[graylog2] Re: Graylog indicies

2016-05-16 Thread Mark Moorcroft
Personally I changed all the references to graylog in the conf files back to graylog2, and so far no issues with that stuff. All my indices came back as expected. On Thursday, May 12, 2016 at 11:52:22 PM UTC-7, kaiser wrote: > > Hello, > > I have updated graylog with current version 2.0 > >

[graylog2] Re: Graylog nodes unable to communicate with each other

2016-05-12 Thread Mark Moorcroft
, but prevents one from changing various inputs/settings or deleting indices. I think we need a third superuser account type. I have seen similar feedback from others here. What to do? On Thursday, May 12, 2016 at 3:50:28 PM UTC-7, Mark Moorcroft wrote: > > > I'm having a similar issue. I ha

[graylog2] Re: Graylog nodes unable to communicate with each other

2016-05-12 Thread Mark Moorcroft
I'm having a similar issue. I have things to a point where neither instance sees more than one "node". Both are seeing the elasticsearch indicies (one local, one not). The master node seems mostly operational. I set up a "slave" node for only one reason. The Graylog user levels made it

[graylog2] Re: Received by deleted input on outdated node?

2015-06-16 Thread Mark Moorcroft
ALL messages are relevant to every user. And unless I don't have a firm grasp of Streams, I found that option unacceptable. So I set up a second VM with full search but no way to mess with the archived data or delete inputs by mistake. On Tuesday, June 16, 2015 at 1:18:53 AM UTC-7, Jochen

[graylog2] Re: Received by deleted input on outdated node?

2015-06-15 Thread Mark Moorcroft
:50 UTC+2, Mark Moorcroft wrote: I asked this back in April and I'm still looking for an answer. I have a protected VM running graylog/mongo/elastic, and all of our actual graylog usage takes place on a slave VM due to the way user accounts work. My question is about the slave graylog log

[graylog2] Received by deleted input on outdated node?

2015-06-12 Thread Mark Moorcroft
I asked this back in April and I'm still looking for an answer. I have a protected VM running graylog/mongo/elastic, and all of our actual graylog usage takes place on a slave VM due to the way user accounts work. My question is about the slave graylog log events. They all show Received by

[graylog2] 1.1.2 kudos

2015-06-10 Thread Mark Moorcroft
When I did the 1.1.0 update it was essentially unusable. 1.1.1 at least eliminated the null pointer errors in search but I couldn't figure out how to see any detail on log entries. After installing 1.1.2 I am frankly WOW'ed by the new interface now that it actually seems to be working. Kudos

Re: [graylog2] Re: Graylog 1.1 rpm update issue on 1 of 2

2015-06-08 Thread Mark Moorcroft
please update to 1.1.1 and check if your problems are solved? Bernd Mark Moorcroft [Fri, Jun 05, 2015 at 04:13:52PM -0700] wrote: BTW and FWIW I am running the Oracle 8U45 JRE on both servers. In case that matters. On Thursday, June 4, 2015 at 8:42:08 PM UTC-7, Mark Moorcroft

[graylog2] Re: Graylog 1.1 rpm update issue on 1 of 2

2015-06-05 Thread Mark Moorcroft
common frames omitted On Thursday, June 4, 2015 at 8:42:08 PM UTC-7, Mark Moorcroft wrote: I yum updated both of my CentOS6 graylog servers to 1.1. The primary server where all the ES indexes reside seemed to have worked no problem. The second one that connects to the 1st seems to work perfectly

[graylog2] Re: Graylog 1.1 rpm update issue on 1 of 2

2015-06-05 Thread Mark Moorcroft
have no choice but to have some sort of local input now? So I guess the question is, what is the best throw-away input to have, since there is no reason for it to exist? On Thursday, June 4, 2015 at 8:42:08 PM UTC-7, Mark Moorcroft wrote: I yum updated both of my CentOS6 graylog servers to 1.1

[graylog2] Re: Graylog 1.1 rpm update issue on 1 of 2

2015-06-05 Thread Mark Moorcroft
Interestingly, if I increase the sleep period between random http messages I still get the null pointer exception. I'm at 3000 milliseconds now and I'm still getting the Oops. On Friday, June 5, 2015 at 12:03:29 PM UTC-7, Mark Moorcroft wrote: So the problem was that the only local input

[graylog2] Re: Graylog 1.1 rpm update issue on 1 of 2

2015-06-05 Thread Mark Moorcroft
statistics about the remote index values. I see details about the remote index size in Indices. Nodes mentions only the local index. Sources shows me info about all sources in the remote index. On Thursday, June 4, 2015 at 8:42:08 PM UTC-7, Mark Moorcroft wrote: I yum updated both of my CentOS6

[graylog2] Re: Graylog 1.1 rpm update issue on 1 of 2

2015-06-05 Thread Mark Moorcroft
$PromiseCompletingRunnable.run(Future.scala:24) ~[org.scala-lang.scala-library-2.10.4.jar:na] ... 6 common frames omitted On Thursday, June 4, 2015 at 8:42:08 PM UTC-7, Mark Moorcroft wrote: I yum updated both of my CentOS6 graylog servers to 1.1. The primary server where all the ES indexes reside seemed to have

[graylog2] Re: Graylog 1.1 rpm update issue on 1 of 2

2015-06-05 Thread Mark Moorcroft
BTW and FWIW I am running the Oracle 8U45 JRE on both servers. In case that matters. On Thursday, June 4, 2015 at 8:42:08 PM UTC-7, Mark Moorcroft wrote: I yum updated both of my CentOS6 graylog servers to 1.1. The primary server where all the ES indexes reside seemed to have worked

[graylog2] Graylog 1.1 rpm update issue on 1 of 2

2015-06-04 Thread Mark Moorcroft
I yum updated both of my CentOS6 graylog servers to 1.1. The primary server where all the ES indexes reside seemed to have worked no problem. The second one that connects to the 1st seems to work perfectly in every way, BUT any attempt to Search results in the Oops message. I see no errors in

[graylog2] Re: Read Only Users and Search and/or Stream which matches all messages

2015-05-19 Thread Mark Moorcroft
FWIW my solution to this was to create a second graylog virtual machine where all users are admin level. The second instance uses the elasticsearch index of the primary. This gives users full search ability without any way to go deleting the inputs by mistake. So far it appears to be a

[graylog2] com.fasterxml.jackson.core.JsonParseException:

2015-05-01 Thread Mark Moorcroft
This morning I was seeing bunches of errors in the server.log. I think I tracked them to a syslog/tcp input. My rsyslog entry on the client is as follows. # Graylog $template GRAYLOGRFC5424,%PRI%%PROTOCOL-VERSION% %TIMESTAMP:::date-rfc3339% %HOSTNAME% %APP-NAME% %PROCID% %MSGID%

[graylog2] Re: com.fasterxml.jackson.core.JsonParseException:

2015-05-01 Thread Mark Moorcroft
doesn't. On Friday, May 1, 2015 at 4:29:49 PM UTC-7, Mark Moorcroft wrote: This morning I was seeing bunches of errors in the server.log. I think I tracked them to a syslog/tcp input. My rsyslog entry on the client is as follows. -- You received this message because you are subscribed

[graylog2] Re: com.fasterxml.jackson.core.JsonParseException:

2015-05-01 Thread Mark Moorcroft
-server update. On Friday, May 1, 2015 at 4:29:49 PM UTC-7, Mark Moorcroft wrote: This morning I was seeing bunches of errors in the server.log. I think I tracked them to a syslog/tcp input. My rsyslog entry on the client is as follows. # Graylog $template GRAYLOGRFC5424,%PRI%%PROTOCOL

[graylog2] Re: Filter or Drop messages from a specific source

2015-05-01 Thread Mark Moorcroft
So this is an undocumented (as of yet) method to have graylog filter an input as it feeds the elasticsearch index? If I do a search on the graylog site for drool I get nothing. On Thursday, April 30, 2015 at 10:43:38 PM UTC-7, temo tsurtsumia wrote: import org.graylog2.plugin.Message rule

[graylog2] Re: Graylog 1.0.2 blacklist

2015-04-30 Thread Mark Moorcroft
I asked a similar question recently (title Exclude strategy), but I never got any reply. On Thursday, April 30, 2015 at 12:59:21 PM UTC-7, temo tsurtsumia wrote: How to apply simply blacklist rules for dropping unnecessary messages -- You received this message because you are subscribed

[graylog2] graylog-server startup failing on boot

2015-04-30 Thread Mark Moorcroft
I have graylog/mongo/elastic installed via repo (RPM) on CentOS6. What I'm seeing is any time I reboot the VM graylog-server fails to start. It seems it tries to start up before elasticsearch has a chance to stabilize, because if I service graylog-server restart later it will work. The problem

[graylog2] Exclude strategy?

2015-04-28 Thread Mark Moorcroft
I'm wondering if anyone can suggest a strategy for eliminating certain classes of collected logged events. In particular I have 3 compute clusters. Each one does NAT DHCP for the compute nodes. I prefer that the head nodes continue to collect logged compute node traffic, but I have no need to

[graylog2] Oracle java updates?

2015-04-23 Thread Mark Moorcroft
The elasticsearch wisdom seems to be to use the Oracle JRE. But has anyone figured out how to keep the Oracle JRE updated on a standalone elastic server that never runs a browser. I can't seem to find any documentation about this. And I can't find any reference to a java command that checks

Re: [graylog2] Re: Increase JVM heap space

2015-04-16 Thread Mark Moorcroft
of the time, as it increases the garbage collection time. What are you trying to achieve with this? Cheers, Jochen On Thursday, 16 April 2015 00:06:03 UTC+2, Mark Moorcroft wrote: From my kickstart: sed -i -e 's/-Xms1g -Xmx1g -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server

[graylog2] Search advise

2015-04-10 Thread Mark Moorcroft
This is probably a dumb newb question, but at this moment it's not obvious to me. If I have a saved search like: dropping event AND queue is full Is it possible to see the list of Sources with the number of logged events per source ONLY, instead of 10 pages of results? I guess you could

[graylog2] Re: Best ElasticSearch version ?

2015-04-09 Thread Mark Moorcroft
Not exactly a Graylog issue, but yum update elasticsearch seems to fail entirely. It simply never finds any updates. I never noticed until just now. I updated the repo file to the 1.5 series, and it still found no updates pending. Finally I just downloaded the 1.4.4 and 1.5.1 RPM's and rpm

[graylog2] Questions about strategy

2015-03-30 Thread Mark Moorcroft
When I initially set out to replace free Splunk with Graylog the requirements were as follows: Create a central log collector with write access granted to only one person (non-tech manager) for compliance and forensics. The collected data includes about 8 CentOS boxes sending auditd and

[graylog2] Re: Questions about strategy

2015-03-30 Thread Mark Moorcroft
and secondary graylog VM's: # we don't want the graylog2 server to store any data, or be master node elasticsearch_node_master = false elasticsearch_node_data = false On Monday, March 30, 2015 at 12:15:39 PM UTC-7, Mark Moorcroft wrote: Initially I set up 2 completely separate Graylog VM's

[graylog2] Re: More Graylog/Elastic questions from the cheap seats

2015-03-26 Thread Mark Moorcroft
to the graylog interface isn't used, the more memory I give it, the more it will use. Also, I switched from OpenJDK to Oracle today. It complains that -XX:PermSize=128m -XX:MaxPermSize=256m from /etc/sysconfig/graylog-server are no longer supported. On Wednesday, March 25, 2015 at 7:31:38 PM UTC-7, Mark

Re: [graylog2] [ANN] Graylog 1.0.1 has been released

2015-03-26 Thread Mark Moorcroft
078 TORCH GmbH - A Graylog company Steckelhörn 11 20457 Hamburg Germany Commercial Reg. (Registergericht): Amtsgericht Hamburg, HRB 125175 Geschäftsführer: Lennart Koopmann (CEO) On 26 Mar 2015, at 01:28, Mark Moorcroft plak...@gmail.com wrote: Nice... BTW, I have been getting

[graylog2] Re: More Graylog/Elastic questions from the cheap seats

2015-03-26 Thread Mark Moorcroft
, but that index is totally empty. The default dynamically named index is filling, and I have increased the heap size there in /etc/sysconfig/elasticsearch. So the web interface is showing me status on the unused index (node). On Wednesday, March 25, 2015 at 7:31:38 PM UTC-7, Mark Moorcroft wrote

[graylog2] More Graylog/Elastic questions from the cheap seats

2015-03-25 Thread Mark Moorcroft
In looking at trying to increase the heap size today after a general overhaul of our logging system I was reminded about a few things I never seemed to get answers to in the past. Some of these statements are in fact questions. Setting mlockall in elasticsearch apparently does NOT set it for

[graylog2] Re: [ANN] Graylog 1.0.1 has been released

2015-03-25 Thread Mark Moorcroft
Nice... BTW, I have been getting This exception has been logged with id 6libgij97. quite a bit today when I click on the nodes link. This is happening on both of my graylog servers. On Monday, March 16, 2015 at 8:00:44 AM UTC-7, Jochen Schalanda wrote: Hi, I'm delighted to announce the

[graylog2] Re: More Graylog/Elastic questions from the cheap seats

2015-03-25 Thread Mark Moorcroft
:+CMSClassUnloadingEnabled-XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow But this at least seems to give you double the heap space. It's still not obvious how you should set mlockall. Or if I should even try. On Wednesday, March 25, 2015 at 7:31:38 PM UTC-7, Mark Moorcroft wrote: In looking at trying to increase

[graylog2] Re: [ANN] Graylog 1.0.1 has been released

2015-03-24 Thread Mark Moorcroft
It still says 1.0.0 for graylog-web at the bottom of the interface despite yum reporting 1.0.1. FYI On Monday, March 16, 2015 at 8:00:44 AM UTC-7, Jochen Schalanda wrote: Hi, I'm delighted to announce the release of Graylog 1.0.1 into the wild. This is purely a bug-fix release and

[graylog2] Re: [ANN] Graylog2 0.92.0 released

2014-12-03 Thread Mark Moorcroft
How long until I can yum update? On Monday, December 1, 2014 1:58:12 AM UTC-8, Jochen Schalanda wrote: Hi everyone, after an extended beta and release candidate phase we just released Graylog2 0.92.0. -- You received this message because you are subscribed to the Google Groups

[graylog2] Re: [ANN] Graylog2 0.92.0 released

2014-12-03 Thread Mark Moorcroft
.noarch Then you can add the new one: rpm -Uvh https://packages.graylog2.org/repo/packages/graylog2-0.92-repository-el6_latest.rpm Finally, yum update graylog2-server On Wednesday, December 3, 2014 9:07:13 PM UTC-5, Mark Moorcroft wrote: How long until I can yum update? On Monday

[graylog2] Re: Mirror server?

2014-11-13 Thread Mark Moorcroft
messages to the instance users can run searches on. If you were sending the log messages to both Graylog2 instances directly, you would need to set up filters and extractors on both of them and keep them in sync. Cheers, Jochen Am Mittwoch, 12. November 2014 22:06:48 UTC+1 schrieb Mark

[graylog2] Mirror server?

2014-11-12 Thread Mark Moorcroft
Question for the room: If I have a need to provide a LOCKED down graylog server for compliance, and second one that someone can actually use to do searches and monitor our systems. Is it considered a best practice to mirror the outputs from all of the systems to two nearly identical VM's? We

Re: [graylog2] Re: Root password shasum change fails

2014-11-12 Thread Mark Moorcroft
Thanks, in my haste I had failed to single quote the input. And changing the password allowed me to get away without doing so. Obviously PEBKAC though, and not a bug. Apologies On Friday, November 7, 2014 1:19:53 AM UTC-8, Jochen Schalanda wrote: Hi Mark, I just tried to reproduce this

Re: [graylog2] Re: Root password shasum change fails

2014-11-07 Thread Mark Moorcroft
Generally true, but when you are setting something up to hand off to a manager the game changes. So I just use a long random hash that he can store in case it's needed some day. On Fri, Nov 7, 2014 at 1:19 AM, Jochen Schalanda joc...@torch.sh wrote: The password for the authentication against

[graylog2] Root password shasum change fails

2014-11-06 Thread Mark Moorcroft
I am in the process of resetting all the passwords on our graylog server to hand over to the system owner. My old password works with the shasum instructions provided, but the new 14 character random one fails every time. Both the old and the new have special characters, but the new one will

[graylog2] Re: Root password shasum change fails

2014-11-06 Thread Mark Moorcroft
Looks like you can't use $. On Thursday, November 6, 2014 1:40:01 PM UTC-8, Mark Moorcroft wrote: I am in the process of resetting all the passwords on our graylog server to hand over to the system owner. My old password works with the shasum instructions provided, but the new 14

Re: [graylog2] Re: Root password shasum change fails

2014-11-06 Thread Mark Moorcroft
I had a dollar in the password itself. Since removing the dollar I have it working. Now I get to go back and change it in mongo and other places :-( On Thu, Nov 6, 2014 at 2:03 PM, Jochen Schalanda joc...@schalanda.name wrote: Hi Mark On 06.11.2014 22:46, Mark Moorcroft wrote: Looks like

[graylog2] Re: Graylog2 capabilities

2014-11-03 Thread Mark Moorcroft
You have to be an admin to configure or save a dashboard. There seems to be no way to have control of the search without having access to disable or remove inputs. It makes no sense to me at all. On Monday, November 3, 2014 2:15:46 PM UTC-8, Mave Zero wrote: Hello, we are looking into how we

[graylog2] Re: Rsync backup?

2014-10-23 Thread Mark Moorcroft
OK, disregard, I will be reporting to the backuppc forum since it appears any file in /var/log may abort the process. If I filter out /var/log I get success. On Tuesday, October 21, 2014 1:57:46 PM UTC-7, Mark Moorcroft wrote: I am just now discovering that I can't rsync backup my

[graylog2] Server fails to start

2014-10-22 Thread Mark Moorcroft
I rebooted my graylog2 box today and now I get the following: [root@graylog ~]# service graylog2-server start Starting graylog2-server: [ OK ] [root@graylog ~]# Exception in thread main java.lang.AssertionError: data were read beyond record size, check your

Re: [graylog2] Server fails to start

2014-10-22 Thread Mark Moorcroft
Thanks, I reverted my VM image and solved it that way. On Wednesday, October 22, 2014 3:58:50 PM UTC-7, lennart wrote: Hey Mark, can you post those Java errors/stacktraces? Thanks, Lennart On Thu, Oct 23, 2014 at 12:10 AM, Mark Moorcroft pla...@gmail.com javascript: wrote: I

[graylog2] Re: Export log

2014-09-10 Thread Mark Moorcroft
Amen, I agree 100%. On Monday, July 28, 2014 11:44:44 PM UTC-7, Dennis Brouwer wrote: Hi All, We are seriously looking into Graylog but for archiving purposes we would like to export the logging in Graylog back to normal Syslog format so we can GZIP it (we need to save logging for a

[graylog2] No Search in non-admin account?

2014-09-04 Thread Mark Moorcroft
Running the repo RPM version of GL2 from yesterday. I finally got around to adding our non-admin accounts in GL. When you log in there is no “Search” function anywhere to be found. And if you enter a search URL:

Re: [graylog2] Re: Newbie to graylog2

2014-08-26 Thread Mark Moorcroft
I have wondered that myself. On Friday, August 22, 2014 7:48:33 AM UTC-7, Foobar Geez wrote: A few questions: - What is the typical release cycle or how soon GL2 typically supports new Elasticsearch versions? I see from GL2 release notes that it supports v0.90 of Elasticsearch and the

Re: [graylog2] 443 as non-root?

2014-08-26 Thread Mark Moorcroft
All CentOS here. On Tue, Aug 26, 2014 at 11:05 AM, Lennart Koopmann lenn...@torch.sh wrote: Another think to look at when on Ubuntu: http://manpages.ubuntu.com/manpages/hardy/man1/authbind.1.html On Tue, Aug 26, 2014 at 8:02 PM, Mark Moorcroft plak...@gmail.com wrote: I have read