[graylog2] Re: graylog server warning every 5-30 minutes

2016-06-21 Thread Frederic Desjarlais
Would it make sense to increase the 'stale_master_timeout' setting to something like 5 minutes? What would be the issues to consider with a large cluster (say 32 Graylog Server nodes) having this set at 5 minutes (instead of 2000ms)? My understanding is that the master is only needed to run s

[graylog2] Re: graylog server warning every 5-30 minutes

2016-06-21 Thread Ariel Godinez
Hello Jochen, Thanks for the response and paraphrase explanation, that helped me make more sense of what was going on. I took another look at my NTP configuration and as it turns out, the system clock wasn't syncing as it should have been. I fixed that, and the warnings from graylog stopped.

[graylog2] Re: graylog server warning every 5-30 minutes

2016-06-21 Thread Jochen Schalanda
Hi Ariel, just for reference, I'll paraphrase the explanation from IRC: Each Graylog node "registers" itself (node id, URI to the Graylog REST API, > timestamp of the last heartbeat) in MongoDB (see the nodes collection). > The timeout/cleanup interval is quite aggressive (2s, see > stale_mast