4 ms·
For small stuff I still like the simple syslog. It’s usually built in and supports aggregating to a single server. In the past have created a server just with
by hn_user2 9y ago
For small stuff I still like the simple syslog. It’s usually built in and supports aggregating to a single server.
In the past have created a server just with syslog. Adjust all your servers syslog configs to point to that one. Then log in and use grep.
Not fancy. But gets the job done with a single line config change in your syslog configs.
- arca_vorago 9y agoSenior sysadmin here, and I agree this is one of the most common methods. I have also had great success tying in the ossec or pam module notifications into syslog messages that all go to the central syslog (nsyslog/rsyslog etc) server. The problem with the elk and similar stacks imho is lack of security and speed. Things this old school setup doesn't have a problem with. The problem is that too many managers don't like not having gui dashboards... which is why splunk et al have really taken off. This re-enforces my idea that a purely terminal based business dashboard might be a cool product with a fairly large market. I've been eyeballing some of the go/ncurses work for this.
- devonkim 9y agorsyslog or syslog-ng were preferred these days for better security and performance I thought? Unless you’re using something like stunnel to wrap the syslog messages that is.