are simple, follow the guide, and you've got a system that works. There could possibly be more around improving the performance, and maybe some more up-to-date calculators on sizing because some of the sizing information we've seen previously are a few years out of date.
What about the implementation team?
For maintenance, we usually need just one or two people. We have a team of three engineers who look after it, and they rotate the maintenance responsibilities every three weeks.
What was our ROI?
The return on investment or cost savings we have seen since the deployment of Graylog is primarily in time savings, allowing our security team and IT engineers quick access to information, as it all goes to one place. It makes it quite quick to find things, enabling us to retrieve the information needed to respond swiftly.
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
Evaluating other options before choosing Graylog was somewhat straightforward because we've been using it for some time and are confident with it. Originally, we recommended Graylog to a customer, but they chose QRadar, which is very expensive and didn't scale as effectively. Eventually, we put Graylog next to QRadar because QRadar couldn't keep up.
What other advice do I have?
My impression of the overall visibility of Graylog is good. In the past few years, as it's transitioning from just an open-source product into more of an enterprise solution, they're trying to grow into that area and do more in the API space. I think it will get better, particularly for orchestration pieces. That's probably its weaker area compared to some of the other products such as Microsoft Sentinel or Log Analytics, where they have more hooks into different products. I appreciate that Graylog is moving towards that, and it's quite simple to get it stood up quickly. We have used it during security incidents with customers, and we have spun up a separate Graylog instance to help them with ransomware type issues.
Graylog has supported our compliance and security monitoring activities because, for one of our customers who falls under the NIST 2 regulation due to critical infrastructure, we heavily use it for that side. However, for the rest, we don't tend to use it for compliance really. A lot of that's handled separately, so it's not really an area we do much with Graylog at the moment, but it could be something that we could do more with in the future.
Graylog is not assisting us with our AI-driven data analysis or any operations with AI at the moment, but it could be something that we could do in the future.
Currently, about 10 people are using Graylog in our company.
We have plans to use Graylog more in the future as we deploy more. We run a private cloud for different platforms, and our intention is to have all of those systems folding their events into Graylog.
Overall, I would rate Graylog at about a seven or eight. The only downside is some of the integrations; if it had more integrations, it would be easier to work with other tools. Contextually, they're transitioning from an open-source background to a more enterprise-oriented space, which understandably takes time.
Which deployment model are you using for this solution?
Facilitates backend service monitoring with efficient log retrieval and API flexibility
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What was my experience with deployment of the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
How was the initial setup?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
Which deployment model are you using for this solution?
Utilizes data adapters for seamless log management but could improve documentation
What is our primary use case?
I mostly use it for log management, log aggregation, and visualization. In my case, I am researching how to basically integrate cyber threat intelligence into open-source team systems.
Graylog is very handy. It has data adapters and lookup tables that utilize HTTP calls to APIs. I can enrich data by automating HTTP calls to a MISP instance, for example, or other threat feeds. This is basically the brunt of the work. Otherwise, normalization and parsing of logs from different sources are involved.
What is most valuable?
I would say log enrichment via these data adapters and lookup tables is valuable, especially the caching ability since Graylog doesn't always have to make API calls for every single instance if it is enriching the same value. That is very handy and makes it scalable.
What needs improvement?
When it comes to configuring the processing pipeline, writing the rules can be very tedious, especially since the documentation isn't extensive on how the functions provided for these rules work. Parsing depends heavily on regular expressions, which makes the process somewhat tedious.
For how long have I used the solution?
I have been using it for a year and a half.
What do I think about the scalability of the solution?
I haven't deployed it in a cluster, so I can't properly evaluate how scalable it is. However, since it allows for cluster redundant setups, I imagine it is theoretically pretty scalable. It is very resource-intensive. We have tried it on a single node, but in a setting where a network has thirty different clients doing search queries for insane amounts of logs, it was very slow and inefficient, even with sixteen gigabytes of RAM for that server.
How are customer service and support?
Until now, I have only used the open-source version. I haven't used Graylog Security or Enterprise, so I'm not sure if there is technical support for the open-source version.Â
Usually, if I have issues that require troubleshooting, I consult the Graylog Community. Sometimes there are solutions on the forum.
How would you rate customer service and support?
Neutral
How was the initial setup?
Configuring the SSL certificates usually takes a lot of time because I have to add the certificate to the Java keystore in a very specific format. Otherwise, it doesn't get recognized. It is not very convenient. That took me about one week to figure out.
What about the implementation team?
I am the person responsible for that.
What other advice do I have?
Graylog is a purpose-driven tool, so we don't really use it in our company. Rather, we usually deploy it for our clients. Some clients wanted it for managing logs for forensic analysis or compliance reasons, and some wanted it as a security option.Â
Some clients abandoned it. Even though it is customizable, it doesn't offer much functionality out of the box. It requires a fair amount of effort and expertise to function. Maybe if there were prebuilt dashboards or processing, like Wazuh , it could be adopted on a higher scale.Â
Overall, my rating for this product is seven out of ten.
Which deployment model are you using for this solution?
Stable solution with room for improvement in interactivity and user-friendliness
What is our primary use case?
As a bank, we use the product to collect logs from various sources, including applications, our website, and mobile applications.
What needs improvement?
Since it's a free tool, I don't have much to say. Troubleshooting is important to me. The initial setup is complex. I hope to see improvements in Graylog for more interactivity, user-friendliness, and creating alerts.
For how long have I used the solution?
I have been using this solution for the past three years, and my current version is v5.1.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The product is scalable. Currently, three individuals, myself included, use the solution in our company. We plan to increase the usage in the future.
How are customer service and support?
There is no customer service and support available for the free version of the solution.
Which solution did I use previously and why did I switch?
We have tested IBM QRadar and now use it. First of all, the key factor is the pricing. I saw that IBM QRadar has an interactive dashboard, providing valuable insights to people. Additionally, I've seen that IBM QRadar has an agent that simplifies installations across various platforms without requiring intricate configurations. Also, IBM QRadar has automatic reporting.
How was the initial setup?
The initial setup was complex. The deployment process involved server configuration, setting up alerts, and configuring the system. When upgrading from version 4.2 to 5.1, the configuration took some time.
What's my experience with pricing, setup cost, and licensing?
We are using the free version of the product. However, the paid version is expensive.
What other advice do I have?
Overall, I rate the product a six out of ten.