[graylog2] Re: Store full message in Grayog Use??

2016-10-25 Thread Jochen Schalanda
Hi, On Tuesday, 25 October 2016 16:08:32 UTC+2, Anant Sawant wrote: > > What is the use of this option?. > That setting will store the raw/unparsed syslog message into the full_message field for further processing. If that setting is false, Graylog will only store the parsed and evaluated

[graylog2] Store full message in Grayog Use??

2016-10-25 Thread Anant Sawant
Hi Graylog Team In syslog udp/tcp inputs there is the following option. "Store full message? (optional)" What is the use of this option?. Does it mean if I send logs/data to Graylog via syslog, when the above option is *unchecked *Graylog is not storing the complete log but incomplete or

[graylog2] Re: Custom Graylog development query

2016-10-25 Thread Jochen Schalanda
Hi, On Tuesday, 25 October 2016 16:01:29 UTC+2, Anant Sawant wrote: > > Is it possible to delete logs from graylog based on different inputs. > That's not possible with Graylog directly, but you can use the Elasticsearch Delete by Query Plugin

[graylog2] Custom Graylog development query

2016-10-25 Thread Anant Sawant
Hi Graylog Team Is it possible to delete logs from graylog based on different inputs. I have two inputs on udp syslog from two different machines pointed to single graylog instance. Can i selectively delete particular logs based on date and time or based on the inputs. If the answer is

[graylog2] Re: use logstash + gelf to send logs to graylog

2016-10-25 Thread Jochen Schalanda
Hi, what kind of input did you create in Graylog and how did you configure it? I'm also not sure if you really want to have that TCP input in Logstash… FWIW, if you only want to read files and send their contents to Graylog, I'd recommend using Filebeat or nxlog which can both be managed via

[graylog2] Re: Graylog 2.1 on Ubuntu 16.04 - no web interface, no port 9000

2016-10-25 Thread Marcio Merlone
Em terça-feira, 25 de outubro de 2016 10:05:57 UTC-2, Benbrahim Anass escreveu: > > r u sure the port 9000 is open? try a telnet on it > No! It was the other way around, it does NOT open port 9000, tested with netstat, lsof and nmap. But as I said, changed from Oracle to OpenJDK and now it

[graylog2] Re: use logstash + gelf to send logs to graylog

2016-10-25 Thread Benbrahim Anass
yea i already saw that, here is my conf input { tcp { type => "tcp" port => "12201" } file { path => "/var/log/messages" type => "rsyslog" start_position => "beginning" } } output {

[graylog2] Re: Elasticsearch upgrade to 5.0, migraton helper plugin - red node settings meaning

2016-10-25 Thread Jochen Schalanda
Hi, Graylog (as of version 2.1.1) doesn't support Elasticsearch 5.x, also see http://docs.graylog.org/en/2.1/pages/installation.html#system-requirements. Cheers, Jochen On Tuesday, 25 October 2016 12:57:18 UTC+2, Aykisn wrote: > > Hello, > > I am planning on upgrading my elasticsearch cluster

[graylog2] Re: use logstash + gelf to send logs to graylog

2016-10-25 Thread Jochen Schalanda
Hi, On Tuesday, 25 October 2016 13:19:51 UTC+2, Benbrahim Anass wrote: > > i'm wondering if is it possible to send logs via logstash/gelf to > Graylog2, if it is, i'm gonna need an exemple of a logstash output via GELF > Of course that's possible. See

[graylog2] Re: Graylog 2.1 on Ubuntu 16.04 - no web interface, no port 9000

2016-10-25 Thread Benbrahim Anass
r u sure the port 9000 is open? try a telnet on it Le mardi 25 octobre 2016 13:55:04 UTC+2, Marcio Merlone a écrit : > > Hi all! > > I am setting up a standalone graylog server on a Ubuntu 16.04 LTS. I went > trough the docs > http://docs.graylog.org/en/2.1/pages/installation/os/ubuntu.html

[graylog2] Graylog 2.1 on Ubuntu 16.04 - no web interface, no port 9000

2016-10-25 Thread Marcio Merlone
Hi all! I am setting up a standalone graylog server on a Ubuntu 16.04 LTS. I went trough the docs http://docs.graylog.org/en/2.1/pages/installation/os/ubuntu.html just fine, Graylot starts but I get no web ui, it does not bind to port 9000 (which is free, no one else is there). Any hint?

[graylog2] use logstash + gelf to send logs to graylog

2016-10-25 Thread Benbrahim Anass
i'm wondering if is it possible to send logs via logstash/gelf to Graylog2, if it is, i'm gonna need an exemple of a logstash output via GELF Thanks cheers anas -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group

[graylog2] Re: Elasticsearch cluster unavailable (I dont have a CLuster)

2016-10-25 Thread 'Schwään' via Graylog Users
i trie it but it shows the massage again -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+unsubscr...@googlegroups.com. To view this discussion on the

[graylog2] Re: Elasticsearch cluster unavailable (I dont have a CLuster)

2016-10-25 Thread 'Schwään' via Graylog Users
but i dont use a cluster Am Dienstag, 25. Oktober 2016 10:06:55 UTC+2 schrieb Schwään: > > Hello, > > when i Start the Webconfig of Graylog it says > Elasticsearch cluster unavailable > > but i dont have a cluster and don´t have configured a cluster. > > > -- You received this message because

[graylog2] Re: Elasticsearch cluster unavailable (I dont have a CLuster)

2016-10-25 Thread Jochen Schalanda
Hi On Tuesday, 25 October 2016 12:11:54 UTC+2, Schwään wrote: > > Elasticsearch Config You haven't set a cluster name in your Elasticsearch configuration. See http://docs.graylog.org/en/2.1/pages/configuration/elasticsearch.html#cluster-name for details. Cheers, Jochen -- You received

[graylog2] Re: Elasticsearch cluster unavailable (I dont have a CLuster)

2016-10-25 Thread Jochen Schalanda
Hi, On Tuesday, 25 October 2016 12:13:40 UTC+2, Schwään wrote: > > Und ich habe gerade gemerkt das wir das eventuell auch auf Deutsch klären > könnten da mein Englisch nicht so gut ist > Damit andere Leute, die ein ähnliches Problem haben, den Verlauf verfolgen können, würde ich dich bitten,

[graylog2] Re: Elasticsearch cluster unavailable (I dont have a CLuster)

2016-10-25 Thread 'Schwään' via Graylog Users
Und ich habe gerade gemerkt das wir das eventuell auch auf Deutsch klären könnten da mein Englisch nicht so gut ist Am Dienstag, 25. Oktober 2016 10:06:55 UTC+2 schrieb Schwään: > > Hello, > > when i Start the Webconfig of Graylog it says > Elasticsearch cluster unavailable > > but i dont have

[graylog2] Re: Elasticsearch cluster unavailable (I dont have a CLuster)

2016-10-25 Thread 'Schwään' via Graylog Users
Elasticsearch Config # Elasticsearch Configuration >> = > > # > > # NOTE: Elasticsearch comes with reasonable defaults for most settings. > > # Before you set out to tweak and tune the configuration, make sure >> you > > # understand

[graylog2] Re: Could not Load field indormation

2016-10-25 Thread Jochen Schalanda
Hi, search in Graylog unsurprisingly doesn't work without Elasticsearch… https://groups.google.com/d/msg/graylog2/1YInasM05Qw/xlwtCvMqBgAJ Cheers, Jochen On Tuesday, 25 October 2016 11:41:31 UTC+2, Schwään wrote: > > I Try to use my Server in Graylog but it shows > > *Could not load field

[graylog2] Re: Elasticsearch cluster unavailable (I dont have a CLuster)

2016-10-25 Thread Jochen Schalanda
Hi, On Tuesday, 25 October 2016 11:25:02 UTC+2, Schwään wrote: > > this is my graylog log i dont know what to do > Check the logs of your Elasticsearch node(s) and post the configuration of your Graylog and Elasticsearch node(s) so that we can take a look at it. In general, please refer to

[graylog2] Could not Load field indormation

2016-10-25 Thread 'Schwään' via Graylog Users
I Try to use my Server in Graylog but it shows *Could not load field information* *Loading field information failed with status: cannot GET http://10.250.20.60:9000/api/system/fields (500* -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To

[graylog2] Re: Elasticsearch cluster unavailable (I dont have a CLuster)

2016-10-25 Thread 'Schwään' via Graylog Users
this is my graylog log i dont know what to do 2016-09-27T04:44:10.604+02:00 ERROR [AnyExceptionClassMapper] Unhandled exception in REST resource org.elasticsearch.discovery.MasterNotDiscoveredException at

[graylog2] Elasticsearch cluster unavailable (I dont have a CLuster)

2016-10-25 Thread 'Schwään' via Graylog Users
Hello, when i Start the Webconfig of Graylog it says Elasticsearch cluster unavailable but i dont have a cluster and don´t have configured a cluster. -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop

[graylog2] Re: [IndexerSetupService] Could not connect to Elasticsearch || [IndexerSetupService] If you're using multicast, check that it is working in your network and that Elasticsearch is accessibl

2016-10-25 Thread Jochen Schalanda
Hi Bernadette, please refer to http://docs.graylog.org/en/2.1/pages/configuration/elasticsearch.html#elasticsearch-versions for the list of Elasticsearch versions used by Graylog. Please keep in mind that Graylog 1.1.3 is a pretty old version and I'd recommend upgrading to at least Graylog

[graylog2] Re: GELF VIA HTTP No Message

2016-10-25 Thread Jochen Schalanda
Hi, you're missing the mandatory "version" field, see http://docs.graylog.org/en/2.1/pages/gelf.html#gelf-format-specification for details. Cheers, Jochen On Monday, 24 October 2016 23:09:57 UTC+2, chris...@maxionwheels.com wrote: > >