[graylog2] Journal reader single-threaded?

2015-09-11 Thread David Dunstan
I'm looking to get some confirmation here ... We are running 1.1.2 with journaling on. We got ourselves into a situation where poor Elasticsearch latency caused our buffers and our journal to fill up. We addressed the ES problem (turned off throttling altogether), and Graylog started

[graylog2] Re: Extractors: Add field with static content

2015-09-11 Thread Jan
Sadly a static field only per input won't help me. The mentioned dools rules however seem to be the right approach. Thanks! Am Mittwoch, 9. September 2015 05:58:01 UTC+2 schrieb Drew Miranda: > I believe a static field can be configured per input. I don't have the web > interface in front

[graylog2] Small set up with 3 servers, "cluster.name"

2015-09-11 Thread Lasse Taul Bjerre
Hi, I’m faily new to Graylog, and setting up a small GrayLog installation. In the beginning, I just want to use it in my LAB. I will be forwarding event logs from ~50 Windows servers, 3 ESXi Hosts and the LABs firewall. My setup is based on the OVA / ESX appliance. I have

Re: [graylog2] Small set up with 3 servers, "cluster.name"

2015-09-11 Thread Marius Sturm
Hi Lasse, every time you run a reconfigure command on one of your hosts all configuration files are rewritten. The Elasticsearch cluster name is only a technical setting. It needs to be the same for the whole cluster but has no other consequences. On 11 September 2015 at 10:48, Lasse Taul Bjerre