SlideShare a Scribd company logo
Log Management Systems
A comparison of message and metric
management solutions
Presenter: Mehdi Hamidi
( @eXtrem0us )
Introduction
Log Management Systems
What is LOG?
●Combination of Time, Tag and Message
●Indicates State of Applications (?)
●Human and Machine Readable Messages (?)
Log Management Systems
Log Management Systems
Level of logs in syslog standard
●From Debug to Panic
●rsyslog, syslog, syslog-ng
●/var/log/syslog /var/log/rsyslog
Importance of logs
●Companies and Businesses
●Even Personal Use!
(Twitter, Sensors,... )
LogAnalyzer: a simple solution :)
LogAnalyzer: a simple solution :)
Importance of Logging Systems
WHAT Actually We NEED?
Collect
Messages
Metrics
●Store
●Visualize
●Alert
Importance of Logging Systems
Heterogeneous Environment
Write our own script for each type of log (?)
Not in an enterprise environment with lots of
devices and services!
●Technical Fragility and dependency to
Individuals
●Strong Dependency to knowledge about
underlying process
Log Management Systems
Log Management Systems
Commercial Solutions
Splunk
(500M/Day is Free, then: 5,000,000 $)
●Nagios
Everything is restricted to Nagios Concept
No separation between metrics and messages
No stylish diagrams (in free solution)
Problems in cloud infrastructure
No realtime monitoring
No manipulating messages
(1,995 $ for commercial solution)
●Online Services
Good logging system Specifications
●Have a common interface
●Decouple data sources from data outputs
Prevent mentioned dependencies
No effect of adding new data source/output
Reliability
Persistent Buffering
●Extensibility
High Availability
Load Balancing
Robustness
Lots of OpenSource Bricks (OSB!)
Logging Systems:
● Fluentd
● LogStash
● GrayLog
● Logalice
● Rsyslog
● Scribe
Message Stores:
● ElasticSeach
● Hadoop
● MongoDB
● File
● RDBMS
● Redis
● ...
Visualization
(Dashboards):
● Kibana
● Grafana
● Gaylog-WebUI
● PacketBeat
● Chronograph
● ...
Metric Stores:
● InfluxDB
● Prometheus
● Graphite
● ...
Alerting:
● Kapacitor
● Skyline
● Oculus
● Cabot
Log Nature
Semistructured or Unstructured
Generated Massively
More Written and less Read
(That's why we use NoSQL)
Popular Stacks (metrics): TICK Stack
Popular Stacks (Messages) : ELK Stack
Log Management Systems
Log Management Systems
Fluentd VS LogStash
Overview
Fluentd:
Written in Cruby
Used in Google Cloud Platform and Kubernetes
Maintained by Tresure Data
●Logstash:
Written in Jruby
Used in ELK Stack
Maintained by Elastic Co.
➢Both use their own RubyGems Repo
➢Out of the box nature, less dependencies
Configuration
Fluentd:
Each Input is tagged
Logs are routed by tags
Logstash:
All inputs are Gathered and Scattered
Conditional Outputs, No tags
Configuration
Transport and Buffering
Fluentd: built-in
LogStash: bundled Redis
version 5.3: persistent buffering
Full Buffer or Output Exception occurrence
Fluentd:
Exception: streaming
Block input plugin: batch
Drop oldest chunk: monitoring
LogStash:
Retry
Discard
Dead Letter Queuing
High Availability and Load balancing
High Availability and Load balancing
High Availability and Load balancing
High Availability and Load balancing
Memory
Fluentd: 40 M
Logstash: 120 M
(in big clusters matter)
Forwarders
●Fluentd:
 Fluentbit (Written in C)
 Fluentd-Forwarder (Written in Go)
 (all in one)
●LogStash:
 Filebeat
 Metricbeat
 Packetbeat
 Winlogbeat
(beat family: separated component for each
purpose)
Community and Support
Fluentd: Poor
Japanese Blogs
Google Group
Logstash: Rich
Documents
Blogs
IRC
Meetups and Certs
Plugins
Fluentd Plugins Verified
Input/Output 554 44
Filter 90 8
Parser 30 2
Formatter 6 0
Obsolete 8 0
Plugins are maintained more by other people.
Plugins
All Plugins are in a Single GitHub Repo.
LogStash Plugins
Input 52
Filter 46
Output 55
Questions?
Thanks You!
ahamidi66@gmail.com
@eXtrem0us
Resources
http://logz.io/blog/fluentd-logstash
http://docs.fluentd.org/articles/buffer-plugin-overvie
https://prometheus.io/docs/introduction/comparison
http://logz.io/blog/elk-stack-5-0
https://www.youtube.com/watch?v=1ye0-sityBw
https://www.youtube.com/watch?v=0lAHrspviIs&list=PL62pIycqXx-TPwtk4JDd0wMuFAyP0gU1y
https://www.youtube.com/watch?v=mfb0R7azKZc
https://www.youtube.com/watch?v=_BAWi9Zhmic

More Related Content

What's hot (20)

PPT
"Grand Challenges" of Log Management
Anton Chuvakin
 
PPTX
Information Security: Advanced SIEM Techniques
ReliaQuest
 
PPTX
EventLog Analyzer - Product overview
ManageEngine EventLog Analyzer
 
PPTX
Implementing and Running SIEM: Approaches and Lessons
Anton Chuvakin
 
PPTX
RuSIEM overview (english version)
Olesya Shelestova
 
PPTX
Large enterprise SIEM: get ready for oversize
Mona Arkhipova
 
PPTX
Security Information and Event Management (SIEM)
k33a
 
PPTX
Tips on SIEM Ops 2015
Anton Chuvakin
 
PPTX
From SIEM to Business processes
Olesya Shelestova
 
PPTX
SIEM Primer:
Anton Chuvakin
 
PDF
Chaos monitoring
Mona Arkhipova
 
PDF
Understanding the Event Log
chuckbt
 
PPTX
Log Standards & Future Trends by Dr. Anton Chuvakin
Anton Chuvakin
 
PDF
Positive Hack Days 7 - Ransomware forensiсs
Mona Arkhipova
 
PPTX
You Can't Correlate what you don't have - ArcSight Protect 2011
Scott Carlson
 
DOCX
Security Incident Log Review Checklist by Dr Anton Chuvakin and Lenny Zeltser
Anton Chuvakin
 
PPTX
Security Ops for large and small companies
Mona Arkhipova
 
PPTX
Five Best and Five Worst Practices for SIEM by Dr. Anton Chuvakin
Anton Chuvakin
 
PPT
Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organiza...
Nagios
 
PPTX
Risks vs real life
Mona Arkhipova
 
"Grand Challenges" of Log Management
Anton Chuvakin
 
Information Security: Advanced SIEM Techniques
ReliaQuest
 
EventLog Analyzer - Product overview
ManageEngine EventLog Analyzer
 
Implementing and Running SIEM: Approaches and Lessons
Anton Chuvakin
 
RuSIEM overview (english version)
Olesya Shelestova
 
Large enterprise SIEM: get ready for oversize
Mona Arkhipova
 
Security Information and Event Management (SIEM)
k33a
 
Tips on SIEM Ops 2015
Anton Chuvakin
 
From SIEM to Business processes
Olesya Shelestova
 
SIEM Primer:
Anton Chuvakin
 
Chaos monitoring
Mona Arkhipova
 
Understanding the Event Log
chuckbt
 
Log Standards & Future Trends by Dr. Anton Chuvakin
Anton Chuvakin
 
Positive Hack Days 7 - Ransomware forensiсs
Mona Arkhipova
 
You Can't Correlate what you don't have - ArcSight Protect 2011
Scott Carlson
 
Security Incident Log Review Checklist by Dr Anton Chuvakin and Lenny Zeltser
Anton Chuvakin
 
Security Ops for large and small companies
Mona Arkhipova
 
Five Best and Five Worst Practices for SIEM by Dr. Anton Chuvakin
Anton Chuvakin
 
Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organiza...
Nagios
 
Risks vs real life
Mona Arkhipova
 

Similar to Log Management Systems (20)

PDF
FluentD vs. Logstash
All Things Open
 
PPTX
centralization of log systems pour suivis
Thierry Gayet
 
KEY
Message:Passing - lpw 2012
Tomas Doran
 
PDF
Centralized + Unified Logging
Gabor Kozma
 
PDF
Log Management: AtlSecCon2015
cameronevans
 
PDF
Fluentd vs. Logstash for OpenStack Log Management
NTT Communications Technology Development
 
KEY
London devops logging
Tomas Doran
 
PDF
Logging in Action: With Fluentd, Kubernetes and more 1st Edition Phil Wilkins
roarxhaarexg
 
PDF
Atmosphere 2014: Centralized log management based on Logstash and Kibana - ca...
PROIDEA
 
PPTX
CSE3069 - FLUENTD real time analytics.pptx
dummyuseage1
 
PPTX
Log management with ELK
Geert Pante
 
KEY
Zero mq logs
Tomas Doran
 
KEY
Messaging, interoperability and log aggregation - a new framework
Tomas Doran
 
PDF
Log aggregation: using Elasticsearch, Fluentd/Fluentbit and Kibana (EFK)
Lee Myring
 
ODP
Turbo charge your logs
Jeremy Cook
 
PDF
LogStash in action
Manuj Aggarwal
 
PPTX
Open Source Monitoring Tools
m_richardson
 
PDF
Technology behind-real-time-log-analytics
Data Science Thailand
 
PPTX
Centralized Logging System Using ELK Stack
Rohit Sharma
 
PPTX
How fluentd fits into the modern software landscape
Phil Wilkins
 
FluentD vs. Logstash
All Things Open
 
centralization of log systems pour suivis
Thierry Gayet
 
Message:Passing - lpw 2012
Tomas Doran
 
Centralized + Unified Logging
Gabor Kozma
 
Log Management: AtlSecCon2015
cameronevans
 
Fluentd vs. Logstash for OpenStack Log Management
NTT Communications Technology Development
 
London devops logging
Tomas Doran
 
Logging in Action: With Fluentd, Kubernetes and more 1st Edition Phil Wilkins
roarxhaarexg
 
Atmosphere 2014: Centralized log management based on Logstash and Kibana - ca...
PROIDEA
 
CSE3069 - FLUENTD real time analytics.pptx
dummyuseage1
 
Log management with ELK
Geert Pante
 
Zero mq logs
Tomas Doran
 
Messaging, interoperability and log aggregation - a new framework
Tomas Doran
 
Log aggregation: using Elasticsearch, Fluentd/Fluentbit and Kibana (EFK)
Lee Myring
 
Turbo charge your logs
Jeremy Cook
 
LogStash in action
Manuj Aggarwal
 
Open Source Monitoring Tools
m_richardson
 
Technology behind-real-time-log-analytics
Data Science Thailand
 
Centralized Logging System Using ELK Stack
Rohit Sharma
 
How fluentd fits into the modern software landscape
Phil Wilkins
 
Ad

Recently uploaded (20)

PPTX
A brief History of counseling in Social Work.pptx
Josaya Injesi
 
PPTX
2025-07-13 Abraham 07 (shared slides).pptx
Dale Wells
 
PDF
What should be in a Leadership and Motivation Plan?
Writegenic AI
 
PDF
Cloud Computing Service Availability.pdf
chakrirocky1
 
PPTX
Speech Act, types of Speech Act in Pragmatics
gracehananatalias
 
PDF
Generalization predition MOOCs - Conference presentation - eMOOCs 2025
pmmorenom01
 
PDF
Mining RACE Newsletter 10 - first half of 2025
Mining RACE
 
PPTX
Sample pitch deck: know what to keep in your pitch deck (for competitions only)
Ujjwaal G
 
PPT
Wireless Communications Course lecture1.ppt
abdullahyaqot2015
 
PPTX
Food_and_Drink_Bahasa_Inggris_Kelas_5.pptx
debbystevani36
 
PDF
From 0 to Gemini: a Workshop created by GDG Firenze
gdgflorence
 
PPTX
some leadership theories MBA management.pptx
rkseo19
 
PPTX
677697609-States-Research-Questions-Final.pptx
francistiin8
 
PDF
Medical Technology Corporation: Supply Chain Strategy
daretruong
 
PPTX
Pastor Bob Stewart Acts 21 07 09 2025.pptx
FamilyWorshipCenterD
 
PPTX
BARRIERS TO EFFECTIVE COMMUNICATION.pptx
shraddham25
 
PDF
FINAL ZAKROS - UNESCO SITE CANDICACY - PRESENTATION - September 2024
StavrosKefalas1
 
PDF
Leveraging the Power of Jira Dashboard.pdf
siddharthshukla742740
 
PDF
CHALLENGIES FACING THEOLOGICAL EDUCATION IN NIGERIA: STRATEGIES FOR IMPROVEMENT
PREVAILERS THEOLOGICAL SCHOOL FCT ABUJA
 
PPTX
AI presentation for everyone in every fields
dodinhkhai1
 
A brief History of counseling in Social Work.pptx
Josaya Injesi
 
2025-07-13 Abraham 07 (shared slides).pptx
Dale Wells
 
What should be in a Leadership and Motivation Plan?
Writegenic AI
 
Cloud Computing Service Availability.pdf
chakrirocky1
 
Speech Act, types of Speech Act in Pragmatics
gracehananatalias
 
Generalization predition MOOCs - Conference presentation - eMOOCs 2025
pmmorenom01
 
Mining RACE Newsletter 10 - first half of 2025
Mining RACE
 
Sample pitch deck: know what to keep in your pitch deck (for competitions only)
Ujjwaal G
 
Wireless Communications Course lecture1.ppt
abdullahyaqot2015
 
Food_and_Drink_Bahasa_Inggris_Kelas_5.pptx
debbystevani36
 
From 0 to Gemini: a Workshop created by GDG Firenze
gdgflorence
 
some leadership theories MBA management.pptx
rkseo19
 
677697609-States-Research-Questions-Final.pptx
francistiin8
 
Medical Technology Corporation: Supply Chain Strategy
daretruong
 
Pastor Bob Stewart Acts 21 07 09 2025.pptx
FamilyWorshipCenterD
 
BARRIERS TO EFFECTIVE COMMUNICATION.pptx
shraddham25
 
FINAL ZAKROS - UNESCO SITE CANDICACY - PRESENTATION - September 2024
StavrosKefalas1
 
Leveraging the Power of Jira Dashboard.pdf
siddharthshukla742740
 
CHALLENGIES FACING THEOLOGICAL EDUCATION IN NIGERIA: STRATEGIES FOR IMPROVEMENT
PREVAILERS THEOLOGICAL SCHOOL FCT ABUJA
 
AI presentation for everyone in every fields
dodinhkhai1
 
Ad

Log Management Systems