Determining data volumes to collect
Doug, as you suggest, organizations need low-cost and low-risk options to tap the intelligence contained in their IT log data. One of biggest hurdles for companies is determining how much data they ultimately need to collect each day. Most first-time users start with a specific area of interest, for example, firewall logs. By the end of the first day they might have collected 5 GB of data. By midweek, they could be collecting 20 GB per day from 50% of their domain controllers. By Friday, they could be collecting 75 GB per day of logs from operating systems, databases, and all the major components of their data center. Organizations with deep budgets can choose any tool they like. For others, open source is a great alternative. There's even a hybrid model we've seen where organizations put Graylog on the front end of all log ingestions, and then use our user-defined streams to send subsets of real-time data to Splunk, a SIEM, or other commercial system for analysis. -Michael Sklar, CEO, Graylog
User Rank: Apprentice
6/30/2015 | 1:26:46 PM