Network activity monitoring is an important process in maintaining service availability and supporting information technology infrastructure security in enterprise environments. Network devices generate log data that can be utilized to monitor system activities, detect network disruptions, and support analysis processes. However, managing logs distributed across multiple devices often makes monitoring activities less effective and more difficult for network administrators. This study aims to implement Graylog as a network activity monitoring system using Syslog to provide centralized log management. The research method consisted of system requirement identification, architecture design, Graylog implementation on Ubuntu Server 22.04.5 LTS, Syslog UDP configuration on a Cisco SG300-28PP switch, and testing of log collection and visualization processes. The system was developed using Graylog 6.1.16 as the log management platform, OpenSearch 2.19.5 as the indexing and search engine, and MongoDB 7.0.34 as the configuration database. The results show that Graylog successfully receives, stores, manages, and displays log data generated by network devices in a centralized manner. In addition, the search and dashboard features provide structured visualization of network activities, enabling administrators to perform monitoring and analysis more efficiently. Based on the testing results, all major functions of the monitoring system operated as expected. Therefore, the implementation of Graylog and Syslog can be considered an effective solution for centralized network activity monitoring in enterprise environments.
Copyrights © 2026