Graylog: Introduction
Introduction to Graylog, a unified and powerful platform for log management and analytics
👋 Welcome to Stackhero documentation
Stackhero offers a fully managed Graylog cloud solution designed for speed and simplicity. You can:
- Rely on an unlimited, dedicated SMTP email server included with your service.
- Apply updates effortlessly with a single click, with no manual intervention required.
- Use a custom domain name secured by HTTPS (for example, https://logs.your-company.com), providing your team with secure, direct access.
- Benefit from strong performance and security on a private, dedicated infrastructure, with no shared resources or noisy neighbours.
Focus on your data, not your tools: you can get started with Stackhero's Graylog cloud hosting solution in just a few minutes.
What is Graylog
Graylog is an open-source log management platform that centralises the collection, storage, search, and analysis of logs across your entire infrastructure. Rather than connecting to each server to manually inspect logs, you can send all your logs to Graylog, which indexes them in real time. Every log entry becomes instantly searchable, even among billions of events, with results returned in just milliseconds.
Graylog offers three key capabilities. It collects log data from almost any source: servers, applications, containers, network equipment, or cloud services, using widely adopted protocols such as Syslog, GELF, Beats, raw TCP/UDP, and HTTP. It then indexes this data using an integrated OpenSearch engine, making every field immediately queryable. Finally, it analyses your data via a web interface with full-text search, customisable dashboards, alerting, and real-time processing pipelines that can enrich, filter, and route events as they arrive.
The company behind Graylog
Graylog was created in 2010 by Lennart Koopmann in Hamburg, Germany, initially as a personal tool for centralised log management. The project was open-sourced in 2012 under the name GELF (Graylog Extended Log Format), and quickly gained popularity within the DevOps and infrastructure communities. Graylog, Inc. was later founded to develop commercial offerings around the open-source core.
Today, the company is headquartered in Houston, Texas, with offices in London and Hamburg. It has received significant venture funding and supports thousands of organisations worldwide, from startups to large enterprises and public sector bodies.
What is Graylog used for
Engineering and operations teams use Graylog for a wide range of scenarios. The most common is production debugging: when incidents occur, teams can search across logs from dozens of services simultaneously, instead of inspecting files on each server. This greatly accelerates and simplifies troubleshooting.
Graylog is also used for infrastructure monitoring. You can define alert conditions that trigger when error rates rise, services become unavailable, or unusual log patterns are detected. Security teams rely on Graylog for audit and compliance, tracking authentication events, access patterns, and anomalies, while retaining logs for the periods required by standards such as GDPR, ISO 27001, SOC 2, and HIPAA. Platform teams use Graylog to correlate events across different systems—web servers, databases, load balancers, or Kubernetes pods—into a single, searchable timeline.
How Graylog works
Graylog acts as a central hub between your infrastructure and your team. Log shippers such as Filebeat, Fluentd, rsyslog, or native GELF client libraries collect logs from your systems and forward them to Graylog's input endpoints. Graylog processes each incoming message through configurable pipelines that can parse fields, transform data, enrich events (for example, with geo-IP lookups), and route messages to specific streams.
Processed messages are indexed by OpenSearch (included with Graylog), which powers the search functionality. MongoDB (also included) stores Graylog's configuration: streams, dashboards, users, alerts, and pipeline definitions. Your team uses the Graylog web interface to run ad-hoc searches, build dashboards, configure alerts, and investigate incidents. This provides a unified view of your log data, with sub-second search even at scale.
Is Graylog free
Graylog is available in two editions. Graylog Open is the community edition: free to use, including in production, with all the essential log management features such as collection, indexing, search, dashboards, streams, pipelines, and basic alerting. The source code is available on GitHub. Graylog Operations and Graylog Security are commercial editions that offer advanced features such as anomaly detection, compliance reporting, advanced correlation, and enterprise support.
A key licensing note: In 2023-2024, Graylog changed its core licence from Apache 2.0 to the Server Side Public License (SSPL). For most users—companies running Graylog internally—this change has no practical impact. You can continue to use Graylog Open for free. The SSPL mainly affects those wishing to offer Graylog as a hosted service to third parties. If you require the Apache 2.0 licence, the last release under it was Graylog 5.0. Versions 5.1 and later use SSPL. For further details, see the official SSPL licence documentation.
When to use Graylog
Graylog is ideal if you want to centralise logs from multiple servers, services, or applications into a single, searchable interface. If your team spends time connecting to machines to diagnose production incidents, or if you lack real-time visibility into your infrastructure, Graylog directly addresses these needs.
It is an excellent choice if you require real-time alerting on log patterns—such as error spikes, failed authentication, or service outages—or if retention for compliance and audit is essential. Teams seeking a dedicated log management interface, without the need to assemble multiple tools, will find Graylog particularly effective.
When not to use Graylog
Graylog is specialised for log management. If your main requirement is storing and querying time-series metrics (such as CPU usage, request latency, or memory consumption), a time-series database like InfluxDB or Prometheus is more suitable. Graylog is designed for log events, not for high-frequency numerical measurements.
What makes Graylog so great
Graylog offers several advantages over building your own log management stack:
- All-in-one solution: OpenSearch and MongoDB are included and pre-configured. You do not need to install, integrate, or maintain separate services.
- Fast, intuitive search: Full-text search across billions of events in milliseconds, using the easy-to-learn Graylog Query Language (GQL).
- Real-time streams and pipelines: Route and transform log data as it arrives. You can filter out noise, enrich data, and direct specific events to specific streams without custom development.
- Integrated alerting: Alert conditions and notifications via email, Slack, PagerDuty, and other channels are built in—no separate alerting system required.
- Native dashboards: Create interactive dashboards directly in the Graylog web interface, without needing additional visualisation tools like Grafana or Kibana.
- Multi-protocol log ingestion: Accept logs via Syslog, GELF, Beats, raw TCP/UDP, HTTP, and more. Graylog works with nearly any log shipper already present in your environment.
What is Graylog cloud
Graylog cloud refers to a managed Graylog deployment provided by a cloud provider, rather than running it on-premises. Self-hosting Graylog means operating three services: Graylog, OpenSearch, and MongoDB, and keeping them up to date, backed up, and secure, which can be a significant operational burden.
With Stackhero, you have a dedicated Graylog instance ready within minutes. OpenSearch and MongoDB are included and configured automatically. Your instance runs on isolated infrastructure, ensuring your log data remains private. All connections are encrypted with TLS 1.3, backups are performed every 24 hours and retained for up to 3 months, and updates are just one click away. You can deploy servers in the United States or Europe, and hourly billing means you only pay for what you use.
How to start with Graylog
If Graylog matches your requirements, you can try a managed, pre-configured instance that is ready to use in just a few clicks. Simply launch a free demo instance in about 2 minutes to explore Graylog without any setup. Upgrading to a production-ready instance is just as straightforward.