I'm wondering if anyone has used Elasticsearch to manage (provide
search for) large log file collections?
I'm looking for solutions to help with a semi-centralized log
management project. The logs would be sent in syslog-style format
from hundreds of servers/routers/firewalls and maintained on a few
dedicated log servers. I looked into Splunk, a popular log management
solution which has the ability to scale horizontally (add more servers
for more storage and performance). I assume it uses some sort of
NoSQL technology. Unfortunately, their solution is too expensive and
after searching for an open-source equivalent and not finding it, I'm
looking into possibly building a home-grown solution.
I came across the following blog post series on log management with
In the comments of the 3rd blog post, Elasticsearch was mentioned as
a possibility and so I'm wondering if anyone out there has applied
Elasticsearch to log management?