So I installed, setup and configured some hosts to send their logs to Graylog. It works great, I can search and find whatever I want.
I’ve read pretty much the entire Graylog documentation and understand how it works, in some degree at least. The docs are great in explaining what each part does but its also evident that setting it up properly is not an easy task (I didn’t think it was).
So now I’m looking for a guide that deals with setting up for the bigger picture written from experience.
If you know something out there please share it.