[graylog2] Re: windows DNS log extractor

2015-08-25 Thread Marsel Qako
Thank you, Marsel On Tuesday, August 25, 2015 at 12:50:17 AM UTC-7, Marsel Qako wrote: Hi All, I'm very new with graylog. I'm testing with sending my DNS logs from windows DNS server to graylog. I would like to have extracted correctly but i can't get it work. Does ony know an example i

[graylog2] windows DNS log extractor

2015-08-25 Thread Marsel Qako
Hi All, I'm very new with graylog. I'm testing with sending my DNS logs from windows DNS server to graylog. I would like to have extracted correctly but i can't get it work. Does ony know an example i can use to get me started? Of if anyone has an extractor they can share? Thank you for the

[graylog2] receiving netflow

2015-08-25 Thread Marsel Qako
HI, I would like to collect netflow from cisco devices into graylog. I haven't been able to find any documentation if it is supported. Is this a supported feature? Thank you, Marsel -- You received this message because you are subscribed to the Google Groups Graylog Users group. To

[graylog2] Re: receiving netflow

2015-08-26 Thread Marsel Qako
2015 00:40:38 UTC+2, Marsel Qako wrote: HI, I would like to collect netflow from cisco devices into graylog. I haven't been able to find any documentation if it is supported. Is this a supported feature? Thank you, Marsel -- You received this message because you are subscribed

[graylog2] Elasticsearch cluster is red.

2015-09-17 Thread Marsel Qako
Hi, I'm having an issue with elasticsearch. Any help would be really appreciated. The first time i had this issue i did a cleanse which fixed the issue for couple of days, but that deleted all my data. Every couple of days i'm getting the follwoing error *Elasticsearch cluster is red.*

[graylog2] Graylog_Content_Pack_WinDNS ThreadID error

2015-09-30 Thread Marsel Qako
Hi, I installed Graylog_Content_Pack_WinDNS from the market palce. I get the following error when it tries the grok pattern. It looks like it breaks at ThreadID. Has anyone had this issue before? [2015-09-30 11:07:38,089][DEBUG][action.bulk ] [Devil Hunter Gabriel]

[graylog2] rotation_strategy configuration

2015-09-25 Thread Marsel Qako
Hi, If i make any changes to rotation_strategy, elasticsearch_max_size_per_index,elasticsearch_max_time_per_index = 1h or elasticsearch_max_number_of_indices = 10 in the graylog.conf file, they all go back to default once i run graylog-ctl reconfigure. I have tried different combinations

[graylog2] Re: Elasticsearch cluster is red.

2015-09-18 Thread Marsel Qako
Hi Drew, Thank you for reply. I only have one node. No other errors except what i posted on the other logs files. I did a cleanse and after reconfiguring it, its working fine for now. On Thursday, September 17, 2015 at 9:06:56 PM UTC-7, Drew Miranda wrote: > > Are you able to do a cat on your

[graylog2] enforcing ssl

2016-03-30 Thread Marsel Qako
Hi, I installed Graylog v2.0 Beta.1. After enforcing ssl with graylog-ctl enforce-ssl and running graylog-ctl reconfigure, i get the following error: We are experiencing problems connecting to the Graylog server running on *http://x.x.x.x:12900/*. Please verify that the server is healthy and

[graylog2] Not able to authenticate using AD Graylog 2.0.0-beta.2

2016-04-05 Thread Marsel Qako
Hi, I can't authenticate using AD. I get invalid credentials error. The configuration is the same as graylog v1.3.3, which works fine. Looking at the server logs i get the error below. 2016-04-05_19:05:07.69721 2016-04-05 12:05:07,695 WARN :

[graylog2] Re: Graylog 2.0.0-beta.1 Could not retrieve Inputs

2016-04-05 Thread Marsel Qako
Jochen > > On Friday, 1 April 2016 23:27:27 UTC+2, Marsel Qako wrote: >> >> I stopped the inputs from running, and so far i'm able to create a new >> one and continue forward with the configuration. >> >> On Friday, April 1, 2016 at 11:24:18 AM UTC-7, Marsel Qako wro

[graylog2] Graylog 2.0.0-beta.2 errors in the logs

2016-04-05 Thread Marsel Qako
Hi all, I need some help with this error messages. Everything in the cluster seems to work fine, but i can't get rid of these errors. Any help would be appreciated. 2016-04-05_20:56:57.73210 2016-04-05 13:56:57,731 INFO : org.elasticsearch.cluster.service -

[graylog2] Re: Graylog 2.0.0-beta.2 errors in the logs

2016-04-06 Thread Marsel Qako
s about your setup and what problems you face. > > > Cheers, > Jochen > > On Tuesday, 5 April 2016 23:02:25 UTC+2, Marsel Qako wrote: >> >> Hi all, >> >> I need some help with this error messages. Everything in the cluster >> seems to wo

[graylog2] Graylog 2.0.0-beta.1 Could not retrieve Inputs

2016-04-01 Thread Marsel Qako
Hi, I installed Graylog 2.0.0-beta.1 OVA. After changing the default appliance-syslog-udp input, i get the following error Could not retrieve Inputs Fetching Inputs failed with status: Error: cannot GET http://x.x.x.x:12900/system/inputs (500)

[graylog2] Re: Graylog 2.0.0-beta.1 Could not retrieve Inputs

2016-04-01 Thread Marsel Qako
I stopped the inputs from running, and so far i'm able to create a new one and continue forward with the configuration. On Friday, April 1, 2016 at 11:24:18 AM UTC-7, Marsel Qako wrote: > > Hi, > > I installed Graylog 2.0.0-beta.1 OVA. After changing the default > appliance-sysl

[graylog2] Process buffer full in 2 node cluster

2016-04-29 Thread Marsel Qako
Hi, I'm running Graylog 2.0.0-rc.1 in a 2 node cluster. First node is primary running all services. Second node is configured as backend. When the secondary node is down, the primary can output around 8k messages per second. Once the secondary node is up and running the output will get down

[graylog2] graylog not working after upgrading to v2.2.0 from 2.1.2

2017-02-17 Thread Marsel Qako
Hi, I have two graylog servers clustered. One is configured as the master with full configuration the other as bakend-server. I upgraded both virtual appliances from 2.1.2 to 2.2.0. Before the upgrade everything was working fine. Now i have multiple errors and no logs show when searching.

[graylog2] graylog messages In 0 / Out 0 msg/s.

2016-09-27 Thread Marsel Qako
Hi all, I have a cluster of two graylog (one configured as server and one as backend), The messages processing on the primary keep jumping from mostly In 0 / Out 0 msg/s. to couple hundred, sometimes to over couple thousands. I don't see any errors on elasticsearch logs, or server logs.