[graylog2] Export CSV doesn't work on IE\Edge

2016-11-15 Thread Jonata
I'm using Graylog v2.1.1 and although Export CSV feature works fine on Chrome I can't make it work on Internet Explorer or Microsoft Edge. It seems for some reason those Microsoft browsers have some problems with sessions. For instance, last time i tried using Edge, the a tag generated for Exp

[graylog2] Gelf Decoding Processor error after upgrade from 1.3.x to 2.1.1

2016-11-15 Thread 5thfishie
After an upgrade of graylog from 1.3 to 2.1.1 I'm seeing lots of errors in the server.log. I've determined which input is the issue, GELF UDP but I'm unable to determine the source. I'm not sure if this is a bug or an offending application that is submitting bad data to graylog. Is there a w

[graylog2] How to upgrade from Graylog 2.1.1 to 2.1.2 without losing any changes to the graylog server (CentOS 7)

2016-11-15 Thread Jose Aquino
Hi everyone, I am relatively new to Graylog as we have just started to look at log management for our network. I was able to install Graylog 2.1.1 and was able to create some basic functionality with the server through inputs, streams and alerts. Recently, Graylog released version 2.1.2 which

Re: [graylog2] Re: Whats Better for Graylog Udp or Tcp

2016-11-15 Thread Jason Haar
On Tue, Nov 15, 2016 at 4:33 AM, Jochen Schalanda wrote: > Use whatever is supported best by your network appliances. > Well I would add "it depends". UDP is absolutely fine over LANs - if you have near guarantees about zero packet loss - use UDP as its more efficient. But if WANs or the Interne

[graylog2] Re: Elastic Search 2.4.1

2016-11-15 Thread Jochen Schalanda
Hi Steve, Elasticsearch 2.4.x is supported by Graylog 2.1.0 and later. Cheers, Jochen On Tuesday, 15 November 2016 22:27:38 UTC+1, Steve Kuntz wrote: > > Hi, > > Quick question, does Graylog fully support connecting to Elastic Search > 2.4 branch or should I stick with 2.3.5? > > Thanks > --

[graylog2] Elastic Search 2.4.1

2016-11-15 Thread Steve Kuntz
Hi, Quick question, does Graylog fully support connecting to Elastic Search 2.4 branch or should I stick with 2.3.5? Thanks -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, sen

[graylog2] Journal processing problem

2016-11-15 Thread John Buchanan
I am encountering a situation on my 2-node cluster (2 Graylog nodes, 3 Elasticsearch nodes) whereby the Process Buffer fills up, or begins to quickly ramp up in usage, messages are being written to the disk journal, but not read from. The journal usage can grow to the hundreds of thousands or m

Re: [graylog2] Pipeline arithmetic (in the then statement) OR datediff ?

2016-11-15 Thread Drew Miranda
Thanks! On Tuesday, November 15, 2016 at 3:25:15 AM UTC-6, Jan Doberstein wrote: > > Hej Drew, > > we have this feature issue in the pipeline repository: > https://github.com/Graylog2/graylog-plugin-pipeline-processor/issues/91 > > the answer is - not yet but will be. > > with kind regards > Jan

[graylog2] Re: Timeout GET http://10.102.0.16:9000/api/system/sessions Status code undefined on graylog Web Interface

2016-11-15 Thread Jochen Schalanda
Hi Pierrick, web_endpoint_uri has to point to the public address of the Graylog REST API. In your case, you've pointed it to the address of the Graylog web interface. Cheers, Jochen On Tuesday, 15 November 2016 11:53:44 UTC+1, Pierrick Prost wrote: > > More informations about my problem : > >

[graylog2] Re: Timeout GET http://10.102.0.16:9000/api/system/sessions Status code undefined on graylog Web Interface

2016-11-15 Thread Pierrick Prost
More informations about my problem : i'm on a Jelastic Pass environnement. To connect to my graylog web UI, I made an endpoint to my http://10.102.0.16:9000/ local URI., configure the Web interface endpoint URI like that : web_endpoint_uri = http://my_public_dns_endpoint:11011 And now i have

[graylog2] Re: Timeout GET http://10.102.0.16:9000/api/system/sessions Status code undefined on graylog Web Interface

2016-11-15 Thread Pierrick Prost
More informations about my problem : i'm on a Jelastic Pass environnement. To connect to my graylog web UI, I made an endpoint to my http://10.102.0.16:9000/ local URI., configure the Web interface endpoint URI like that : web_endpoint_uri = http://my_public_dns_endpoint:11011 And now i have

[graylog2] Re: using graylog just for indexing logs not storing them

2016-11-15 Thread Benbrahim Anass
yes that's what i'm going to do thanks man cheers Le mardi 15 novembre 2016 11:11:03 UTC+1, Jochen Schalanda a écrit : > > Hi Anas, > > On Tuesday, 15 November 2016 10:49:53 UTC+1, Benbrahim Anass wrote: >> >> i wanna use graylog just for indexing in real time thoses logs and >> configure alarms

[graylog2] Timeout GET http://10.102.0.16:9000/api/system/sessions Status code undefined on graylog Web Interface

2016-11-15 Thread Pierrick Prost
hy guys, i have trouble to configure my graylog web interface working with graylog server. Here is my configuration : Packages: yum list installed | grep gray* graylog-2.1-repository.noarch 1-3 installed graylog-server.noarch 2.1.2-1

[graylog2] Re: using graylog just for indexing logs not storing them

2016-11-15 Thread Jochen Schalanda
Hi Anas, On Tuesday, 15 November 2016 10:49:53 UTC+1, Benbrahim Anass wrote: > > i wanna use graylog just for indexing in real time thoses logs and > configure alarms based on them in real time always > That's not possible. Graylog is using regular searches to check for alert conditions. You c

[graylog2] Re: How remove old messages in graylog?

2016-11-15 Thread Jochen Schalanda
Hi, On Tuesday, 15 November 2016 10:55:58 UTC+1, Israel Martinez Bermejo wrote: > > What is the recommend retaing messages and indices? > Whatever fits your requirements best. Cheers, Jochen -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To

[graylog2] Re: How remove old messages in graylog?

2016-11-15 Thread Israel Martinez Bermejo
OMG!! HAHAHA What is the recommend retaing messages and indices? El martes, 15 de noviembre de 2016, 9:15:05 (UTC+1), Jochen Schalanda escribió: > > Hi, > > you've configured to retain 2,000,000 messages per index and to retain 20 > indices, meaning you will have 40,000,000 messages until Gray

[graylog2] Re: using graylog just for indexing logs not storing them

2016-11-15 Thread Benbrahim Anass
i already have a basic Syslog server storing everything, i dont want to do the same thing with graylog i wanna use graylog just for indexing in real time thoses logs and configure alarms based on them in real time always Cheers Anas Le lundi 14 novembre 2016 14:52:18 UTC+1, Jochen Schalanda a é

Re: [graylog2] Pipeline arithmetic (in the then statement) OR datediff ?

2016-11-15 Thread Jan Doberstein
Hej Drew, we have this feature issue in the pipeline repository: https://github.com/Graylog2/graylog-plugin-pipeline-processor/issues/91 the answer is - not yet but will be. with kind regards Jan 2016-11-14 16:11 GMT+01:00 Drew Miranda : > Hi All, > Is it possible to do date comparisons in the

[graylog2] Re: How remove old messages in graylog?

2016-11-15 Thread Jochen Schalanda
Hi, you've configured to retain 2,000,000 messages per index and to retain 20 indices, meaning you will have 40,000,000 messages until Graylog starts rotating/deleting old indices. Cheers, Jochen On Tuesday, 15 November 2016 08:41:30 UTC+1, Israel Martinez Bermejo wrote: > > Hi Jochen. > > I p