Graylog information inquiries (About version)

Daer all,

We have a few inquiries and need you to confirm regarding Graylog as following questions.

  1. Now we are using Graylog virtual appliance (OVA). we would like to know how long can keep the file ? and Where is the path for keep file ? and We can select path for keep file ?
  2. As we find more information, please confirm that the virtual appliance version is not suited to use as a production because it is unsecured? Why ?
  3. We would like to know difference between virtual appliance (OVA) and RPM package (Ubuntu). because now, we are using Graylog virtual appliance (OVA) and we would like to change use RPM package ?
  4. We find more information by the link below
    Planning Your Log Collection — Graylog 4.0.0 documentation
    Topic “Retention”
    For “Most Graylog customers retain 30-90 days online (searchable in Elasticsearch) and 6-13 months of archives” What does it mean?

Anyway if you need more information from us, please kindly let us know.

Thank you for your kind support.

Daer all,

Anyway if you need more information from us, please kindly let us know.

Thank you for your kind support.

  1. Data retention in graylog is defined in Index rotation settings. You can define retention by index size, time or number of messages. All data is stored in Elastic Search DB, so you define retention in graylog web UI.
    Index model — Graylog 4.0.0 documentation
  2. Better way is to setup own installation by your company standard. For example OVA is based on Ubuntu linux 18.04, which is older LTS version of Ubuntu, and you may prefer Redhat or Debian distribution in your company. Best way is to use distribution you have the most experience with.
  3. OVA is preconfigured virtual machine based on Ubuntu 18.04. RPM is totally different, it’s way to install packages on RPM based distributions like Red Hat, CentOS.
  4. Graylog documentation is very good, I recommend read it all to better understandig the concepts and software.
2 Likes

Dear @shoothub,

Thank you for your reply. If we have more any questions We would like to ask you again.

Thank you

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.