Expose Graylog to Internet

Hello to all!

Can you give an advise for security tweaking when Graylog exposed to Internet. Or is it bad idea? We often need check logs and not always vpn connection can be established.

The principles for critical (internal) infrastructure also apply to Graylog: Only expose it if absolutely necessary and put some proper gateway with authentication in front of it (e. g. using client certificates).

