[graylog2] Re: Graylog Training Courses

2016-10-19 Thread 'Stefan Krüger' via Graylog Users
any news on this? -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+unsubscr...@googlegroups.com. To view this discussion on the web visit

[graylog2] Debian/Ubuntu SHA1Removal causing error when updating package list from graylog repo

2016-08-16 Thread Stefan Ioan
Hello, Please forgive me if this issue has already been posted (I could not find it by searching for it) or if this is not the proper place for this kind of issue. Does anyone have a problem using the "deb https://packages.graylog2.org/repo/debian/ stable 2.1" repo ? I'm using Debian

[graylog2] Re: email callback and message.source..

2016-06-30 Thread 'Stefan Krüger' via Graylog Users
ok, I am to stupid for this.. the body looks like: ## Alert Description: ${check_result.resultDescription} Date: ${check_result.triggeredAt} Stream ID: ${stream.id} Stream title: ${stream.title} Stream description: ${stream.description} ${if stream_url}Stream URL: ${stream_url}${end}

[graylog2] Re: email callback and message.source..

2016-06-30 Thread 'Stefan Krüger' via Graylog Users
Hi Jochen, sorry for my bad english. I've a Stream, and i want a message if root is logged in via ssh (that works fine) but i want to see in the email the source/server where the message come from (sshserver1, sshserver2,etc) bests Stefan -- You received this message because you

[graylog2] Re: email callback and message.source..

2016-06-29 Thread 'Stefan Krüger' via Graylog Users
Hi Jochen, ok if I understand it correct, it is not possible to alert me if root as been logged in, because no backlog exist, right? best regards Stefan -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from

[graylog2] Re: email callback and message.source..

2016-06-29 Thread 'Stefan Krüger' via Graylog Users
Hi Jochen, ok if I understand it correct, it is not possible to alert me if root as been logged in, because no backlog exist, right? -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails

[graylog2] email callback and message.source..

2016-06-29 Thread 'Stefan Krüger' via Graylog Users
Hello I've create a stream and an alert with email-call back, that works, but not all variables are filled, here the callback: body: ## Alert Description: ${check_result.resultDescription} Date: ${check_result.triggeredAt} Stream ID: ${stream.id} Stream title:

[graylog2] Re: Load Balancer health check with Big-IP F5

2016-06-08 Thread Stefan
Hi Marty Graylog 2.0.1. We have tls enabled for the REST API. If I try to connect and check the lbstatus using telnet I always get a "Connection closed by foreign host." back. Do you maybe have an idea how to solve this? Thank you and kind regards, Stefan Am Freitag, 15. April 201

[graylog2] Re: HTTP Callback and variables

2016-06-03 Thread 'Stefan Krüger' via Graylog Users
It's a pity, but i created a feature request.. https://github.com/Graylog2/graylog2-server/issues/2333 -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[graylog2] HTTP Callback and variables

2016-06-03 Thread 'Stefan Krüger' via Graylog Users
Hello short question, is it possible to input some variables in the graylog http callback? somthing like: https://api.example.org/mybot/sendMessage?chat_id=123456789="Stream: ${stream.title} ... ${source} ${message}" thanks in advance! -- You received this message because you are subscribed

[graylog2] Graylog 1.3.4 with 2 data nodes failover of ES not working

2016-05-18 Thread Stefan Zahnd
sn't work and would be more than happy if someone has an idea. Thank you very much in advance. Kind regards, Stefan Following are the ES related configurations of each server: ## Graylog 1 - /etc/graylog/server/server.conf elasticsearch_shards = 1 elasticsearch_replicas = 1 elasticsearch_ind

[graylog2] Re: SSL setup making website unavailable

2016-04-28 Thread Stefan Tiede
I had to tweak my apache config, see here: http://docs.graylog.org/en/2.0/pages/configuring_webif.html#apache Proxy pass to api is needed now. -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving

[graylog2] Re: v2 and multiple interfaces, web not working

2016-04-28 Thread Stefan Tiede
I had to tweak my apache config... see here: http://docs.graylog.org/en/2.0/pages/configuring_webif.html#apache Proxy pass to api is needed now. -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop

[graylog2] Re: rewrite incoming messages

2016-02-17 Thread 'Stefan Krüger' via Graylog Users
wow.. thanks that was easy.. i try something like regex ([\d]+.[\d]+.) and copy.. -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[graylog2] rewrite incoming messages

2016-02-17 Thread 'Stefan Krüger' via Graylog Users
Hello, I would like to send apache-logs to graylog ( at the moment i don't know whcih variant i would choose) is it possible to change the IP from the access.log? for example I would like to change the IP from 192.168.1.123 to 192.168.x.x Thanks for help! -- You received this message

[graylog2] Re: Integrating graylog collector with apache 2 log

2015-12-09 Thread Stefan Krüger
in now that solve not you problem but it is also a good solution: https://groups.google.com/d/msg/graylog2/WOfk-TnFt_c/4IJiQG3uDwAJ Am Dienstag, 8. Dezember 2015 13:52:44 UTC+1 schrieb Sean McGurk: > > Hi, > > Did you ever get to the bottom of this? > > I seem to be having the same issue. > >

[graylog2] Re: ldap-login only if user in a special group

2015-11-12 Thread Stefan Krüger
has nobody an idea? -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+unsubscr...@googlegroups.com. To view this discussion on the web visit

[graylog2] Re: unable to post GLEF messages in UDP port

2015-11-11 Thread Stefan Krüger
Hi, can you please try this: nmap -sU -p 12201 sample.domain.com is this port open? maybe you can also create a "raw" input and send messages.. maybe there is a firewall or somthing like that? -- You received this message because you are subscribed to the Google Groups "Graylog Users" group.

[graylog2] Re: unable to post GLEF messages in UDP port

2015-11-11 Thread Stefan Krüger
you check TCP and not UDP ;) try nmap -sU -Pn -p 12201 sample.domain.com can you please create a RAW-Input and send some data to him, to check if graylog works correctly and get messages? -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To

[graylog2] ldap-login only if user in a special group

2015-11-02 Thread Stefan Krüger
Hello is it possible to configure Graylog to check if the user in a special group? We don't use the overlay MemberOf. Maybe somthing like this: GroupDN: cn=Graylog-Agents,cn=groups,dc=example,dc=de AccessAttr: memberUid thanks for help! When i try Search base DN=

[graylog2] ldap-login only if user in a special group

2015-11-02 Thread Stefan Krüger
Hello is it possible to configure Graylog to check if the user in a special group? We don't use the overlay MemberOf. Maybe somthing like this: GroupDN: cn=Graylog-Agents,cn=groups,dc=example,dc=de AccessAttr: memberUid thanks for help! -- You received this message because you are subscribed

[graylog2] Re: Send apache log to Graylog Syslog Input

2015-10-29 Thread Stefan Krüger
Hello, i think the easiest way is the following, put this in you apache config: LogFormat "{ \"version\": \"1.1\", \"host\": \"%V\", \"short_message\": \"%r\", \"timestamp\": %{%s}t, \"level\": 6, \"_user_agent\": \"%{User-Agent}i\", \"_source_ip\": \"%a\", \"_duration_usec\": %D,

[graylog2] Graylog stop sending messages to elasticsearch

2015-10-20 Thread Stefan Zahnd
Hi I hope someone can give me a hint. After search for two weeks now I cannot find the solution for my problem. Graylog stops sending messages to elasticsearch (throuput In: xxx / Out: 0). If I restart graylog messages are beeing sent to elasticsearch but not with the same performance as it

[graylog2] Graylog stop sending messages to elasticsearch after adding extractor

2015-10-20 Thread Stefan Zahnd
Hi I have the problem that right after adding a grok extractor to an input the system immediately stopps sending messages to elasticsearch (out = 0). Does somebody had the same experience? My pattern looks like

[graylog2] Re: How to set up REST API with TLS support

2015-08-04 Thread Stefan Zahnd
Problem solved. See https://github.com/Graylog2/graylog2-server/issues/818 Sorry and thanks Am Dienstag, 4. August 2015 08:29:48 UTC+2 schrieb Stefan Zahnd: Hi there I try to set up the REST API with TLS support. Does someone have experience with it? I created the certificate (PEM

[graylog2] Re: Service JournalReader has failed in the RUNNING state

2015-08-04 Thread Stefan Zahnd
Hi Jochen Thank you for your answer! Raised the heapsize up to 4G, cleared the journal and restarted the server. Everything's fine again. Best regards Am Dienstag, 4. August 2015 14:19:47 UTC+2 schrieb Jochen Schalanda: Hi Stefan, your Graylog server runs out of (heap) memory while reading

[graylog2] Graylog2-Web with keystore from OpenSSL leads to Cannot Recover Key

2014-09-06 Thread Stefan Zahnd
Hi I try to create the a keytool from an existing certificate and private key created with openssl. I can create the keystore and start the web gui with https support. When I try to browse the site I get a Cannot recover key error on the console. Play server process ID is 7262 [debug]