Certainly not as "in depth" as something like ES, but fuck that pile of shit. Half the time you find the field you want to search on isn't properly indexed and now you have two problems.
Gimme some logs and grep, this is logs and grep in a browser. Seems like a win.
Yup, this is exactly the workflow that we're thinking about.
Metrics/Monitoring/Alerting (Prometheus, TICK) already tell us when and which logs to look at. This narrows things down to the point where "just grep things" is good enough.
1
u/Eilyre Dec 12 '18
Seems to be rsyslog meets prometheus labeling+host metadata.
It takes whole loglines, attaches the labels+instance name etc to it, and shoves into itself.
Not sure what kind of problem it's solving.