[graylog2] Re: Stream alert not generated even alert condition satisfied

2015-08-04 Thread Avdhoot Dendge
It should send mail when stream recived any message then wait for 1 min to send another one. Note: from past 7days strem not generating any alert when stream have more than 0 message in minitue. Alert condition: *Alert is triggered when there are more than 0 messages in the last minute. Grace

[graylog2] Re: Service JournalReader has failed in the RUNNING state

2015-08-04 Thread Stefan Zahnd
Hi Jochen Thank you for your answer! Raised the heapsize up to 4G, cleared the journal and restarted the server. Everything's fine again. Best regards Am Dienstag, 4. August 2015 14:19:47 UTC+2 schrieb Jochen Schalanda: > > Hi Stefan, > > your Graylog server runs out of (heap) memory while read

[graylog2] Re: query about performance of time retention_policy settings

2015-08-04 Thread Jochen Schalanda
Hi Jason, the answer to your question depends on multiple factors, like the structure of your log messages, their average size, the available hardware resources for Graylog and Elasticsearch, and the kind of queries you've been running. In short, modern hardware with decent amounts of memory sh

[graylog2] Re: Export all logs from the last month

2015-08-04 Thread Jochen Schalanda
Hi Anders, all log messages processed by Graylog are indexed into Elasticsearch and you can, of course, also query Elasticsearhc directly to get the messages you want. You could for example use the Elasticsearch CSV plugin (https://github.com/jprante/elasticsearch-csv) to get all messages out o

[graylog2] Export all logs from the last month

2015-08-04 Thread Anders Wind
Hi I am trying to export all logs we have from the last month or so, and I have tried to do so in several ways. To begin with i tried to use the "download as .csv file" but that only allowed me to download 1 lines or so, which is not nearly enough. Querying the rest API for more than 24 hou

[graylog2] Re: Service JournalReader has failed in the RUNNING state

2015-08-04 Thread Jochen Schalanda
Hi Stefan, your Graylog server runs out of (heap) memory while reading from the message journal. Please increase the maximum size of heap memor for the JVM (see GRAYLOG_SERVER_JAVA_OPTS in the init scripts). Cheers, Jochen On Tuesday, 4 August 2015 12:42:06 UTC+2, Stefan Zahnd wrote: > > Hi th

[graylog2] Re: Stream alert not generated even alert condition satisfied

2015-08-04 Thread Jochen Schalanda
Hi Avdhoot, how does your alert condition look like and what should it do actually? Cheers, Jochen On Tuesday, 4 August 2015 13:04:11 UTC+2, Avdhoot Dendge wrote: > > > Need help to debug why graylog is not generating alert even alert > condition satisfied. Please check below screenshot for ale

[graylog2] Stream alert not generated even alert condition satisfied

2015-08-04 Thread Avdhoot Dendge
Need help to debug why graylog is not generating alert even alert condition satisfied. Please check below screenshot for alert conditions & stream histogram of 30 min. Message count condition Alert is triggered when there are more than 0 messages in the last minute. Grace period: 1 minute. In

[graylog2] Service JournalReader has failed in the RUNNING state

2015-08-04 Thread Stefan Zahnd
Hi there Suddenly my Graylog installation 1.1.5 stopped processing messages. Input is ok but no processes for processing. In the graylog server.log I see the following error 2015-08-04T12:25:36.543+02:00 ERROR [ServiceManager] Service JournalReader [FAILED] has failed in the RUNNING state. jav

[graylog2] Alerts from Graylog internal system logs?

2015-08-04 Thread adrian . robert
I'd like to get an email if there is a WARNING or ERROR message from Graylog's internal system logs. Is this possible? Context: I know there is the load-balancer status check http://localhost:12900/system/lbstatus , however my understanding is this will still say "ALIVE" unless the server is e

Re: [graylog2] Very slow output msg/s read from journal

2015-08-04 Thread Edmundo Alvarez
Hi, You can see metrics from extractors in the extractor page (System -> Inputs -> Manage extractors) by clicking on the details button of a extractor. You can also see those and more metrics in the node list page. Hope that helps. Regards, Edmundo > On 04 Aug 2015, at 00:17, Jason Haar wro

[graylog2] Re: Graylog-web not logging to /var/logs

2015-08-04 Thread Jochen Schalanda
Hi Mike, I haven't heard of that error scenario until now. Are you using tools like logrotate to rotate log files in /var/log/? Maybe the log file the Graylog web interface was writing into was rotated (renamed, deleted, …) and now it couldn't keep writing into that file. Cheers, Jochen On Tu