The Graylog Extended Log Format (GELF) is a log format that avoids the shortcomings of classic plain syslog:
- Limited to length of 1024 bytes. Inadequate space for payloads like backtraces.
- No data types in structured syslog. Numbers and strings are indistinguishable.
- The RFCs are strict enough, but there are so many syslog dialects out there that you cannot possibly parse all of them.
- No compression.
Syslog is sufficient for logging system messages of machines or network gear, while GELF is a strong choice for logging from within applications. There are libraries and appenders for many programming languages and logging frameworks, so it is easy to implement. GELF can send every exception as a log message to your Graylog cluster without complications from timeouts, connection problems, or anything that may break your application from within your logging class because GELF can be sent via UDP.
!(Graylog GELF)(https://go2docs.graylog.org/current/resources/images/logo.png)
The following configuration reads the Windows EventLog and sends it to the Graylog2 server in GELF format.
In concept nxlog is similar to syslog-ng or rsyslog but it is not limited to unix and syslog only. It supports different platforms, log sources and formats so nxlog can be an ideal choice to implement a centralized logging system.
Centralize your Windows, Unix, Linux, BSD, Android and application logs on Windows, Unix, Linux, BSD, Android.
Centralize all your log messages
- Collect terabytes of log messages
- Process in real-time
- Search and analyze in seconds