Why to log centrally? (osc24) episode artwork

EPISODE · Jun 28, 2024 · 39 MIN

Why to log centrally? (osc24)

from Chaos Computer Club - archive feed · host Peter Czanik

Why is central logging so important? Convenience, availability and security. Convenience, as you have a single place to check instead of many. Availability, as you can check log messages, even if the sending host is unavailable. Security, as logs leave hosts as soon as they are produced, so an attacker has no chance to modify them. Developers, operators, and security have a single view of the whole network and can easily correlate events from multiple hosts. Often, the various tools to analyze log messages provide you with their own agents to forward logs to SIEM or other analytics tools. However, this is inefficient for several reasons. Most importantly, it is a waste of computing resources. You install multiple applications to do the same job: forwarding log messages. And these messages then travel through your network multiple times. So, what you should do instead is build a dedicated log management layer for central log collection. This ensures that log messages are collected only once. Using the OpenTelemetry protocol, logs, traces and metrics can be collected together, simplifying the architecture of collecting data about your infrastructure even further. From this talk, you can learn how to implement central logging using syslog-ng and how OpenTelemetry changes logging. Syslog-ng in openSUSE Tumbleweed already supports the OpenTelemetry protocol. Why is central logging so important? Convenience, availability and security. Convenience, as you have a single place to check instead of many. Availability, as you can check log messages, even if the sending host is unavailable. Security, as logs leave hosts as soon as they are produced, so an attacker has no chance to modify them. Developers, operators, and security have a single view of the whole network and can easily correlate events from multiple hosts. Often, the various tools to analyze log messages provide you with their own agents to forward logs to SIEM or other analytics tools. However, this is inefficient for several reasons. Most importantly, it is a waste of computing resources. You install multiple applications to do the same job: forwarding log messages. And these messages then travel through your network multiple times. So, what you should do instead is build a dedicated log management layer for central log collection. This ensures that log messages are collected only once. Using the OpenTelemetry protocol, logs, traces and metrics can be collected together, simplifying the architecture of collecting data about your infrastructure even further. From this talk, you can learn how to implement central logging using syslog-ng and how OpenTelemetry changes logging. Syslog-ng in openSUSE Tumbleweed already supports the OpenTelemetry protocol. about this event: https://c3voc.de

Episode metadata supplied by the publisher feed · Published Jun 28, 2024

Embed this episode

NOW PLAYING

Why to log centrally? (osc24)

0:00 39:19

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Chaos Computer Club - archive feed?

This episode is 39 minutes long.

When was this Chaos Computer Club - archive feed episode published?

This episode was published on June 28, 2024.

Can I download this Chaos Computer Club - archive feed episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!