When comparing SolarWinds Log & Event Manager vs Fluentd, the Slant community recommends Fluentd for most people. In the question“What are the best log management, aggregation & monitoring tools?” Fluentd is ranked 2nd while SolarWinds Log & Event Manager is ranked 37th. The most important reason people chose Fluentd is:
Gives structure to unstructured logs.
Ranked in these QuestionsQuestion Ranking
Pro Has custom search for in-depth log analysis
The in-depth, custom search helps you search by IP addresses, user names, etc, enabling faster root cause analysis when troubleshooting network, system, application and database issues.
Pro Peripheral security for enhanced visibility into malicious activities
All-in-one security solution that includes file integrity monitoring (zero-day malware& APT detection), SQL Auditor and USB detection
Pro Active response to detect and respond to threats in real-time
Automated response to events, like deleting user account, sending warning messages, kill processes, log off user, adding user to privileged account groups, etc
Pro Reduced costs with straight-forward licensing
Licensed by nodes (not log volume). No add-on purchases, DBA or expensive consultant support required. Extensive number of free connectors. Reduces SIEM management, training and operational overhead for resource-sensitive security departments.
Pro Automated industry-standard rules and reports to meet compliance and audit requirements
Demonstrate compliance and meet audit requirements with out of the box compliance reports for HIPAA, SOX, PCI DSS, DISA STIG and many more. Beyond SIEM monitoring and remediation capabilities, Log & Event Manager includes stronger security and broader compliance capabilities – like, SQL Auditor, File Integrity Monitoring, Active Response and USB Defender.
Pro Intuitive interface
Graphical Web UI with easy to read customizable dashboards, and search functionality to find the right information among thousands of logs. Log data and events are represented in bar graphs, with respect to time, and you can easily drill down to the specific system or node that's generating excessive or suspicious traffic.
Pro Centralized threat detection improves security incident awareness
Real-time, in-memory event correlations, based on built-in and custom rules, for instantaneous detection of unauthorized application/user-activity, database, configuration changes and suspicious network traffic
Pro Logs everything in JSON
Gives structure to unstructured logs.
Pro Logs stored to FS buffer while network is down
Logs aren't lost due to network issues
Pro In-stream processing
With a list of 150+ plugins, Fluentd can perform all kinds of in-stream data processing tasks.
Pro Huge plugin ecosystem
Fluentd has a plugin ecosystem that has resulted in developers creating over 150 plugins for the service.
Pro Prioritizes simplicity and robustness
For example, inputs and outputs have built-in support for buffering, load-balancing, timeouts and retries so to be able to deliver data reliably.
Pro Free and open source
Licensed under Apache 2.0.
Pro Routing based on tags
Pro Exponential retry wait
Pro Copy to multiple storages
Pro Based on CRuby
Con Linux agent don't manage to read logs
Linux agent made do not manage to read system logs which are in the default format which LEM is supposed to manage and also the installer seems to mess up the system during install as it assumes you are using a sysv like init system.
Con Bad UI
UI is confusing and difficult to find the information from the logs which you are looking for
Con Windows only
SolarWinds Log & Event Manager only works on Windows.
Con Difficult to setup
Requires a significant time investment to get up and running.
Con Does not run on Windows
No Windows version is available.