As part of trying to make our environment more manageable, secure, and available - I've had a desire to consolidate logs to a centralized location for identifying issues, reporting, trending, etc. Splunk is pretty slick, but frankly our budget would never accommodate purchasing it and we would go through the 500mb/day volume so the free version won't cut it.
Has anybody worked with anything somewhat similar? To be honest, anything is better than what we're doing now - which is essentially ignoring all log files unless we are aware of some sort of problem. It doesn't have to be as searchable as Splunk is - which seems to be one of it's strongest points. Simply consolidating logs to central point and checking for particular logged events and alerting, archival, and perhaps some graphing ability would be nice but not required. Alerting on particular events and just archiving logs in case we need to reference past logs in the future are the two primary features I'd like.
So far I'm leaning towards setting up a simple Linux server with rsyslog and LogAnalyzer (formerly phpLogCon) but was wondering if any of the brilliant minds on TE had any other suggestions before I get too far involved going this route