Re: [graylog2] Re: Elasticsearch cluster unhealthy (RED)

2016-07-11 Thread Arief Hydayat
Hi Marcus, Thanks a lot. Been few days trying and it was my bad. Suppose to be I change the localhost with the specific IP that I've been setup. the curl command that you given it's work now and I can get the return value of those command. >From the curl http://localhost:9200/_cat/indices comma

[graylog2] Help for wildcards

2016-07-11 Thread Bruno Ribeiro
Hello, I need a help for wildcards. I want to find a modification in file server, but i know only the file name is anual_revenues. If I use the query, source: servername AND ObjectName:*revenues* - > I have several results contains revenues in objectname field. But I use the query, source

[graylog2] Re: Graylog IO Exception Error

2016-07-11 Thread Ariel Godinez
Increasing the heap size on ES and Graylog respectively fixed the issue. On Friday, July 8, 2016 at 11:07:46 AM UTC-5, Ariel Godinez wrote: > > After further investigation I think this was due to elasticsearch and > graylog being overloaded. I have increased their heap sizes accordingly and > w

[graylog2] Re: Graylog slow processing.

2016-07-11 Thread Hema Kumar
Hi Jan, Upgrading to 2.x version will take at-least 6-7 months for us to migrate. About the heap, it is at 70% and no issues with it. No logs are showing up based on the slow rate, apart from what i have posted. There was an error on indice which mentioned about not able to calculate the ran

[graylog2] Re: rsylog to graylog over tls

2016-07-11 Thread Jochen Schalanda
Hi John, please refer to the rsyslog documentation for instructions about setting up TLS: http://www.rsyslog.com/doc/v8-stable/tutorials/tls_cert_client.html Cheers, Jochen On Monday, 11 July 2016 10:23:24 UTC+2, john wrote: > > Hi, > > I created a cerificate and configured a tcp syslog input w

[graylog2] rsylog to graylog over tls

2016-07-11 Thread 'john' via Graylog Users
Hi, I created a cerificate and configured a tcp syslog input with tls. openssl req -x509 -days 365 -nodes -newkey rsa:2048 -keyout pkcs5-plain.pem -out cert.pem openssl pkcs8 -in pkcs5-plain.pem -topk8 -nocrypt -out pkcs8-plain.pem How do I need to configure rsyslog to be able to log to my i

[graylog2] Can't create extractors for inputs on a 2nd graylog node

2016-07-11 Thread Jan
Hi Group, I've experienced an issue when I try to create an extractor for an input which is configured on a remote Graylog cluster node. My setup has 4x Graylog nodes. Two of them are used exclusively for UI-access (*graylog-ui0* and *graylog-u*i1). The other two are used to receive log messag

Re: [graylog2] Graylog slow processing.

2016-07-11 Thread Jan Doberstein
Hey Hema, On 8. Juli 2016 at 14:10:50, Hema Kumar (vhs...@gmail.com) wrote: > I am using graylog 1.3.3 with ES 1.7.5, from yesterday we are seeing the > process buffer filled up on the master node and the outgoing process is too > slow than normal, I have tried restarting GL and ES but did not fi