Re: [graylog2] Graylog Web Interface Internal Server Error

2015-10-26 Thread Michel Laporte
Sure,

Sorry for the delay i was out of the country.

As for the Graylog Web interface, i don't get any errors when i click 
sources and get the error " Could not load histogram data. Loading 
Histogram data failed with status : BAD REQUEST".

Graylog Web : http://pastebin.ca/3219548

It says there was a timeout i don't know if that is the key element on why 
it's timing out?

ES Didn't really give me no errors whilst i was tailing the logs.

Unsure if that means anything

On Tuesday, 20 October 2015 15:09:40 UTC+1, Edmundo Alvarez wrote:
>
> Hi Michel, 
>
> Could you please look into your ES and Graylog logs and share any errors 
> that you see while loading the data? 
>
> Regards, 
>
> Edmundo 
>
> > On 20 Oct 2015, at 10:49, Michel Laporte <michel@essencedigital.com 
> > wrote: 
> > 
> > Hi There, 
> > 
> > On the Graylog Web Interface, after a day or so, everytime i click on 
> "Sources" to try and view up to date log information, i get the following 
> error: 
> > 
> > 
> > Could not load sources data 
> > Loading of sources data failed with status: Internal Server Error. Try 
> reloading the page. 
> > 
> > However, on the right hand side if i click on anything other than Last 
> hour. . It works. So if i click on Last day , Week , All it shows me the 
> logs, however on the last hour i always get this error on internal server 
> error. Restarting Graylog & ES on the master node always sort this issue. 
> Does anyone know what the issue could be please? 
> > 
> > Thanks 
> > 
> > - 
> > essencedigital.com 
> > Google+ • Facebook • Twitter • YouTube 
> > 
> > -- 
> > You received this message because you are subscribed to the Google 
> Groups "Graylog Users" group. 
> > To unsubscribe from this group and stop receiving emails from it, send 
> an email to graylog2+u...@googlegroups.com . 
> > To view this discussion on the web visit 
> https://groups.google.com/d/msgid/graylog2/0b9c73d1-1505-40c5-a344-3e87c070baca%40googlegroups.com.
>  
>
> > For more options, visit https://groups.google.com/d/optout. 
>
>
-- 
-
essencedigital.com <http://www.essencedigital.com/>
Google+ <https://plus.google.com/102138558390623994587/about> • Facebook 
<http://www.facebook.com/essencedigital> • Twitter 
<https://twitter.com/essencedigital> • YouTube 
<http://www.youtube.com/essencedigitalvideos>

-- 
You received this message because you are subscribed to the Google Groups 
"Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to graylog2+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/graylog2/876213c1-0367-4185-b20c-51fc652fa7fc%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[graylog2] Graylog Web Interface Internal Server Error

2015-10-20 Thread Michel Laporte
Hi There,

On the Graylog Web Interface, after a day or so, everytime i click on 
"Sources" to try and view up to date log information, i get the following 
error:


Could not load sources data
Loading of sources data failed with status: Internal Server Error. Try 
reloading the page.

However, on the right hand side if i click on anything other than Last 
hour. . It works. So if i click on Last day , Week , All it shows me the 
logs, however on the last hour i always get this error on internal server 
error. Restarting Graylog & ES on the master node always sort this issue. 
Does anyone know what the issue could be please?

Thanks

-- 
-
essencedigital.com 
Google+  • Facebook 
 • Twitter 
 • YouTube 


-- 
You received this message because you are subscribed to the Google Groups 
"Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to graylog2+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/graylog2/0b9c73d1-1505-40c5-a344-3e87c070baca%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[graylog2] Re: Graylog Sources Tab always showing Error "Could not load histogram Data"

2015-10-08 Thread Michel Laporte
I've just realised that this happens every 2 or so hours on the dot.



On Wednesday, 7 October 2015 11:22:31 UTC+1, Michel Laporte wrote:
>
> Hi Jochen,
>
> Is there any way to reduce the pauses from the Java GC? Or any way around 
> that? Someone from ES also told me it might be the GC pauses.
>
> Thanks
>
> On Monday, 5 October 2015 22:01:30 UTC+1, Jochen Schalanda wrote:
>>
>> Hi Michel,
>>
>> this looks like the Graylog server node is losing connection to the 
>> Elasticsearch cluster occasionally. It might be connected to long GC pauses 
>> in the Graylog server process. Do you see any error messages in the logs of 
>> your Graylog server node?
>>
>> You can also activate GC logging as described at 
>> https://plumbr.eu/blog/garbage-collection/understanding-garbage-collection-logs
>> .
>>
>>
>> Cheers,
>> Jochen
>>
>> On Monday, 5 October 2015 18:24:26 UTC+2, Michel Laporte wrote:
>>>
>>> Hi,
>>>
>>> 2 Main Errors i keep noticing is:
>>>
>>> 2015-10-05 11:36:44,406][WARN ][discovery.zen.publish] 
>>> [ess-lon-gray-003_master] timed out waiting for all nodes to process 
>>> published state [8625] (timeout [30s], pending nodes: 
>>> [[graylog2-server][IuYwswm-QGCfMoIIYEGyMA][ess-lon-gray-002][inet[/192.168.32.70:9350]]{client=true,
>>>  
>>> data=false, master=false}, 
>>> [ess-lon-gray-002_slave][Gy1EMkaTSgilwenuqw5o7Q][ess-lon-gray-002][inet[/192.168.32.70:9300]]])
>>>
>>>
>>> &
>>>
>>> [2015-10-05 11:47:54,495][INFO ][cluster.service  ] 
>>> [ess-lon-gray-003_master] removed 
>>> {[graylog2-server][IuYwswm-QGCfMoIIYEGyMA][ess-lon-gray-002][inet[/192.168.32.70:9350]]{client=true,
>>>  
>>> data=false, master=false},}, reason: 
>>> zen-disco-node_failed([graylog2-server][IuYwswm-QGCfMoIIYEGyMA][ess-lon-gray-002][inet[/192.168.32.70:9350]]{client=true,
>>>  
>>> data=false, master=false}), reason transport disconnected
>>>
>>> The second one states Transport Disconnected?
>>>
>>>
>>> You reckon that would be an issue with ES 1.4.2? Im withholding 
>>> upgrading yet just incase it messes up my config.
>>>
>>> Thanks
>>>
>>>
>>> On Monday, 5 October 2015 16:47:49 UTC+1, Jochen Schalanda wrote:
>>>>
>>>> Hi Michel,
>>>>
>>>> first of all I'd recommend upgrading to the latest stable version of 
>>>> Elasticsearch (which is Elasticsearch 1.7.2 
>>>> <https://www.elastic.co/downloads/past-releases/elasticsearch-1-7-2> 
>>>> at the time of writing).
>>>>
>>>> Are there any error messages in the logs of your Elasticsearch nodes?
>>>>
>>>>
>>>> Cheers,
>>>> Jochen
>>>>
>>>> On Monday, 5 October 2015 17:16:07 UTC+2, Michel Laporte wrote:
>>>>>
>>>>> Hi,
>>>>>
>>>>> I have 2 Graylog Servers both running ES instances. However, after 1-2 
>>>>> days of running, my Elasticsearch cluster always goes "No Active Master" 
>>>>> (Using KOPF) for about 10-15 minutes, then comes back up.
>>>>>
>>>>>
>>>>> When it comes back up, i can NEVER search for Sources. I get this 
>>>>> Error:
>>>>>
>>>>>
>>>>> Could not load histogram data
>>>>> Loading of histogram data failed with status: Bad Request
>>>>>
>>>>>
>>>>> However, if i select time to " All Week, or All month", data shows up, 
>>>>> but sometimes doesn't show the messages when you query it from the 
>>>>> source. 
>>>>> The only way to fix this is to restart ES on the Master then everything 
>>>>> comes back up and works fine.
>>>>>
>>>>>
>>>>> Could someone help me?
>>>>>
>>>>> So far i've increased Ram to 16GB on each Machine and dedicated 7GB 
>>>>> Heap to each one as i thought it would be RAM. However, after a few days 
>>>>> each machine has about 500-900MB of RAM free. They are both on Linux 
>>>>> Ubuntu 
>>>>> 14.04 Machines.
>>>>>
>>>>>
>>>>> Thanks (Errors Below)
>>>>>
>>>>>
>>>>> ES KOPF LOG:
>>>>> [2015-10-05 13:44:48] 
>>>>> {"status&qu

[graylog2] Re: Graylog Sources Tab always showing Error "Could not load histogram Data"

2015-10-07 Thread Michel Laporte
Hi Jochen,

Is there any way to reduce the pauses from the Java GC? Or any way around 
that? Someone from ES also told me it might be the GC pauses.

Thanks

On Monday, 5 October 2015 22:01:30 UTC+1, Jochen Schalanda wrote:
>
> Hi Michel,
>
> this looks like the Graylog server node is losing connection to the 
> Elasticsearch cluster occasionally. It might be connected to long GC pauses 
> in the Graylog server process. Do you see any error messages in the logs of 
> your Graylog server node?
>
> You can also activate GC logging as described at 
> https://plumbr.eu/blog/garbage-collection/understanding-garbage-collection-logs
> .
>
>
> Cheers,
> Jochen
>
> On Monday, 5 October 2015 18:24:26 UTC+2, Michel Laporte wrote:
>>
>> Hi,
>>
>> 2 Main Errors i keep noticing is:
>>
>> 2015-10-05 11:36:44,406][WARN ][discovery.zen.publish] 
>> [ess-lon-gray-003_master] timed out waiting for all nodes to process 
>> published state [8625] (timeout [30s], pending nodes: 
>> [[graylog2-server][IuYwswm-QGCfMoIIYEGyMA][ess-lon-gray-002][inet[/192.168.32.70:9350]]{client=true,
>>  
>> data=false, master=false}, 
>> [ess-lon-gray-002_slave][Gy1EMkaTSgilwenuqw5o7Q][ess-lon-gray-002][inet[/192.168.32.70:9300]]])
>>
>>
>> &
>>
>> [2015-10-05 11:47:54,495][INFO ][cluster.service  ] 
>> [ess-lon-gray-003_master] removed 
>> {[graylog2-server][IuYwswm-QGCfMoIIYEGyMA][ess-lon-gray-002][inet[/192.168.32.70:9350]]{client=true,
>>  
>> data=false, master=false},}, reason: 
>> zen-disco-node_failed([graylog2-server][IuYwswm-QGCfMoIIYEGyMA][ess-lon-gray-002][inet[/192.168.32.70:9350]]{client=true,
>>  
>> data=false, master=false}), reason transport disconnected
>>
>> The second one states Transport Disconnected?
>>
>>
>> You reckon that would be an issue with ES 1.4.2? Im withholding upgrading 
>> yet just incase it messes up my config.
>>
>> Thanks
>>
>>
>> On Monday, 5 October 2015 16:47:49 UTC+1, Jochen Schalanda wrote:
>>>
>>> Hi Michel,
>>>
>>> first of all I'd recommend upgrading to the latest stable version of 
>>> Elasticsearch (which is Elasticsearch 1.7.2 
>>> <https://www.elastic.co/downloads/past-releases/elasticsearch-1-7-2> at 
>>> the time of writing).
>>>
>>> Are there any error messages in the logs of your Elasticsearch nodes?
>>>
>>>
>>> Cheers,
>>> Jochen
>>>
>>> On Monday, 5 October 2015 17:16:07 UTC+2, Michel Laporte wrote:
>>>>
>>>> Hi,
>>>>
>>>> I have 2 Graylog Servers both running ES instances. However, after 1-2 
>>>> days of running, my Elasticsearch cluster always goes "No Active Master" 
>>>> (Using KOPF) for about 10-15 minutes, then comes back up.
>>>>
>>>>
>>>> When it comes back up, i can NEVER search for Sources. I get this Error:
>>>>
>>>>
>>>> Could not load histogram data
>>>> Loading of histogram data failed with status: Bad Request
>>>>
>>>>
>>>> However, if i select time to " All Week, or All month", data shows up, 
>>>> but sometimes doesn't show the messages when you query it from the source. 
>>>> The only way to fix this is to restart ES on the Master then everything 
>>>> comes back up and works fine.
>>>>
>>>>
>>>> Could someone help me?
>>>>
>>>> So far i've increased Ram to 16GB on each Machine and dedicated 7GB 
>>>> Heap to each one as i thought it would be RAM. However, after a few days 
>>>> each machine has about 500-900MB of RAM free. They are both on Linux 
>>>> Ubuntu 
>>>> 14.04 Machines.
>>>>
>>>>
>>>> Thanks (Errors Below)
>>>>
>>>>
>>>> ES KOPF LOG:
>>>> [2015-10-05 13:44:48] 
>>>> {"status":503,"name":"ess-lon-gray-002_slave","cluster_name":"graylogemea","version":{"number":"1.4.5","build_hash":"2aaf797f2a571dcb779a3b61180afe8390ab61f9","build_timestamp":"2015-04-27T08:06:06Z","build_snapshot":false,"lucene_version":"4.10.4"},"tagline":"You
>>>>  
>>>> Know, for Search"}
>>>> [2015-10-05 13:44:48] No active master, switching to basic mode
>>>>
>>>> -
>>>> essencedigital.com <http://www.essencedigital.com/>
>>>> Google+ <https://plus.google.com/102138558390623994587/about> • 
>>>> Facebook <http://www.facebook.com/essencedigital> • Twitter 
>>>> <https://twitter.com/essencedigital> • YouTube 
>>>> <http://www.youtube.com/essencedigitalvideos>
>>>>
>>>
-- 
-
essencedigital.com <http://www.essencedigital.com/>
Google+ <https://plus.google.com/102138558390623994587/about> • Facebook 
<http://www.facebook.com/essencedigital> • Twitter 
<https://twitter.com/essencedigital> • YouTube 
<http://www.youtube.com/essencedigitalvideos>

-- 
You received this message because you are subscribed to the Google Groups 
"Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to graylog2+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/graylog2/7f927c43-b7e1-4e12-834c-a0aa138ca6dd%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[graylog2] Graylog Sources Tab always showing Error "Could not load histogram Data"

2015-10-05 Thread Michel Laporte


Hi,

I have 2 Graylog Servers both running ES instances. However, after 1-2 days 
of running, my Elasticsearch cluster always goes "No Active Master" (Using 
KOPF) for about 10-15 minutes, then comes back up.


When it comes back up, i can NEVER search for Sources. I get this Error:


Could not load histogram data
Loading of histogram data failed with status: Bad Request


However, if i select time to " All Week, or All month", data shows up, but 
sometimes doesn't show the messages when you query it from the source. The 
only way to fix this is to restart ES on the Master then everything comes 
back up and works fine.


Could someone help me?

So far i've increased Ram to 16GB on each Machine and dedicated 7GB Heap to 
each one as i thought it would be RAM. However, after a few days each 
machine has about 500-900MB of RAM free. They are both on Linux Ubuntu 
14.04 Machines.


Thanks (Errors Below)


ES KOPF LOG:
[2015-10-05 13:44:48] 
{"status":503,"name":"ess-lon-gray-002_slave","cluster_name":"graylogemea","version":{"number":"1.4.5","build_hash":"2aaf797f2a571dcb779a3b61180afe8390ab61f9","build_timestamp":"2015-04-27T08:06:06Z","build_snapshot":false,"lucene_version":"4.10.4"},"tagline":"You
 
Know, for Search"}
[2015-10-05 13:44:48] No active master, switching to basic mode

-- 
-
essencedigital.com 
Google+  • Facebook 
 • Twitter 
 • YouTube 


-- 
You received this message because you are subscribed to the Google Groups 
"Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to graylog2+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/graylog2/b4b46738-9771-44b3-a0bb-ca63e5f460e9%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[graylog2] Re: Graylog Sources Tab always showing Error "Could not load histogram Data"

2015-10-05 Thread Michel Laporte
Hi,

2 Main Errors i keep noticing is:

2015-10-05 11:36:44,406][WARN ][discovery.zen.publish] 
[ess-lon-gray-003_master] timed out waiting for all nodes to process 
published state [8625] (timeout [30s], pending nodes: 
[[graylog2-server][IuYwswm-QGCfMoIIYEGyMA][ess-lon-gray-002][inet[/192.168.32.70:9350]]{client=true,
 
data=false, master=false}, 
[ess-lon-gray-002_slave][Gy1EMkaTSgilwenuqw5o7Q][ess-lon-gray-002][inet[/192.168.32.70:9300]]])


&

[2015-10-05 11:47:54,495][INFO ][cluster.service  ] 
[ess-lon-gray-003_master] removed 
{[graylog2-server][IuYwswm-QGCfMoIIYEGyMA][ess-lon-gray-002][inet[/192.168.32.70:9350]]{client=true,
 
data=false, master=false},}, reason: 
zen-disco-node_failed([graylog2-server][IuYwswm-QGCfMoIIYEGyMA][ess-lon-gray-002][inet[/192.168.32.70:9350]]{client=true,
 
data=false, master=false}), reason transport disconnected

The second one states Transport Disconnected?


You reckon that would be an issue with ES 1.4.2? Im withholding upgrading 
yet just incase it messes up my config.

Thanks


On Monday, 5 October 2015 16:47:49 UTC+1, Jochen Schalanda wrote:
>
> Hi Michel,
>
> first of all I'd recommend upgrading to the latest stable version of 
> Elasticsearch (which is Elasticsearch 1.7.2 
> <https://www.elastic.co/downloads/past-releases/elasticsearch-1-7-2> at 
> the time of writing).
>
> Are there any error messages in the logs of your Elasticsearch nodes?
>
>
> Cheers,
> Jochen
>
> On Monday, 5 October 2015 17:16:07 UTC+2, Michel Laporte wrote:
>>
>> Hi,
>>
>> I have 2 Graylog Servers both running ES instances. However, after 1-2 
>> days of running, my Elasticsearch cluster always goes "No Active Master" 
>> (Using KOPF) for about 10-15 minutes, then comes back up.
>>
>>
>> When it comes back up, i can NEVER search for Sources. I get this Error:
>>
>>
>> Could not load histogram data
>> Loading of histogram data failed with status: Bad Request
>>
>>
>> However, if i select time to " All Week, or All month", data shows up, 
>> but sometimes doesn't show the messages when you query it from the source. 
>> The only way to fix this is to restart ES on the Master then everything 
>> comes back up and works fine.
>>
>>
>> Could someone help me?
>>
>> So far i've increased Ram to 16GB on each Machine and dedicated 7GB Heap 
>> to each one as i thought it would be RAM. However, after a few days each 
>> machine has about 500-900MB of RAM free. They are both on Linux Ubuntu 
>> 14.04 Machines.
>>
>>
>> Thanks (Errors Below)
>>
>>
>> ES KOPF LOG:
>> [2015-10-05 13:44:48] 
>> {"status":503,"name":"ess-lon-gray-002_slave","cluster_name":"graylogemea","version":{"number":"1.4.5","build_hash":"2aaf797f2a571dcb779a3b61180afe8390ab61f9","build_timestamp":"2015-04-27T08:06:06Z","build_snapshot":false,"lucene_version":"4.10.4"},"tagline":"You
>>  
>> Know, for Search"}
>> [2015-10-05 13:44:48] No active master, switching to basic mode
>>
>> -
>> essencedigital.com <http://www.essencedigital.com/>
>> Google+ <https://plus.google.com/102138558390623994587/about> • Facebook 
>> <http://www.facebook.com/essencedigital> • Twitter 
>> <https://twitter.com/essencedigital> • YouTube 
>> <http://www.youtube.com/essencedigitalvideos>
>>
>
-- 
-
essencedigital.com <http://www.essencedigital.com/>
Google+ <https://plus.google.com/102138558390623994587/about> • Facebook 
<http://www.facebook.com/essencedigital> • Twitter 
<https://twitter.com/essencedigital> • YouTube 
<http://www.youtube.com/essencedigitalvideos>

-- 
You received this message because you are subscribed to the Google Groups 
"Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to graylog2+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/graylog2/f62d4ca4-e3c3-406f-83c4-c4bc336c17f5%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.