Graylog: Free and Open Log Management with Elasticsearch and OpenSearch Backends
Free and open log management
At a glance
- What is it?
- Graylog is a Java-based log management platform released under the Server Side Public License, with modular storage backends for Elasticsearch 7 and OpenSearch 2 and 3, and a web interface for search and analysis.
- Who is it for?
- Graylog is worth considering for teams that need a free log management platform with a web interface and structured search, and who can operate their own Elasticsearch or OpenSearch cluster. The SSPL v1 license permits free use but restricts offering Graylog as a hosted service to others without a commercial license from Graylog Inc.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- Mainly Java, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Graylog Does and Who It Is For
Graylog is a centralized log management platform that collects, indexes, and searches log data from infrastructure, applications, and services. The project describes itself as a free and open log management platform. The CONTRIBUTING.md states it is used by thousands of people.
The primary audience is operations and engineering teams who need to aggregate logs from multiple sources, search them efficiently, and set up alerts on patterns. Graylog provides a web interface for these tasks rather than requiring users to write queries in a separate tool or script.
Log management of this kind sits between raw log storage (writing logs to files or a message queue) and full-stack observability platforms that combine logs, metrics, and traces. Graylog focuses on the log collection and search use case specifically.
The graylog.org website and docs.graylog.org are the primary resources for configuration and operational documentation. The README is intentionally brief and points outward to those resources rather than duplicating them.
Repository Layout and What It Reveals About the Architecture
The repository structure describes the architecture more precisely than the README does. The top-level directories include: graylog2-server/ (the core Java server), graylog2-web-interface/ (the frontend), data-node/ (a data node component), graylog-storage-elasticsearch7/ (the Elasticsearch 7 storage backend), graylog-storage-opensearch2/ (the OpenSearch 2 backend), and graylog-storage-opensearch3/ (the OpenSearch 3 backend).
The presence of three separate storage modules means Graylog abstracts its storage layer: the same core server can work against Elasticsearch 7, OpenSearch 2, or OpenSearch 3 depending on which storage module is configured. This is architecturally significant for teams planning long-term deployments, since both Elasticsearch and OpenSearch release major versions on different timelines.
The data-node/ directory suggests a distributed deployment model where processing nodes are separated from the storage backend. The graylog-plugin-parent/ and graylog-plugin-archetype/ directories indicate a plugin system for extending core functionality.
The project uses Maven as its build system (pom.xml, mvnw wrapper, .mvn/ directory) and is organized as a multi-module Maven project. The graylog-project-parent/ directory is a shared parent POM for dependency management across modules.
The UPGRADING.md file documents breaking changes between versions, which implies that major version upgrades require deliberate migration steps rather than a drop-in replacement.
Storage Backend Choices: Elasticsearch 7 and OpenSearch
Graylog's storage backend is the index where log messages are written and searched. The repository ships three separate storage modules: graylog-storage-elasticsearch7/ for Elasticsearch 7, graylog-storage-opensearch2/ for OpenSearch 2, and graylog-storage-opensearch3/ for OpenSearch 3.
Elasticsearch 7 and OpenSearch diverged following Elastic's license change in 2021. OpenSearch is an Apache-licensed fork maintained by Amazon Web Services. Graylog supports both paths, which means organizations already running one of these backends can choose the compatible module without switching their search infrastructure.
The choice of backend affects operational requirements. Both Elasticsearch and OpenSearch are JVM-based, memory-intensive services that need dedicated resources. Graylog does not bundle or embed either; the operator provisions and manages the backend cluster separately. This is a meaningful operational burden: a production Graylog deployment requires managing at least a Graylog server, a storage backend cluster, and a MongoDB instance (referenced in Graylog's public documentation), each with their own backup, scaling, and upgrade requirements.
The separation between graylog-storage-opensearch2/ and graylog-storage-opensearch3/ suggests that the OpenSearch 2-to-3 upgrade is not automatic and requires selecting the correct module.
License: SSPL v1 and What It Means in Practice
Graylog is released under version 1 of the Server Side Public License. The README states this directly and points to the LICENSE file. The SSPL is a source-available license that was created by MongoDB Inc. and adopted by projects that want to prevent cloud providers from offering the software as a hosted service without contributing back.
Under the SSPL, using Graylog to manage your own logs is free and unrestricted. The restriction applies if you offer Graylog as a service to others: in that case, you must release the complete source code of the service, including all orchestration software, management tooling, and infrastructure code. This is a significantly broader copyleft obligation than the AGPL.
For an internal deployment, the SSPL imposes no special burden. For a managed service provider or a SaaS company that wants to include Graylog as part of a product offered to external customers, the SSPL terms require either complying with the source disclosure obligation or obtaining a commercial license from Graylog Inc.
The SSPL is not approved by the Open Source Initiative as an open-source license. The Free Software Foundation has not endorsed it either. This is a point of contention in the community, and it means Graylog may be excluded from distributions and environments that require OSI-approved licenses.
Comparison with the ELK Stack and Getting Started
The ELK Stack (Elasticsearch, Logstash, Kibana) is the primary comparison point for Graylog. Both platforms use a search backend for log indexing and provide a web interface for query and visualization. The architectural difference is that the ELK Stack requires assembling and configuring three components independently: Logstash or Beats for data ingestion, Elasticsearch for storage, and Kibana for the interface. Graylog provides its own server as the management and ingestion layer and its own web interface, with the search backend (Elasticsearch or OpenSearch) as a configurable dependency.
The trade-off is between composability and integration. The ELK Stack gives operators more control over each component independently and benefits from Elastic's full ecosystem of beats and data collectors. Graylog offers a single administrative interface for the complete pipeline and ships with built-in features like GELF (Graylog Extended Log Format) for structured logging.
The README does not document installation steps. Installation is covered at docs.graylog.org. The documentation site describes installation paths for Docker, Debian/Ubuntu, and RHEL/CentOS, as well as the server.conf configuration file. The repository provides the CONTRIBUTING.md at github.com/Graylog2/graylog2-server/blob/master/CONTRIBUTING.md for developers who want to work on the codebase. Community support is available in the #graylog channels on Libera.chat and the community forums at community.graylog.org.
Maintenance Status and Upgrade Considerations
The last push to the repository was on 2026-09-25. The project is under active development. The repository has no GitHub releases listed; releases are tracked through the Maven versioning visible in the pom.xml and distributed through the official Graylog download channels.
The presence of UPGRADING.md is a practical signal: Graylog maintains explicit upgrade documentation because version migrations can require schema changes, configuration updates, or index migrations in the storage backend. This is common in Java-based platforms that evolve their data model. Teams running Graylog in production should consult UPGRADING.md before each major version change.
The changelog/ directory in the repository suggests that release notes are tracked per-version. The api-specs/ directory indicates that Graylog maintains a documented API, which is relevant for teams that automate Graylog configuration or query through the REST API.
The CONTRIBUTING.md offers a paid path for developers: "Do you want to get paid for developing our free and open product? Apply for one of our jobs." This means the core development team is employed by Graylog Inc., and the project is not a purely volunteer-maintained community effort.
Editorial conclusion
Graylog is worth considering for teams that need a free log management platform with a web interface and structured search, and who can operate their own Elasticsearch or OpenSearch cluster. The SSPL v1 license permits free use but restricts offering Graylog as a hosted service to others without a commercial license from Graylog Inc. Teams building a product on top of Graylog should review the SSPL terms directly. The official documentation at docs.graylog.org is where installation and configuration details live; the repository README itself does not provide them. Given the storage backend modules in the repository, verify that your chosen backend version (Elasticsearch 7, OpenSearch 2, or OpenSearch 3) is supported before committing to an upgrade path.
Frequently asked questions
Is Graylog free or paid?
The community edition of Graylog is free. The software is released under the Server Side Public License, which permits free use for managing your own logs. A commercial license is required only if you intend to offer Graylog as a hosted service to external customers.
Can Graylog be used as a syslog server?
The Graylog documentation at docs.graylog.org covers syslog input configuration; the repository README does not document this directly. The Graylog server is designed to accept log data from multiple sources including syslog, and the GELF format is a structured alternative for applications that can be instrumented.
What is Graylog used for?
Graylog is a centralized log management platform used to collect, index, and search log data from servers, applications, and infrastructure. It provides a web interface for searching logs, creating dashboards, and setting up alerts on log patterns.
Is Graylog still open-source?
Graylog is released under the Server Side Public License v1, which Graylog describes as free and open. The SSPL is not recognized as an open-source license by the Open Source Initiative. The source code is publicly available and free to use for internal log management.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/graylog2-graylog2-server)