Graylog is a log management and SIEM platform for security, IT and audit teams. It began in 2009 as an open source log management project and grew into a full SIEM on the same codebase. It collects logs from many sources, groups related alerts into incidents, assembles investigation timelines and includes pre-built detection content. The product line comprises Graylog Open, Graylog Enterprise, Graylog Security and Graylog API Security. Graylog is available as Graylog Cloud, hosted by Graylog, and as a self-managed installation, including in air-gapped environments.
Graylog is headquartered in Houston, Texas, in the United States, with offices in London and in Hamburg (Graylog Germany GmbH). Graylog Open is free and self-managed under the Server Side Public License (SSPL), and Graylog itself describes it as source-available. The website does not state in which region Graylog Cloud runs. An organisation that wants to keep data within the EU can run the self-managed edition on its own infrastructure, which leaves the vendor's US jurisdiction relevant mainly to licensing and support.