Gestion de log : suivi et exploitation d'un parc informatique via Graylog

Johan Thomas · HAL (Le Centre pour la Communication Scientifique Directe) · 2015

This presentation shows how a tool (Graylog) can be used to centralise and analyse log files within a computer stock.The originality of this solution lies in the scope of the computer stock. Log centralisation tools are more traditionally used for system and network infrastructures.The Rennes education authority has deployed a tool to collect and send log/event viewer data on its more than 1200 workstations spread over 9 sites. The NXLog tool converts event viewers and log files from workstations and servers into GELF format, focusing on information of interest. The Graylog server centralises all of this information and analyses it, allowing dashboards and alerts to be created and information to be re-routed.Graylog was chosen due to its many natively integrated features (dashboards for each user, alerts, authentication, upgradeability, ease of use, etc.). Graylog is responsible for the GELF format. This provides a number of improvements over the traditional syslog format. The centraliser uses an Elasticsearch database to store all information.Used in production for over 2 years, this tool has enabled functional and dynamic dashboards to be created to provide assistance. In certain cases, these dashboards help to enable assistance teams to play an active role (intervening before data loss occurs, for example).

Read the paper · More papers on PaperTik