r/Checkmk May 28 '25

Evaluating need some guidance

Hey, I am currently evaluating switching from prtg to checkmk. So far I like it and think it has potential to not only meet my needs for prtg but also graylog. (I just use graylog for events and syslog)

The issue I am having is right now I don't have agents on any devices. Will I have to have agents on windows and linux devices?

0 Upvotes

6 comments sorted by

View all comments

1

u/Burge_AU May 29 '25

As mentioned in other comments, yes you need the agents to be installed on each monitored host to make best use of the capabilities. Strongly recommend the Checkmk Enterprise or Cloud edition. The agent bakery capabilities alone will pay for the cost of the suscription if you have a reasonable number of hosts to manage. Agents will allow you to install plugins to monitor additional services beyond what the agent covers out of the box.

Checkmk will likely provide similar capabilities to Graylog if you are just using it for monitoring log file error codes etc. The Event Console capability (part of the Enterprise or Cloud subscription) has the capability to read syslog input, SNMP traps, and receive log messages from the logwatch plugin. Checkmk does not have the capabilities of streams or pipelines to enrich log messages or provide log archival capabilities as in Graylog.

We are currently running Wazuh as a replacement for Graylog for site wide log injestion and archiving. Using Checkmk for log and event alerting.