The Graylog Extended Log Format (GELF) is a log format that avoids the shortcomings of classic plain syslog:
- Limited to length of 1024 bytes. Inadequate space for payloads like backtraces.
- No data types in structured syslog. Numbers and strings are indistinguishable.
- The RFCs are strict enough, but there are so many syslog dialects out there that you cannot possibly parse all of them.
- No compression.
Syslog is sufficient for logging system messages of machines or network gear, while GELF is a strong choice for logging from within applications. There are libraries and appenders for many programming languages and logging frameworks, so it is easy to implement. GELF can send every exception as a log message to your Graylog cluster without complications from timeouts, connection problems, or anything that may break your application from within your logging class because GELF can be sent via UDP.
!(Graylog GELF)(https://go2docs.graylog.org/current/resources/images/logo.png)
The following configuration reads the Windows EventLog and sends it to the Graylog2 server in GELF format.
Graylog is a fully integrated platform for collecting, indexing, and analyzing both structured and unstructured data from almost any source. Non Graylog-authored components Include MongoDB for metadata and Elasticsearch for log file storage and text search.
Centralize all your log messages
- Collect terabytes of log messages
- Process in real-time
- Search and analyze in seconds