3 ms·
I like how this is mostly based on the Kibana UI. Makes easier to convince other people to move to it.
by darkstar_16 2y ago
I like how this is mostly based on the Kibana UI. Makes easier to convince other people to move to it.
- r0b3r4 2y agoTo be honest, I was more inspired by DataDog :)
- danmur 2y agoI've used graylog the most so that's what it looks like to me :P. I like how you can do a bunch of extraction stuff right there in the query interface though, that's awesome. It seems like a very thoughtful UI.
- sleepybrett 2y agoHonestly that pushes me away from it. I find kibana to be a very frustrating experience.
- mikeshi42 2y ago(not op) curious what you find frustrating about it?
- sleepybrett 2y agoat the enterprise scale on the backend you end up paying for a bunch of indexing you will likely never use. On top of that you spend a LOT of money in engineering hours setting up indexes for many teams all with different log formats so the whole thing doesn't just melt down. On the kibana side, their query language is unshared by any other tool, at least any that I use, meaning that in the middle of an outage I end up chasing my tail reading docs on how to query what you want. The returns are often slow and it's very hard to just export the logs you do find to text files so you can ingest them into other tools. I mean I came up on cat/gerp/awk/sed/less/tail/(more recently jq for json logs) .. it wasn't perfect but it was RESPONSIVE and portable. I just think that tools like ES/Splunk weren't conceived for dealing with logs (especially if your logs come in many formats) and are both overkill and at the same time underkill for the task. It's like using a ball peen hammer to drive nails, you can certainly DO it, but a claw hammer is cheaper and a more ergonomic experience.