What’s new in Graylog 3.0?

Why Centralized Logging?

Debugging

Debugging

Debugging (2)

Murder Mystery

Security (1)

A theme in this article will be: "what separates standard incidents from horrifying nightmares?"

A good or bad story around logging will dictate the rest of the incident.

Security (2)

I recommend that any security or infrastructure team putting off a comprehensive approach to logging drop nearly everything to invest in it.

Security (3)

A10:2017 Insufficient Logging & Monitoring

Exploitation of insufficient logging and monitoring is the bedrock of nearly every major incident.

Graylog

  • Open source log management platform

  • Built for security and operations

  • Easy to set up, powerful features

  • Extensible via plugins

Graylog πŸ’Έ

  • Commercial plugins (Audit log, Archiving, Reporting, Views)

  • Professional support

  • Link: Graylog Enterprise

Inputs

  • GELF

  • Beats (Filebeat, Metricbeat, etc.)

  • Syslog

  • CEF

  • Netflow (v5 and v9)

Inputs (community)

πŸ’₯ Graylog 3.0

πŸ’₯ Graylog Sidecar

  • Centralized config management for log shippers

  • Completely new implementation

  • Allows managing arbitrary binaries

  • Runs on Linux & Windows

πŸ’₯ Grok Editor

  • Grok == Regular Expressions on Steroids

  • Sometimes hard to debug

  • No more external Grok Debugger

  • Grok editor now with preview and test

πŸ’₯ Content Packs 2.0

  • Sharing configuration between Graylog clusters

  • Allow using parameters

  • Versioning

  • Removal (uninstall)

πŸ’₯ Views πŸ’Έ

  • Interactive dashboards

  • Completely customizable

  • Can be saved and shared

πŸ’₯ Reporting πŸ’Έ

  • For your management team πŸ˜‰

  • Create shiny reports (PDF)

  • Allows scheduling of report creation

  • Reports can automatically be sent via email

What’s in a Graylog cluster?

  • Graylog

  • Elasticsearch 5.6 or higher

  • MongoDB 2.4 or higher

  • Optional: Graylog Collector Sidecar

Live Demo 😱

Questions? πŸ€”

Contact Details

Yoshi

– – –

Image Credits