[graylog2] Re: Graylog Email Callbacks - which fields/variables can I use?

2016-06-01 Thread Dennis Seaton
.graylog.org/en/1.3/pages/streams.html#alert-callbacks-types-explained > > in your email template (scroll down a little bit). > > In your case, you would access the ad_username field of the message with > ${message.fields.ad_username}. > > Cheers, > Jochen > > On T

[graylog2] "Empty" messages received from Graylog Collector

2016-05-10 Thread Dennis Seaton
We are using Graylog2 v1.3.4 with Graylog Collector 0.4.1 to grab logs from our Windows machines. I have noticed an issue where some log entries are being replaced with the word "Empty" in the message field (all the other fields are correct). These are valid log entries which are not empty;

[graylog2] "Empty" log entries from Windows Event Logs

2016-05-10 Thread Dennis Seaton
We are using Graylog2 v1.3.4 with GrayLog collector v0.4.1 on our Windows boxes to collect Windows Event Logs. I notice that on all of these Windows machines we are often (1 in 20) receiving log entries where the message field contains the text "Empty" instead of the proper entry. Valuable

[graylog2] The Graylog Collector is Depreciated?

2016-05-09 Thread Dennis Seaton
Silly question: I notice the Graylog documentation has been updated and that the Graylog Collector is now depreciated with v2.0 GA. Looks like NXLog is recommended for Windows clients. so I want to go ahead and start switching over to NXLog, but the official docs also mention installing

[graylog2] Preventing Flooding

2016-03-19 Thread Dennis Seaton
We have concerns that any one of our machines could have an issue and suddenly start flooding Graylog with a million messages per second (as an example) and filling up all our indexes and disk space 1000x faster than anticipated while we were away for the weekend; we have fears of coming in on

[graylog2] "Collectors" page vs "Sources" page

2016-03-15 Thread Dennis Seaton
In Graylog if I click "System" on the menu, then "Collectors", I only see about 10 Collectors listed - even if I hit the "Include Inactive Collectors" button. However, if I click "Sources" from the menu it shows me that we in fact have at least 50 collectors up and running perfectly. So...

[graylog2] Dashboard doesn't stay "locked"

2016-03-10 Thread Dennis Seaton
We've been experimenting with dozens of dashboards and notice that regardless of if the dashboard is "locked" or not it frequently re-arranges the widgets graphs and other items we have placed. It seems to want to adjust them based on the browser resolution you are using, or something like

[graylog2] Graylog DNS resolution

2016-02-18 Thread Dennis Seaton
On our DNS server one of my machines has two A records, and two corresponding PTR records. ie: server1 = 10.10.10.1 server001 = 10.10.10.1 This causes Graylog to treat this server as two different sources, it splits all input from that collector 50/50, some log entries show as source

[graylog2] Re: Collecting logs from OSX 10.11 El Capitan

2016-02-18 Thread Dennis Seaton
g.org/en/1.3/pages/sending_data.html#sending-syslog-from-macos-x-hosts > > > Cheers, > Jochen > > On Wednesday, 17 February 2016 20:12:01 UTC+1, Dennis Seaton wrote: >> >> Has anyone had success collecting logs from OSX? What about El Capitan >> (v10.11.3)? &g

[graylog2] Collecting logs from OSX 10.11 El Capitan

2016-02-17 Thread Dennis Seaton
Has anyone had success collecting logs from OSX? What about El Capitan (v10.11.3)? >From what I find on Google it USED to be as simple as adding a line to your syslog.conf file in OSX: **.* mygraylog.server.com* But that doesn't appear to work anymore, and if you look at the syslog.conf

[graylog2] Re: Dealing with rotating log files

2016-02-11 Thread Dennis Seaton
Good info, thanks Jochen -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+unsubscr...@googlegroups.com. To view this discussion on the web visit

[graylog2] Dealing with rotating log files

2016-02-10 Thread Dennis Seaton
Hello, I am new to Graylog and looking for suggestions on how to get rotating log files (text files) into Graylog2. I have several apps that use rotating log files, these apps are not syslog capable, and the format of their log files cannot be altered. Here's an example of how they are named:

[graylog2] Dealing with rotating log files

2016-02-10 Thread Dennis Seaton
Hello, I am looking for suggestions -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+unsubscr...@googlegroups.com. To view this discussion on the