|
|
|
|
|
by mmt
5734 days ago
|
|
The "pro" that I am is sysadmin, and I'm asserting that evaluating all three is a waste of time. Splunk, given its cost and complexity, is almost never right for startups. Non-ng syslog is, on the other hand, so simplistic that it's not worth the effort of fancy configuration. Is there some kind of compelling advantage that I've been overlooking? I never quite understood the conceit that every environment is a precious-and-unique snowflake requiring careful evaluation of any given tool. |
|
http://fedoraproject.org/wiki/Releases/FeatureRsyslog
Further, I think that RELP and on-demand disk spooling of messages are compelling features. Its performance and reliability are good enough to feed your web-server access logs through.
I wouldn't overlook rsyslog, but I'm also not saying "just use it" because syslog-ng is certainly worth evaluating as well.
Edit: see also http://www.linuxjournal.com/content/centralized-logging-web-...