Log sources
Control inputs, transport, buffering and timestamps.

We install and operate Graylog on your infrastructure - including inputs, pipelines, search, retention, alerts, dashboards, updates and recovery with an assessed edition.
Companies worldwide trust WZ-IT
Graylog is a trademark of Graylog, Inc. WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with Graylog, Inc. We install and operate Graylog on customer infrastructure; the edition, feature scope, and any required vendor licences are clarified in advance.

Graylog brings together system, application and network logs. Without a source inventory, parsing, timestamps, retention and defined alert rules, central collection quickly becomes expensive storage with little dependable value.
We install and operate Graylog on your infrastructure, connect inputs and sources and design pipelines, index lifecycles, dashboards, alerts and backups. Security and compliance requirements are scoped for each data source.
Graylog Open is source-available under the SSPL; Enterprise and Security capabilities have their own vendor terms. WZ-IT operates the platform for your internal use on your infrastructure.
Vendor licences, infrastructure, log storage and WZ-IT services are itemised separately. Binding retention and evidence requirements are defined by the customer.
Transport, processing, search, retention and alerting are monitored together so missing or delayed logs are visible.
Control inputs, transport, buffering and timestamps.
Structure parsing, routing, search and lifecycle.
Implement roles, data classes and retention technically.
Own updates, monitoring, backup and capacity.
WZ-IT operates the technical pipeline; sources, data classification and binding retention are agreed with the customer.
| Area | Responsibility | Scope and boundaries |
|---|---|---|
| Graylog and foundation services | WZ-IT | Installation, configuration, hardening, updates and monitoring. |
| Index lifecycle and capacity | WZ-IT | Technical retention, shards, storage and health control. |
| Inputs and pipelines | Shared | WZ-IT implements; the customer confirms sources, fields and routing. |
| Alerts and runbooks | Shared | Technical rules and desired response are defined together. |
| Data classification and periods | Customer | Business and legal policies come from the organisation. |
| SIEM and compliance expansion | Optional WZ-IT service | Correlation, reports and security processes are designed separately. |
Collect syslog, GELF and other supported sources through controlled endpoints.
Normalise, enrich and filter fields and route data into suitable streams.
Separate logs by system, environment, tenant or area of responsibility.
Expose technical patterns and alert on relevant events.
Design index lifecycles and retention around value, cost and policy.
Connect servers, applications, firewalls, cloud services and ticketing.
Assess existing data and configuration, migrate them in a test run and move to managed operations through a controlled cutover.
Secure SSO, roles, administrative paths and external access for the application and existing infrastructure.
Back up all stateful components consistently and document the recovery path for the agreed scope.
Monitor and update the application and its technical dependencies and operate them under the agreed service level.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.
We combine the right compute size with ongoing operations, backups, monitoring and a service level appropriate for the criticality of Graylog. High availability and recovery targets are designed separately where needed.
We also design custom hosting architectures, integrations and migrations around Graylog. Contact us for a technical assessment.
One managed standard Graylog application is included in the Starter workload. Business and higher levels add a flexible operations allowance for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Enquiry
Briefly describe the current state and objective for Graylog. We assess infrastructure, integration, and ongoing operations.
Logs per second, daily volume, parsing cost, search window, replication and retention determine platform and cost.
| Usage scenario | Technical starting point | Key factors |
|---|---|---|
| Small central log view | Compact single environment | Few sources, short retention and normal search. |
| Production server and application logs | Separate Graylog and data services | Buffering, maintenance and storage are decoupled. |
| High ingest or long retention | Log assessment | EPS, GB per day, fields and search profile are measured. |
| Security or compliance use | Platform assessment | Edition, audit, archive, HA and response processes are clarified. |
A proposal requires at least source count, daily log volume, retention, search profile, edition and desired incident response.
Log data remains in your controlled environment; WZ-IT receives defined administrative access for operations.
Central log platform inside your cloud and network boundaries.
Collect logs from internal servers, networks and applications locally.
Predictable storage and I/O for continuous ingest.
Collector and relay paths across clouds and sites.
Sources send over defined and preferably buffered paths; Graylog processes and routes data into controlled index areas.
Search, dashboards, alerts and approved exports.
Protected inputs, web access and restricted administration.
Access by team, stream, data class and edition.
Inputs, pipelines, streams, search, dashboards and alerts.
Sources, sidecars or brokers stabilise log flow.
Data storage, lifecycle, replication and capacity.
Ingest gaps, journal, index health, alerts and backups.
Graylog backups must account consistently for application configuration and underlying data services. Restore is documented for the exact version and topology.
Answers about editions, log volume, retention, alerting and takeovers.
On your cloud or on-premise infrastructure for your internal use. Edition and licence are assessed before build or takeover.
Yes. We inventory inputs, formats, pipelines, streams, dashboards, alerts and retention and migrate them through a controlled parallel or test phase.
That depends on daily raw volume, field structure, replication, search window and retention. We measure or estimate these values before sizing.
Central logs and alerts are a foundation. Correlation, use cases, incident process, threat intelligence and compliance evidence require a security design and potentially an appropriate edition.
That is available with a suitable service level. Alert rules, priorities, runbooks and responsibilities are documented first.
As an alternative to managed hosting in the data centre, WZ-IT provides the hardware, configures Graylog, and handles hardening, monitoring, updates, backup and technical support. Access can be limited to the internal network or enabled through VPN and existing identities.
from EUR 349 excl. VAT / month · plus one-time provisioning and initial setup

These solutions are often used together with Graylog
These solutions offer similar functionalities and can be evaluated together
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.