Graylog: Introduction

Introduction to Graylog, a unified and powerful platform for log management and analytics

👋 Welcome to Stackhero documentation

Stackhero offers a fully managed Graylog cloud solution designed for speed and simplicity. You can:

  • Count on an unlimited, dedicated SMTP email server included with your service.
  • Apply updates easily with a single click, with no manual intervention required.
  • Use a custom domain name secured by HTTPS (for example, https://logs.your-company.com), providing your team with secure, direct access.
  • Benefit from strong performance and security on a private, dedicated infrastructure with no shared resources or noisy neighbours.

Focus on your data, not your tools: you can get started with Stackhero's Graylog cloud hosting solution in just a few minutes.

Graylog is an open-source log management platform that centralizes the collection, storage, search, and analysis of logs across your entire infrastructure. Instead of connecting to each server to manually inspect logs, you can send all your logs to Graylog, which indexes them in real time. Every log entry becomes instantly searchable, even among billions of events, with results displayed in just milliseconds.

Graylog offers three key features. It collects log data from virtually any source: servers, applications, containers, network devices, or cloud services, using widely adopted protocols such as Syslog, GELF, Beats, raw TCP/UDP, and HTTP. It then indexes this data using an integrated OpenSearch engine, making every field immediately queryable. Finally, it analyzes your data through a web interface with full-text search, customizable dashboards, alerting, and real-time processing pipelines that can enrich, filter, and route events as they arrive.

Graylog was created in 2010 by Lennart Koopmann in Hamburg, Germany, initially as a personal tool for centralized log management. The project was open-sourced in 2012 under the name GELF (Graylog Extended Log Format) and quickly gained popularity in the DevOps and infrastructure communities. Graylog, Inc. was later founded to develop commercial offerings around the open-source core.

Today, the company is headquartered in Houston, Texas, with offices in London and Hamburg. It has received significant venture funding and supports thousands of organizations worldwide, from startups to large enterprises and public sector organizations.

Engineering and operations teams use Graylog in a variety of scenarios. The most common is production debugging: when incidents occur, teams can search through logs from dozens of services at once, instead of inspecting files on each server. This greatly speeds up and simplifies troubleshooting.

Graylog is also used for infrastructure monitoring. You can define alert conditions that trigger when error rates increase, services become unavailable, or unusual log patterns are detected. Security teams rely on Graylog for audit and compliance, tracking authentication events, access patterns, and anomalies, while retaining logs for the periods required by standards such as GDPR, ISO 27001, SOC 2, and HIPAA. Platform teams use Graylog to correlate events across different systems—web servers, databases, load balancers, or Kubernetes pods—into a single, searchable timeline.

Graylog acts as a central hub between your infrastructure and your team. Log shippers like Filebeat, Fluentd, rsyslog, or native GELF client libraries collect log data from your systems and forward it to Graylog's input endpoints. Graylog processes each incoming message through configurable pipelines that can parse fields, transform data, enrich events (for example, with geo-IP lookups), and route messages to specific streams.

Processed messages are indexed by OpenSearch (included with Graylog), which powers the search functionality. MongoDB (also included) stores Graylog's configuration: streams, dashboards, users, alerts, and pipeline definitions. Your team uses the Graylog web interface to run ad-hoc searches, build dashboards, set up alerts, and investigate incidents. This provides a unified view of your logs, with sub-second search even at large scale.

Graylog is available in two editions. Graylog Open is the community edition: free to use, including in production, with all the essential log management features such as collection, indexing, search, dashboards, streams, pipelines, and basic alerting. The source code is available on GitHub. Graylog Operations and Graylog Security are commercial editions that offer advanced features like anomaly detection, compliance reporting, advanced correlation, and enterprise support.

A key licensing note: In 2023-2024, Graylog changed its core license from Apache 2.0 to the Server Side Public License (SSPL). For most users—companies running Graylog internally—this change has no practical impact. You can continue to use Graylog Open for free. The SSPL mainly affects those who want to offer Graylog as a hosted service to third parties. If you require the Apache 2.0 license, the last release under it was Graylog 5.0. Versions 5.1 and later use SSPL. For more details, see the official SSPL license documentation.

Graylog is ideal if you want to centralize logs from multiple servers, services, or applications into a single, searchable interface. If your team spends time connecting to machines to diagnose production incidents, or if you lack real-time visibility into your infrastructure, Graylog directly addresses these needs.

It is an excellent choice if you need real-time alerting on log patterns—such as error spikes, failed authentication, or service outages—or if retention for compliance and audit is essential. Teams looking for a dedicated log management UI, without having to piece together multiple tools, will find Graylog especially effective.

Graylog is specialized for log management. If your main requirement is storing and querying time-series metrics (such as CPU usage, request latency, or memory consumption), a time-series database like InfluxDB or Prometheus is a better fit. Graylog is designed for log events, not for high-frequency numerical measurements.

Graylog offers several advantages over building your own log management stack:

  1. All-in-one solution: OpenSearch and MongoDB are included and preconfigured. You do not need to install, integrate, or maintain separate services.
  2. Fast, intuitive search: Full-text search across billions of events in just milliseconds, thanks to the easy-to-learn Graylog Query Language (GQL).
  3. Real-time streams and pipelines: Route and transform logs as they arrive. You can filter out noise, enrich data, and direct specific events to specific streams without custom development.
  4. Integrated alerting: Alert conditions and notifications via email, Slack, PagerDuty, and other channels are built in—no separate alerting system required.
  5. Native dashboards: Build interactive dashboards directly in the Graylog web interface, without needing additional visualization tools like Grafana or Kibana.
  6. Multi-protocol log ingestion: Accept logs via Syslog, GELF, Beats, raw TCP/UDP, HTTP, and more. Graylog works with nearly any log shipper already present in your environment.

Graylog cloud refers to a managed Graylog deployment provided by a cloud provider, instead of an on-premises installation. Self-hosting Graylog means operating three services: Graylog, OpenSearch, and MongoDB, and keeping them updated, backed up, and secure, which can be a significant operational burden.

With Stackhero, you get a dedicated Graylog instance ready in just a few minutes. OpenSearch and MongoDB are included and configured automatically. Your instance runs on isolated infrastructure, ensuring your log data remains private. All connections are encrypted with TLS 1.3, backups are performed every 24 hours and retained for up to 3 months, and updates are just one click away. You can deploy your servers in the United States or Europe, and hourly billing means you only pay for what you use.

If Graylog fits your needs, you can try a managed, preconfigured instance that is ready to use in just a few clicks. Simply launch a free demo instance in about 2 minutes to explore Graylog without any setup. Upgrading to a production-ready instance is just as easy.

Learn more about Graylog cloud and start a free instance.