[graylog2] Re: How to upgrade Graylog 2.1 > 2.2 ?

2017-02-15 Thread dheffem
On Wednesday, February 15, 2017 at 3:09:36 AM UTC-6, Jochen Schalanda wrote: > > Hi, > > you can find upgrade instructions in the documentation, depending on how > you've installed Graylog in the first place. > > Thanks. Very painless upgrade on Ubuntu. # wget

[graylog2] How to upgrade Graylog 2.1 > 2.2 ?

2017-02-14 Thread dheffem
I looked here http://docs.graylog.org/en/2.2/pages/upgrade.html and don't see any directions for upgrading Graylog 2.1 to 2.2. A Stackoverflow post[1] mentions backing up /etc/gralog2.conf and simply untarring the new graylog. Is this the correct upgrade path? I've already posted this

[graylog2] RE: Github page on giving Graylog read-access to non-admin users

2017-02-10 Thread dheffem
I've added LDAP auth to graylog 2.1.0-SNAPSHOT and assigned "Allow Reading" roles to all my streams. I want users in this role to be able to query the "regular" search data so I added a "Default Search" stream with a rule to match "^.*$" on the "message" field (for syslog). I've added "Allow

[graylog2] Re: Pipeline - Stream - Syslog output and customized messages

2017-01-06 Thread dheffem
On Friday, January 6, 2017 at 6:33:17 AM UTC-6, Frank wrote: > > > Plain shows the message without the fields that should be removed, but > also without the added custom fields. > Full and structured show the message with the custom fields, but also with > all fields that should be removed. >

[graylog2] Plugin API documentation?

2017-01-04 Thread dheffem
I've installed the Jabber Alarm Callback plugin and found it to be of little use and would like to make it a little more informative. It really only tells you about a specific stream triggered an alert for some reason but you have no idea about the event context. Is there a better source of

[graylog2] Help creating fields (Streams, Pipelines and Rules)

2016-12-23 Thread dheffem
I've setup Snort integration with Graylog via https://www.graylog.org/blog/64-visualize-and-correlate-ids-alerts-with-open-source-tools. It's working quite well. now that I have a place to store remote logs I thought I'd try and add those to Graylog too. I have syslog-ng listening on my