[graylog2] Re: graylog2 v0.20.1: UnavailableShardsException

2014-05-09 Thread Mark Nickolai
I stopped the job which was responsible for the massive amount of data. The server was still procucing these errors, so I used 'Manually cycling the deflector' After a few seconds my clus

[graylog2] Re: graylog2 v0.20.1: UnavailableShardsException

2014-05-09 Thread Mark Nickolai
By the way: Shards: 4 active, 0 initializing, 0 relocating, 1 unassigned Am Freitag, 9. Mai 2014 17:38:47 UTC+2 schrieb Mark Nickolai: > > Hi there, > > while sending a massive amount of logs to the tcp gelf input my > elasticsearch cluster turns red. > > I'm receiving a lot 'UnavailableShard

[graylog2] Re: RegEx Trouble

2014-05-09 Thread Jarred Masterson
Success! I have at last sorted this out. As it turns out the issue was non obvious due to the way that the HTML spec displays multiple whitespace characters. I ran upon the answer when I decided to give another run at writing a working regex for these messages. I brought up the extractor cre

[graylog2] graylog2 v0.20.1: UnavailableShardsException

2014-05-09 Thread Mark Nickolai
Hi there, while sending a massive amount of logs to the tcp gelf input my elasticsearch cluster turns red. I'm receiving a lot 'UnavailableShardsException' Errors, earch for another ID: e.g.: UnavailableShardsException[[graylog2_1][0] [1] shardIt, [0] active : Timeout waiting for [1m], reque

[graylog2] Re: Doesn't work: Importing old logs using GELF.

2014-05-09 Thread Mark Nickolai
Hi again, found the bug, there had to be '\0' at end of the line. Now it works. -- You received this message because you are subscribed to the Google Groups "graylog2" group. To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+unsubscr...@googlegroups.co

[graylog2] How to import old syslog log files with graylog2 v0.20.1

2014-05-09 Thread Mark Nickolai
Hello there, I need to import old logfiles due to the migration prrocess to graylog2. I have tons of logfiles written by rsyslog. Sending with netcat to the raw input is not helpful, because I need the timestamp of the syslog instead of new ones. Sending with netcat to syslog input fails, due t

[graylog2] How to import old syslog log files with graylog2 v0.20.1

2014-05-09 Thread Mark Nickolai
Hello there, I need to import old logfiles due to the migration prrocess to graylog2. I have tons of logfiles written by rsyslog. Sending with netcat to the raw input is not helpful, because I need the timestamp of the syslog instead of new ones. Sending with netcat to syslog input fails, due t

[graylog2] Re: How to start graylog2-web-interface on windows?

2014-05-09 Thread Joe CHAHINE
Hhi alvan chen, I am trying to install graylog2-server on windows but its not working with me, could you point out how you did that? Thanks!! On Wednesday, August 22, 2012 12:00:10 PM UTC+3, alvan chen wrote: > > Hi all, > I have installed and start the graylog2-server on windows, and trying to

[graylog2] Last 10 messages of a stream as a widget

2014-05-09 Thread Benoit Chabord
Hello, I can create Historgrams and Count of the messages in the last 30min of my stream but I am trying to get in the dashboard the last 10 messages of a stream is it possible ? Nothing in http://support.torch.sh/help/kb/graylog2-web-interface/the-dashboards-explained And I can't find the "a

[graylog2] Show me only abnormals logs

2014-05-09 Thread Francis
Hello, I wonder if what I want to do is doable with graylog2. I would like to "train" graylog2 to record what logs are "normal". Then, I would like to have a view allowing me to only see logs that are "not normal". My minimal knowledge of graylog tell me that I should create a stream, but se

[graylog2] Re: Graylog2 v0.20.2-rc.1 and missing event.

2014-05-09 Thread Dmitri Stoljarov
Hi, Installed graylog2 0.20.2-rc1 (server & webserver) on more powerful server than i used for previous tests - 16x2.93GHz, 32GB Ram, SSD disks. Elasticsearch v 0.90.0 installed on second server, but same hardware specs as above. I did several tests with same 5 log lines and raw tcp input. On a

[graylog2] Re: Sending logs to Graylog2

2014-05-09 Thread Silvian Cretu
Well, it should be: *.* @graylog_ip:514 And on graylog2 you need to have a Syslog UDP input open on that IP and port... On Thursday, 8 May 2014 08:22:02 UTC+3, Randeep P Raman wrote: > > Hi all, > > I have a central syslog log server running in my production environment. > Which is collecting lo