[graylog2] Re: grok and date conversion problem

2016-01-08 Thread Alex B.
Thank you for your answer, this really helps :) -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+unsubscr...@googlegroups.com. To view this discussion

[graylog2] Re: grok and subpatterns

2016-01-08 Thread Alex B.
Ok just have to wait for a fix then :) Thank you Jochen. -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+unsubscr...@googlegroups.com. To view this

[graylog2] Re: grok and subpatterns

2016-01-07 Thread Alex B.
Problem remains using graylog 1.3.2 -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+unsubscr...@googlegroups.com. To view this discussion on the web

[graylog2] Re: grok and date conversion problem

2016-01-07 Thread Alex B.
I'm using graylog 1.3.2 -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+unsubscr...@googlegroups.com. To view this discussion on the web visit

[graylog2] Re: Graylog collector and timestamp

2015-12-02 Thread Alex B.
> On Tuesday, 1 December 2015 17:20:02 UTC+1, Alex B. wrote: >> >> Hello, using graylog 1.2.2 and collector 0.4.1, there is a big difference >> between graylog timestamp and log file timestamp. >> >> A line in a logfile with a 17:11:34,887 timestamp can have a 17:11

[graylog2] grok and subpatterns

2015-12-01 Thread Alex B.
Hello, using graylog 1.2.2, i'm facing issues with grok sub-patterns. For example, with a message beginning with 2015-12-01 17:03:53,250, if in my extractor i have %{TIMESTAMP_ISO8601:date}, the resulting fields are : MONTHDAY 01 MONTHNUM 12 SECOND 53,250 YEAR 2015 date 2015-12-01 17:03:53,250

[graylog2] Graylog collector and timestamp

2015-12-01 Thread Alex B.
Hello, using graylog 1.2.2 and collector 0.4.1, there is a big difference between graylog timestamp and log file timestamp. A line in a logfile with a 17:11:34,887 timestamp can have a 17:11:53.328 timestamp in graylog, which is a 20 seconds difference ! I'm currently testing collector to

[graylog2] Grok extractor + break on match

2015-09-30 Thread Alex B.
Hello ! Is there a way to do things like that with graylog ? grok { break_on_match => true match => [ "message", "<%{POSINT:syslog_pri}>1 %{TIMESTAMP_ISO8601:syslog_time}

[graylog2] Dashboards problems

2015-07-21 Thread Alex B.
My dashboards widgets load very slowly, there is a warning icon on each widget : Error loading widget value: Gateway Timeout Nothing happens in graylog servers logs, but webinterface server logs get full with messages like this : 2015-07-21

Re: [graylog2] Delete all messages from specific host

2015-06-24 Thread Alex B.
When using wildcards, i get this error : { error : ClusterBlockException[blocked by: [FORBIDDEN/8/index write (api)];], status : 403 } Delete query only works if i specify the current index used by graylog. How can i delete entries from past indexes ? (which are not closed nor deleted,

Re: [graylog2] Delete all messages from specific host

2015-06-24 Thread Alex B.
Thank you so much ! I'm an elasticsearch newbie, learning new options everyday :) -- You received this message because you are subscribed to the Google Groups graylog2 group. To unsubscribe from this group and stop receiving emails from it, send an email to

[graylog2] Re: Graylog 1.1.2 and ES 1.6

2015-06-15 Thread Alex B.
in an incompatible way. Cheers, Jochen On Thursday, 11 June 2015 12:28:59 UTC+2, Alex B. wrote: Hello ! Is Graylog 1.1.2 ok to run on last ES 1.6 ? Ty -- You received this message because you are subscribed to the Google Groups graylog2 group. To unsubscribe from this group and stop