https://www.reddit.com/r/sysadmin/comments/3xymfu/splunk_vs_graylog_vs_elk_ease_of_configuration/
https://www.reddit.com/r/devops/comments/4jsuo2/elk_stack_vs_graylog/
ELK for devs, graylog for Ops (alerting is important). Logstash does the routing.
it