# Documentation Campfire

**URL:** https://community.graylog.org/c/documentation-campfire/30.md

[Latest](https://community.graylog.org/latest.md) · [Categories](https://community.graylog.org/categories.md) · [Tags](https://community.graylog.org/tags.md)

---

## [Accessing documentation prior to v 3.3](https://community.graylog.org/t/accessing-documentation-prior-to-v-3-3/22304)

<div class="topic-metadata">

**Author:** [@dulanism](https://community.graylog.org/u/dulanism)\
**Replies:** 0\
**Last updated:** [January 12, 2022, 12:42pm UTC](https://community.graylog.org/t/accessing-documentation-prior-to-v-3-3/22304 "2022-01-12T12:42:38Z")

</div>

Looking for OLDER versions of Graylog? Check out our archived documentation: https://archivedocs.graylog.org/

---

## [About the Documentation Campfire category](https://community.graylog.org/t/about-the-documentation-campfire-category/21567)

<div class="topic-metadata">

**Author:** [@dscryber](https://community.graylog.org/u/dscryber)\
**Replies:** 5\
**Last updated:** [October 29, 2021, 10:39am UTC](https://community.graylog.org/t/about-the-documentation-campfire-category/21567 "2021-10-29T10:39:05Z")

</div>

Do you have questions about our documentation? Post a comment or start a discussion here so our technical content team can help you succeed.

---

## [Graylog and OpenSearch Index Templates](https://community.graylog.org/t/graylog-and-opensearch-index-templates/36879)

<div class="topic-metadata">

**Author:** [@edp](https://community.graylog.org/u/edp)\
**Replies:** 3\
**Last updated:** [January 29, 2026, 5:23pm UTC](https://community.graylog.org/t/graylog-and-opensearch-index-templates/36879 "2026-01-29T17:23:39Z")

</div>

Does Graylog use OpenSearch Index Templates? I’m not seeing any. I need to set up an OpenSearch index template pattern to apply a setting to all new indices that are created in one of our index sets… can I do this with…

---

## [Data tiering configuration](https://community.graylog.org/t/data-tiering-configuration/35797)

<div class="topic-metadata">

**Author:** [@brosef](https://community.graylog.org/u/brosef)\
**Replies:** 7\
**Last updated:** [June 12, 2025, 8:08am UTC](https://community.graylog.org/t/data-tiering-configuration/35797 "2025-06-12T08:08:54Z")

</div>

We’re upgrading from Graylog Open 5.2 → 6.2 and I’m trying to wrap my head around the new index rotation options. Looks like we’re leapfrogging the now-deprecated “Index Time Size Optimizing” config and the recommended w…

---

## [Installation instructions aren't clear](https://community.graylog.org/t/installation-instructions-arent-clear/34909)

<div class="topic-metadata">

**Author:** [@Sinan](https://community.graylog.org/u/Sinan)\
**Replies:** 2\
**Last updated:** [February 13, 2025, 9:44pm UTC](https://community.graylog.org/t/installation-instructions-arent-clear/34909 "2025-02-13T21:44:15Z")

</div>

Setup Graylog → Get started with Graylog → initial config setting page doesn’t mention datanode at all. In fact, there’s a discussion about adding elasticsearch\_hosts. Seeing the related line in server.conf, I added m…

---

## [Graylog - Vendor Risk Assessment Documentation](https://community.graylog.org/t/graylog-vendor-risk-assessment-documentation/34622)

<div class="topic-metadata">

**Author:** [@ak99](https://community.graylog.org/u/ak99)\
**Replies:** 10\
**Last updated:** [January 23, 2025, 8:14am UTC](https://community.graylog.org/t/graylog-vendor-risk-assessment-documentation/34622 "2025-01-23T08:14:46Z")

</div>

Hello, My organization is currently utilizing Graylog Open and we were looking for Security Documentation to support performing a Vendor Risk Assessment of Graylog. A Vendor Risk Assessment is necessary for us to conti…

---

## [Windows logs from azure machine are not getting shipped in graylog hosted in AKS](https://community.graylog.org/t/windows-logs-from-azure-machine-are-not-getting-shipped-in-graylog-hosted-in-aks/34349)

<div class="topic-metadata">

**Author:** [@sagar94](https://community.graylog.org/u/sagar94)\
**Replies:** 3\
**Last updated:** [December 9, 2024, 9:44am UTC](https://community.graylog.org/t/windows-logs-from-azure-machine-are-not-getting-shipped-in-graylog-hosted-in-aks/34349 "2024-12-09T09:44:51Z")

</div>

We are setting up graylog in AKS. For that kongz/graylog helm is used for setting up graylog, mongodb and opensearch in azure Kubernetes. Along with nginx-ingress controller has been set to access graylog outside AKS an…

---

## [Docs still mention is\_master instead of is\_leader](https://community.graylog.org/t/docs-still-mention-is-master-instead-of-is-leader/34284)

<div class="topic-metadata">

**Author:** [@evert](https://community.graylog.org/u/evert)\
**Replies:** 0\
**Last updated:** [November 26, 2024, 12:00pm UTC](https://community.graylog.org/t/docs-still-mention-is-master-instead-of-is-leader/34284 "2024-11-26T12:00:26Z")

</div>

I noticed that Initial Configuration Settings still refers to is\_master instead of is\_leader, even for Graylog 6.1

---

## [Security-related events in the Windows environment should be logged to facilitate the detection of suspicious activities and to aid in the investigation of security incidents.please suggest](https://community.graylog.org/t/security-related-events-in-the-windows-environment-should-be-logged-to-facilitate-the-detection-of-suspicious-activities-and-to-aid-in-the-investigation-of-security-incidents-please-suggest/33895)

<div class="topic-metadata">

**Author:** [@phaneendra176](https://community.graylog.org/u/phaneendra176)\
**Replies:** 0\
**Last updated:** [October 20, 2024, 7:47am UTC](https://community.graylog.org/t/security-related-events-in-the-windows-environment-should-be-logged-to-facilitate-the-detection-of-suspicious-activities-and-to-aid-in-the-investigation-of-security-incidents-please-suggest/33895 "2024-10-20T07:47:07Z")

</div>

Hello everyone, I am looking to install Graylog Server on Ubuntu 22.04 and would appreciate guidance on the following: Version Selection: Which version of Graylog server should I use for this setup? Client Machine Con…

---

## [Data Retention since Graylog 6.0](https://community.graylog.org/t/data-retention-since-graylog-6-0/33651)

<div class="topic-metadata">

**Author:** [@s0p4L1N](https://community.graylog.org/u/s0p4L1N)\
**Replies:** 11\
**Last updated:** [October 7, 2024, 11:23am UTC](https://community.graylog.org/t/data-retention-since-graylog-6-0/33651 "2024-10-07T11:23:22Z")

</div>

1. Describe your incident: I just upgraded from Graylog 5.2 to 6.0.6 and noticed that the Indice retention is being deprecated. And now I just have Data tiering with max days and min days but I still want to rely on dai…

---

## [How to run Graylog 6, MongoDB and Opensearch in a Docker Stack](https://community.graylog.org/t/how-to-run-graylog-6-mongodb-and-opensearch-in-a-docker-stack/32377)

<div class="topic-metadata">

**Author:** [@schneich](https://community.graylog.org/u/schneich)\
**Replies:** 4\
**Last updated:** [September 18, 2024, 12:57pm UTC](https://community.graylog.org/t/how-to-run-graylog-6-mongodb-and-opensearch-in-a-docker-stack/32377 "2024-09-18T12:57:14Z")

</div>

Dear community, I have spend the last two nights and a great part of today to figure out, how to run Graylog 6 in a Docker environment. The official Graylog documentation was partly helpful, partly misleading. I will su…

---

## [Multi node cluster](https://community.graylog.org/t/multi-node-cluster/33378)

<div class="topic-metadata">

**Author:** [@omkar](https://community.graylog.org/u/omkar)\
**Replies:** 3\
**Last updated:** [September 3, 2024, 10:03am UTC](https://community.graylog.org/t/multi-node-cluster/33378 "2024-09-03T10:03:06Z")

</div>

I have 3 node graylog cluster our kubernetes pod logs tranfer on this by using node ip and port but when node goes down then not getting logs how to create node load balancing for fault tolerance

---

## [MongoDB 5.0 upgrade guide, specify AVX support requirements](https://community.graylog.org/t/mongodb-5-0-upgrade-guide-specify-avx-support-requirements/26508)

<div class="topic-metadata">

**Author:** [@lmm5247](https://community.graylog.org/u/lmm5247)\
**Replies:** 4\
**Last updated:** [August 28, 2024, 8:08am UTC](https://community.graylog.org/t/mongodb-5-0-upgrade-guide-specify-avx-support-requirements/26508 "2024-08-28T08:08:03Z")

</div>

I’m testing Graylog 5 beta and MongoDB 5. I’m following this document to upgrade from MongoDB 4.4 to 5.0. When starting MongoDB I’m getting an error about MongoDB 5 and higher requiring AVX CPU support. My hypervisor d…

---

## [The guide link may broken](https://community.graylog.org/t/the-guide-link-may-broken/33165)

<div class="topic-metadata">

**Author:** [@mvtrung](https://community.graylog.org/u/mvtrung)\
**Replies:** 2\
**Last updated:** [August 1, 2024, 10:00am UTC](https://community.graylog.org/t/the-guide-link-may-broken/33165 "2024-08-01T10:00:26Z")

</div>

Hi all, The guideline on How to use Graylog as a Syslog Server session maybe broken or attack wrong link. Please see the pic as attach. Thank you for your attention.

---

## [Multi Node cluster setup](https://community.graylog.org/t/multi-node-cluster-setup/33147)

<div class="topic-metadata">

**Author:** [@omkar](https://community.graylog.org/u/omkar)\
**Replies:** 4\
**Last updated:** [August 1, 2024, 7:12am UTC](https://community.graylog.org/t/multi-node-cluster-setup/33147 "2024-08-01T07:12:24Z")

</div>

when create 3 node HA cluster assign one of them is master. but master node goes down then cluster not initiate master on remaining two nodes ??

---

## [Compatibility Matrix - there are at least two different versions in the docs](https://community.graylog.org/t/compatibility-matrix-there-are-at-least-two-different-versions-in-the-docs/33130)

<div class="topic-metadata">

**Author:** [@larsfessler](https://community.graylog.org/u/larsfessler)\
**Replies:** 0\
**Last updated:** [July 29, 2024, 1:30pm UTC](https://community.graylog.org/t/compatibility-matrix-there-are-at-least-two-different-versions-in-the-docs/33130 "2024-07-29T13:30:39Z")

</div>

Hi, there are at least two different compatibility matrices within the Graylog docs with different content, e.g MongoDB version usable with Graylog 4.3 https://go2docs.graylog.org/5-0/upgrading\_graylog/upgrading\_graylo…

---

## [Documentation of parse\_date outdated - links to Joda time](https://community.graylog.org/t/documentation-of-parse-date-outdated-links-to-joda-time/32293)

<div class="topic-metadata">

**Author:** [@nisow95612](https://community.graylog.org/u/nisow95612)\
**Replies:** 1\
**Last updated:** [July 18, 2024, 8:37am UTC](https://community.graylog.org/t/documentation-of-parse-date-outdated-links-to-joda-time/32293 "2024-07-18T08:37:28Z")

</div>

I remember graylog switching from Joda time to Java time a while ago, so it looks like documetation of pipeline function parse\_date is outdated, because it still links to joda time help: parse\_date(value, pattern, \[loca…

---

## [How to create backup of graylog data](https://community.graylog.org/t/how-to-create-backup-of-graylog-data/32453)

<div class="topic-metadata">

**Author:** [@avkva](https://community.graylog.org/u/avkva)\
**Replies:** 0\
**Last updated:** [May 17, 2024, 1:13pm UTC](https://community.graylog.org/t/how-to-create-backup-of-graylog-data/32453 "2024-05-17T13:13:35Z")

</div>

I have a task to backup only streams, event defenitions, notifications, and extractors to our repository. Which way I can do it? Should I do dump database , elastic snapshot etc?

---

## [Update Graylog Docker Stack from 5.2 to 6.0.1, incl. change from Elasticsearch to Opensearch and upgrade mongodb](https://community.graylog.org/t/update-graylog-docker-stack-from-5-2-to-6-0-1-incl-change-from-elasticsearch-to-opensearch-and-upgrade-mongodb/32411)

<div class="topic-metadata">

**Author:** [@schneich](https://community.graylog.org/u/schneich)\
**Replies:** 0\
**Last updated:** [May 14, 2024, 9:35pm UTC](https://community.graylog.org/t/update-graylog-docker-stack-from-5-2-to-6-0-1-incl-change-from-elasticsearch-to-opensearch-and-upgrade-mongodb/32411 "2024-05-14T21:35:51Z")

</div>

Dear community, during the last couple of days, I was trying to upgrade my Docker Graylog Stack. I ran into several issues and finally managed to solve them all. I thought it worth while to document, so that others ca…

---

## [Graylog pipeline function index docs out of date](https://community.graylog.org/t/graylog-pipeline-function-index-docs-out-of-date/31780)

<div class="topic-metadata">

**Author:** [@jgrammen\_agility](https://community.graylog.org/u/jgrammen_agility)\
**Replies:** 0\
**Last updated:** [March 11, 2024, 2:18pm UTC](https://community.graylog.org/t/graylog-pipeline-function-index-docs-out-of-date/31780 "2024-03-11T14:18:28Z")

</div>

The following page of the documentation which lists all functions available in graylog pipeline is out of date, there have been functions added that are not present in the index (eg: map\_get, map\_remove) https://go2docs…

---

## [Installation of OpenSearch with Graylog 5.x (CentOS/Rocky Linux)](https://community.graylog.org/t/installation-of-opensearch-with-graylog-5-x-centos-rocky-linux/29735)

<div class="topic-metadata">

**Author:** [@shenke](https://community.graylog.org/u/shenke)\
**Replies:** 3\
**Last updated:** [November 27, 2023, 3:24pm UTC](https://community.graylog.org/t/installation-of-opensearch-with-graylog-5-x-centos-rocky-linux/29735 "2023-11-27T15:24:57Z")

</div>

Hi, in CentOS installation and CentOS installation you write sudo yum install -y opensearch But this will break the installation, since (at the moment) version 2.9 is actual, but GL only supports OS up to 2.5. The co…

---

## [Sidecar version matrix](https://community.graylog.org/t/sidecar-version-matrix/30332)

<div class="topic-metadata">

**Author:** [@nicosalva](https://community.graylog.org/u/nicosalva)\
**Replies:** 6\
**Last updated:** [October 19, 2023, 9:47am UTC](https://community.graylog.org/t/sidecar-version-matrix/30332 "2023-10-19T09:47:57Z")

</div>

Hello there :slight\_smile: Just wondering about the sidecar version matrix in the docs. https://go2docs.graylog.org/5-0/getting\_in\_log\_data/graylog\_sidecar.html#InstalltheSidecar There is no mention of Graylog serve…

---

## [Graylog Upgrade to 5.1.4 page mistakes](https://community.graylog.org/t/graylog-upgrade-to-5-1-4-page-mistakes/29820)

<div class="topic-metadata">

**Author:** [@ereiss](https://community.graylog.org/u/ereiss)\
**Replies:** 3\
**Last updated:** [August 11, 2023, 6:59pm UTC](https://community.graylog.org/t/graylog-upgrade-to-5-1-4-page-mistakes/29820 "2023-08-11T18:59:31Z")

</div>

On page: Prerequisites Step 4 says: “Backup existing configuration file(s) of your Graylog server:” and the command says: “- /etc/graylog/server/server.conf” Seems to be incomplete!

---

## [Email notifications about Graylog node's errors](https://community.graylog.org/t/email-notifications-about-graylog-nodes-errors/29148)

<div class="topic-metadata">

**Author:** [@roman.potato](https://community.graylog.org/u/roman.potato)\
**Replies:** 6\
**Last updated:** [June 21, 2023, 5:23pm UTC](https://community.graylog.org/t/email-notifications-about-graylog-nodes-errors/29148 "2023-06-21T17:23:41Z")

</div>

I want to know when Graylog server / nodes experience problems. I can see that in UI, but I don’t want to check UI every day. Is it possible to configure Graylog to send Email notifications about system errors for events…

---

## [API Formatting returning specific fields](https://community.graylog.org/t/api-formatting-returning-specific-fields/29179)

<div class="topic-metadata">

**Author:** [@icsj2007](https://community.graylog.org/u/icsj2007)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 9:12pm UTC](https://community.graylog.org/t/api-formatting-returning-specific-fields/29179 "2023-06-15T21:12:19Z")

</div>

I’m trying to get the messages from a searchID. I can do this fine. Its the part where I’m trying to specify which fields. In the api browser I enter: { “fields\_in\_order”: \[ “timestamp”, “message”, “EventID”, “T…

---

## [Alert when no logs is sent from a host | ChatGPT solution](https://community.graylog.org/t/alert-when-no-logs-is-sent-from-a-host-chatgpt-solution/29098)

<div class="topic-metadata">

**Author:** [@roman.potato](https://community.graylog.org/u/roman.potato)\
**Replies:** 8\
**Last updated:** [June 8, 2023, 9:58pm UTC](https://community.graylog.org/t/alert-when-no-logs-is-sent-from-a-host-chatgpt-solution/29098 "2023-06-08T21:58:43Z")

</div>

I’ve spent a few hours yesterday trying to figure out how to create an Event that would alert me when no logs received from any of the host, and I could not find a solution on the internet. There was a solution that work…

---

## [How to search for messages that starts with \[](https://community.graylog.org/t/how-to-search-for-messages-that-starts-with/29011)

<div class="topic-metadata">

**Author:** [@roman.potato](https://community.graylog.org/u/roman.potato)\
**Replies:** 11\
**Last updated:** [June 7, 2023, 7:12pm UTC](https://community.graylog.org/t/how-to-search-for-messages-that-starts-with/29011 "2023-06-07T19:12:43Z")

</div>

I’m mildly confused with Graylog search syntax. I was under impression that I can use basic regular expressions but perhaps it’s a bit more sophisticated than that. I’m trying to find all messages that do not start with…

---

## [Configure cluster of sidecars](https://community.graylog.org/t/configure-cluster-of-sidecars/29056)

<div class="topic-metadata">

**Author:** [@roman.potato](https://community.graylog.org/u/roman.potato)\
**Replies:** 2\
**Last updated:** [June 7, 2023, 3:11pm UTC](https://community.graylog.org/t/configure-cluster-of-sidecars/29056 "2023-06-07T15:11:15Z")

</div>

When using sidecars, do I have to assign configuration to each sidecar node independently? What if I have 100 servers with sidecars? Do I have to manually configure each new node added to a cluster? On the other hand, is…

---

## [Pipeline does not work with custom stream, only with "All Messages"](https://community.graylog.org/t/pipeline-does-not-work-with-custom-stream-only-with-all-messages/29071)

<div class="topic-metadata">

**Author:** [@roman.potato](https://community.graylog.org/u/roman.potato)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 8:28pm UTC](https://community.graylog.org/t/pipeline-does-not-work-with-custom-stream-only-with-all-messages/29071 "2023-06-06T20:28:14Z")

</div>

This post is similar to Pipeline only work on "all messages" stream - #2 by jan Pipeline Moves messages, but still in All Messages Stream - #3 by jan Pipeline Rules Works if Streams is set to "All Messages" but not spe…

---

## [Reduce amount of duplicated metadata for logs collected from Filebeat](https://community.graylog.org/t/reduce-amount-of-duplicated-metadata-for-logs-collected-from-filebeat/29049)

<div class="topic-metadata">

**Author:** [@roman.potato](https://community.graylog.org/u/roman.potato)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 3:55pm UTC](https://community.graylog.org/t/reduce-amount-of-duplicated-metadata-for-logs-collected-from-filebeat/29049 "2023-06-05T15:55:15Z")

</div>

We are using Filebeat to collect logs and I cannot by notice that we have a lot of unnecessary information collected with each log from Filebeat. Moreover many pieces of that information is duplicated within a single log…

[Next page](https://community.graylog.org/c/documentation-campfire/30.md?page=1)
