[graylog2] Re: help !!!!! for a newbie

2015-11-04 Thread Werner van der Merwe
The ova is certainly the easiest way to get started. We had a requirement of having to run RedHat, so I went with the puppet manifests, which is also fairly easy with some reading required. Using the manifests will effectively install the product via apt-get. Partitioning is up to you, if you

[graylog2] Re: create custom chart

2015-11-04 Thread Werner van der Merwe
I am not 100% sure what you mean, but there are two ways to generate detail graphs: Both: Filter the logs until you only see the logs you are interested in using search. Option 1: On the left, select the blue triangle to expand the ID field, then select Quick Values. That will give you a pie

[graylog2] Two Graylog2 streams to dedicated Outputs all going to first graphite output only

2015-11-04 Thread Werner van der Merwe
Hi, I have two streams: LDAP Results and LDAP Searches. Each goes to a separate Graphite Output. The first stream, indicating results, works correct and is configured as such: - prefix: org.graylog.ldap.prod.results - url: graphite://XX:2003 - fields:

[graylog2] Re: new messages not processed

2015-11-04 Thread Werner van der Merwe
> > > First option will be to ensure processing is not paused in System/Nodes => Nodes, click on the Node name. Make sure the top right is not saying that it is not processing any messages - click resume processing if this is the case. If this was paused, give it some time to recover.

[graylog2] Re: Weird behaviour after upgrade

2015-11-04 Thread Werner van der Merwe
If you click System/Overview and select Overview, can you then see the notification? -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[graylog2] Getting "handshake_failure" using ''graylog2-plugin-input-httpmonitor"

2015-11-04 Thread eleftherios Banos
Hi all. I am using "'graylog2-plugin-input-httpmonitor" (https://github.com/sivasamyk/graylog2-plugin-input-httpmonitor) to recover JSON data from a HTTPS request. The issue is that I am getting an " handshake_failure" when I am doing an HTTPS request. The same request works properly with

[graylog2] Re: Required disk space for a new graylog2 installation unter Linux...

2015-11-04 Thread klaus
Hi Jochen, hi list, first of all, thank you! of course your're right, that the disk volume is not only depending on the count of messages, the averge message size is important to. I will reme,ber this! BUT, *another Question*: How is the *relationship between* the *used space from MongoDB

[graylog2] Extractor Help

2015-11-04 Thread Charles Francis
Hello all, I couldn't find it listed anywhere so I was wonder if anyone had a magic way to take some of the information from the logstash configs and make them work with Graylog. For example, could you take this: https://gist.github.com/dav3860/5345656 and somehow port it to work with

[graylog2] Re: help !!!!! for a newbie

2015-11-04 Thread Charles Francis
I ended up using this link for the install. https://www.digitalocean.com/community/tutorials/how-to-install-graylog2-and-centralize-logs-on-ubuntu-14-04 It was the most complete link that I could fine for Ubuntu LTS. We have been running it for about a week and are somewhat pleased. We are

[graylog2] Re: graylog-server 1.2 unable to find elasticsearch: Failed to send ping

2015-11-04 Thread Christian Studer
And I've just discovered my mistake: I was running Elasticsearch 2.0 instead of Elasticsearch 1.7. Removing Elasticsearch 2 and installing the older version (https://www.elastic.co/guide/en/elasticsearch/reference/1.7/setup-repositories.html) solved the problem. With regards, Christian Am

[graylog2] Re: JAVA warning with graylog 1.2.2

2015-11-04 Thread Jochen Schalanda
Hi Yves, given the error messages ("Bad file descriptor" and "Invalid argument"), it seems that the kernel used by SLES 12 doesn't support all epoll(2) options or somehow restricts access to those (e. g. with grsecurity, SELinux, or AppArmor). You should check the appropriate logs of your

[graylog2] Re: help !!!!! for a newbie

2015-11-04 Thread ollivier . marques
thanks a lot for your response, it's the same for me we are torn between graylog and elk and now i'm in the task elk vs graylog and the choice that really difficult I ll make some test on a virtual pc (with a linux machine a virtueal sw and a virtual ws2k12) Le mercredi 4 novembre 2015

[graylog2] Re: help !!!!! for a newbie

2015-11-04 Thread Jochen Schalanda
Hi, On Wednesday, 4 November 2015 16:19:34 UTC+1, Charles Francis wrote: > > I ended up using this link for the install. > > > https://www.digitalocean.com/community/tutorials/how-to-install-graylog2-and-centralize-logs-on-ubuntu-14-04 > Holy cow, that article is quite out of date and I wouldn't