When comparing Papertrail vs Sumo Logic, the Slant community recommends Papertrail for most people. In the question“What are the best log management, aggregation & monitoring tools?” Papertrail is ranked 5th while Sumo Logic is ranked 12th. The most important reason people chose Papertrail is:
To set Papertrail up, use NXLog, or simply direct logs to a URL provided by Papertrail. No proprietary agent.
Specs
Ranked in these QuestionsQuestion Ranking
Pros
Pro Easy set-up process
To set Papertrail up, use NXLog, or simply direct logs to a URL provided by Papertrail. No proprietary agent.
Pro Simple interface
The default view is mostly taken up by log events with a small row at the bottom for entering a search query, setting date range, accessing saved searches and enabling or disabling real-time logging.
Pro Event and search updates can be viewed in real-time
By default log events and searches in Papertrail are updated in real-time.
Pro Logs can be colorized via third-party software
Logs can be colorized by installing Stylish, a browser extension for Chrome and Firefox that overrides CSS stylesheets, and writing a custom stylesheet.
Papertrail's log entries have various attributes that can be used to change css properties for specific programs or systems, or based on message contents.
Logs can also be colorized within the actual logs by adding ANSI escape codes (will override user-specific colorization).
Pro Scalable
Sumo logic is entirely cloud based and very scalable.
Pro Flexible licensing model
Licensing cost is primarily determined by daily ingest of logs, however this is averaged out over 30 days instead of locking a user out of their own data after an arbitrary number of license breaches.
Pro Truly multi-tenant
Sumo Logic is truly multi-tenant, a single instance running on the server can serve multiple groups of users.
Pro A large set of supporting Apps
Allows customers to quickly setup and start getting actionable insights from their infrastructure by using Apps that integrate with various different platforms out of the box.
Cons
Con Expensive
Averages out at $8/GB/mo, which feels exorbitant.
Con Ridiculous free plan
Unfortunately, compared with other competitors, their free plan comes with only 50MB/month.
Con No built-in graphing
Papertrail can integrate with Librato Metrics and StatHat to graph event occurrence count over time, but there's no built-in way to visualize data.
Con Antiquated interface
The interface is simple, yet it is slow and hard to work with.
Con Useless need for collectors
You have to install a plugin on each host to collect logs, the collector is 89MBs and is written in Java. there's no reason to install a Java tool to send syslog data when Linux already does that natively. The memory footprint for Java-based apps is way too high and, in this case, completely unnecessary.
Con Does not support structured data
They don't support RFC5424 standard events
Con Install is very painful
Con Search is very difficult
Here's an example:_sourceCategory=*windows* _sourceName=Security (4771 OR 4768 OR 4776 OR 4625) | parse regex "EventIdentifier = (?<event_id>\d+?);" | parse regex "ComputerName = \"(?<hostname>.+?)\"" | parse regex "(?:Result|Failure|Error) Code:.+?(?<result_code>0x[A-Fa-f\d]+)\b" nodrop | where result_code !="0x0" AND event_id in ("4771", "4768", "4776","4625") | count by hostname
Con Indexing and search are very slow
Sending around 45000 events to it may take more than 3 minutes to show up in the interface.
Once they show up, a search may take up to 32 seconds to return results. On only 45000 events, the search should return in milliseconds.
Con Difficult / Confusing Interface
The service and interface are very confusing.
Con There can be issues with smaller vendors
There may be some issues when using devices and services for smaller vendors which are not officially supported by Sumo Logic.