# Latest

**URL:** https://community.graylog.org/latest.md

[Latest](https://community.graylog.org/latest.md) · [Categories](https://community.graylog.org/categories.md) · [Tags](https://community.graylog.org/tags.md)

---

## [Questions and You: A guide to getting an answer](https://community.graylog.org/t/questions-and-you-a-guide-to-getting-an-answer/9882)

<div class="topic-metadata">

**Author:** [@benvanstaveren](https://community.graylog.org/u/benvanstaveren)\
**Replies:** 0\
**Last updated:** [April 9, 2019, 7:52pm UTC](https://community.graylog.org/t/questions-and-you-a-guide-to-getting-an-answer/9882 "2019-04-09T19:52:53Z")

</div>

Hi folks, Lately it seems that questions are being asked which have been answered already, either on the forum, in the documentation, or with 5 minutes of Googling. Please keep in mind that these are the community forum…

---

## [Missing links in input "Message Error" section](https://community.graylog.org/t/missing-links-in-input-message-error-section/37569)

<div class="topic-metadata">

**Author:** [@aybora](https://community.graylog.org/u/aybora)\
**Replies:** 0\
**Last updated:** [September 21, 2026, 12:15pm UTC](https://community.graylog.org/t/missing-links-in-input-message-error-section/37569 "2026-09-21T12:15:38Z")

</div>

1. Describe your incident: I noticed on the /system/input/diagnosis/\<input id\> page a section called “Message Errors” and the flavor text suggesting to “Click on a category to view the associated messages”, but there is…

---

## [Graylog DataNode Storage – Can Wasabi S3-Compatible Storage Be Used for Hot Data and Archiving?](https://community.graylog.org/t/graylog-datanode-storage-can-wasabi-s3-compatible-storage-be-used-for-hot-data-and-archiving/37568)

<div class="topic-metadata">

**Author:** [@Golobolus](https://community.graylog.org/u/Golobolus)\
**Replies:** 1\
**Last updated:** [September 21, 2026, 8:07am UTC](https://community.graylog.org/t/graylog-datanode-storage-can-wasabi-s3-compatible-storage-be-used-for-hot-data-and-archiving/37568 "2026-09-21T08:07:22Z")

</div>

Hi Graylog Community, We are currently evaluating our Graylog storage architecture and would appreciate some guidance from the community. Our current setup has Graylog DataNodes using AWS EFS for data storage. The envi…

---

## [OpenSearch 2.19.6](https://community.graylog.org/t/opensearch-2-19-6/37527)

<div class="topic-metadata">

**Author:** [@greendoom](https://community.graylog.org/u/greendoom)\
**Replies:** 6\
**Last updated:** [September 11, 2026, 11:26am UTC](https://community.graylog.org/t/opensearch-2-19-6/37527 "2026-09-11T11:26:27Z")

</div>

Has anyone tried installing this version Opensearch with Graylog? It’s been out for about 2 months now. Compatibility Matrix is still on version 2.19.5.

---

## [API for graylog-datanode](https://community.graylog.org/t/api-for-graylog-datanode/37557)

<div class="topic-metadata">

**Author:** [@igoriceg](https://community.graylog.org/u/igoriceg)\
**Replies:** 1\
**Last updated:** [September 10, 2026, 9:01am UTC](https://community.graylog.org/t/api-for-graylog-datanode/37557 "2026-09-10T09:01:56Z")

</div>

Hello everyone. I’ve run into the following problem: Graylog version 7.3 — graylog‑server and graylog‑datanode are installed on the same physical server. I need to access the API to manage indices via the terminal (use b…

---

## [Customize or Remove the message Column/Field from Graylog Search Results](https://community.graylog.org/t/customize-or-remove-the-message-column-field-from-graylog-search-results/37555)

<div class="topic-metadata">

**Author:** [@chandru](https://community.graylog.org/u/chandru)\
**Replies:** 2\
**Last updated:** [September 9, 2026, 3:28pm UTC](https://community.graylog.org/t/customize-or-remove-the-message-column-field-from-graylog-search-results/37555 "2026-09-09T15:28:04Z")

</div>

Hi Graylog Team, We are currently using Graylog for syslog collection and have a requirement to customize the message column/field displayed in the Graylog interface. For example, our device is sending the following sy…

---

## [Proper allocation of computing resources](https://community.graylog.org/t/proper-allocation-of-computing-resources/37551)

<div class="topic-metadata">

**Author:** [@igoriceg](https://community.graylog.org/u/igoriceg)\
**Replies:** 12\
**Last updated:** [September 3, 2026, 12:41pm UTC](https://community.graylog.org/t/proper-allocation-of-computing-resources/37551 "2026-09-03T12:41:37Z")

</div>

Hi community! I have already installed all-in-one server: graylog-server 7.1.3 graylog-datanode 7.1.3 mongodb Hardware of this bare-metal install is - 32thread CPU and 64GB ram i need proper config to allocate as fl…

---

## [Script-Callback with SBS - change to API](https://community.graylog.org/t/script-callback-with-sbs-change-to-api/37548)

<div class="topic-metadata">

**Author:** [@coffee\_is\_life](https://community.graylog.org/u/coffee_is_life)\
**Replies:** 2\
**Last updated:** [September 3, 2026, 8:44am UTC](https://community.graylog.org/t/script-callback-with-sbs-change-to-api/37548 "2026-09-03T08:44:48Z")

</div>

Hi there, this is no question, this is a solution for all who cant use the SBS-License in future. unfortunatly our SBS Licence will expire in december and our higher ups are not willing to pay for this. so we need to m…

---

## [Pipeline to stream](https://community.graylog.org/t/pipeline-to-stream/37550)

<div class="topic-metadata">

**Author:** [@igoriceg](https://community.graylog.org/u/igoriceg)\
**Replies:** 4\
**Last updated:** [September 3, 2026, 8:38am UTC](https://community.graylog.org/t/pipeline-to-stream/37550 "2026-09-03T08:38:24Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [GrayView — native Graylog log client for iPhone/iPad](https://community.graylog.org/t/grayview-native-graylog-log-client-for-iphone-ipad/37539)

<div class="topic-metadata">

**Author:** [@ntngel1](https://community.graylog.org/u/ntngel1)\
**Replies:** 0\
**Last updated:** [August 26, 2026, 1:05pm UTC](https://community.graylog.org/t/grayview-native-graylog-log-client-for-iphone-ipad/37539 "2026-08-26T13:05:45Z")

</div>

Hi all — I’ve been building a native iOS/iPadOS client for Graylog called GrayView, and the TestFlight beta just got approved. It connects to your own server with an access token or username/password (self-signed certs …

---

## [New Marketplace listing — ITOC360 integration for Graylog](https://community.graylog.org/t/new-marketplace-listing-itoc360-integration-for-graylog/37537)

<div class="topic-metadata">

**Author:** [@talhabektas](https://community.graylog.org/u/talhabektas)\
**Replies:** 0\
**Last updated:** [August 26, 2026, 1:05pm UTC](https://community.graylog.org/t/new-marketplace-listing-itoc360-integration-for-graylog/37537 "2026-08-26T13:05:22Z")

</div>

Repository: GitHub - itoc360/ITOC360-graylog: Route Graylog event notifications to ITOC360 for on-call alerting and incident management · GitHub ITOC360 is an incident response platform — it receives alerts from your mo…

---

## [Remove AWS SDK v1 from the AWS plugin + bump amqp-client to fix 3 CVEs (PR #27074, targets 7.1)](https://community.graylog.org/t/remove-aws-sdk-v1-from-the-aws-plugin-bump-amqp-client-to-fix-3-cves-pr-27074-targets-7-1/37535)

<div class="topic-metadata">

**Author:** [@pranavphate](https://community.graylog.org/u/pranavphate)\
**Replies:** 0\
**Last updated:** [August 26, 2026, 1:05pm UTC](https://community.graylog.org/t/remove-aws-sdk-v1-from-the-aws-plugin-bump-amqp-client-to-fix-3-cves-pr-27074-targets-7-1/37535 "2026-08-26T13:05:14Z")

</div>

Hi all — opened a PR against 7.1 and wanted to give some context and get eyes on it before it goes further: Remove AWS SDK v1 from the AWS plugin and bump amqp-client to 5.34.0 by pranavp26 · Pull Request #27074 · Graylo…

---

## [Opensearch (under Datanode) reachable with default user admin/admin; how to fix this?](https://community.graylog.org/t/opensearch-under-datanode-reachable-with-default-user-admin-admin-how-to-fix-this/37517)

<div class="topic-metadata">

**Author:** [@schurd](https://community.graylog.org/u/schurd)\
**Replies:** 6\
**Last updated:** [August 21, 2026, 12:35pm UTC](https://community.graylog.org/t/opensearch-under-datanode-reachable-with-default-user-admin-admin-how-to-fix-this/37517 "2026-08-21T12:35:10Z")

</div>

Hello, after the successful migration from opensearch 1.3.20 to Graylog Datanode 7.1.7 we found out, that the opensearch nodes are reachable on port 9200 (with self-signed certificates). That’s not the probelm, but one…

---

## [Systemd journal ingestion?](https://community.graylog.org/t/systemd-journal-ingestion/37493)

<div class="topic-metadata">

**Author:** [@richardm1](https://community.graylog.org/u/richardm1)\
**Replies:** 2\
**Last updated:** [August 18, 2026, 4:07pm UTC](https://community.graylog.org/t/systemd-journal-ingestion/37493 "2026-08-18T16:07:45Z")

</div>

I have a very small use case for something like graylog: Power it up; ingest a system’s entire \[systemd\] journal for search, analysis, and troubleshooting of a specific problem. Shut down graylog when done. Fire it up …

---

## [Graylog server+datanode 7.0.11 Watermark calculation incorrect/unclear](https://community.graylog.org/t/graylog-server-datanode-7-0-11-watermark-calculation-incorrect-unclear/37489)

<div class="topic-metadata">

**Author:** [@roman\_the](https://community.graylog.org/u/roman_the)\
**Replies:** 2\
**Last updated:** [August 17, 2026, 9:27am UTC](https://community.graylog.org/t/graylog-server-datanode-7-0-11-watermark-calculation-incorrect-unclear/37489 "2026-08-17T09:27:36Z")

</div>

1. Describe your incident: After migrating our Graylog instance to a new server (as a part of widespread OS replacement process) we started encountering frequent Flood Watermark warnings that keep coming back. Importan…

---

## [HTTP JSON input dropping messages and failing to parse raw payload from external web service](https://community.graylog.org/t/http-json-input-dropping-messages-and-failing-to-parse-raw-payload-from-external-web-service/37501)

<div class="topic-metadata">

**Author:** [@elenawhit218](https://community.graylog.org/u/elenawhit218)\
**Replies:** 1\
**Last updated:** [August 14, 2026, 1:52pm UTC](https://community.graylog.org/t/http-json-input-dropping-messages-and-failing-to-parse-raw-payload-from-external-web-service/37501 "2026-08-14T13:52:32Z")

</div>

Hi everyone, I am currently configuring Graylog to collect execution status logs and event webhooks from an external application server. I have been attempting to stream HTTP JSON payloads directly into an HTTP input fr…

---

## [Graylog 7.0.11 with self-manged Opensearch 2.19.3 cluster, looking to migrate to Graylog Data Node](https://community.graylog.org/t/graylog-7-0-11-with-self-manged-opensearch-2-19-3-cluster-looking-to-migrate-to-graylog-data-node/37498)

<div class="topic-metadata">

**Author:** [@ovreba](https://community.graylog.org/u/ovreba)\
**Replies:** 1\
**Last updated:** [August 14, 2026, 6:13am UTC](https://community.graylog.org/t/graylog-7-0-11-with-self-manged-opensearch-2-19-3-cluster-looking-to-migrate-to-graylog-data-node/37498 "2026-08-14T06:13:37Z")

</div>

1. Describe your incident: Hi guys! I’m in the process of planning to migrate our self-managed OpenSearch backend to Graylog Data Nodes. We currently have 3 OpenSearch master nodes (VM’s) and 4 Data Nodes (physical ser…

---

## [Feature request - allow suppression of specific system notifications](https://community.graylog.org/t/feature-request-allow-suppression-of-specific-system-notifications/37490)

<div class="topic-metadata">

**Author:** [@GiverSeries](https://community.graylog.org/u/GiverSeries)\
**Replies:** 1\
**Last updated:** [August 10, 2026, 3:58pm UTC](https://community.graylog.org/t/feature-request-allow-suppression-of-specific-system-notifications/37490 "2026-08-10T15:58:41Z")

</div>

It should be possible to suppress/silence unwanted system notifications. For example my datanode heap size is 4 GB and I am pestered by the “Data Node Heap Size Warning” every time. No matter how many times it happens I…

---

## [How to collect graylog server/datanode logs, using plugins or sidecar?](https://community.graylog.org/t/how-to-collect-graylog-server-datanode-logs-using-plugins-or-sidecar/37487)

<div class="topic-metadata">

**Author:** [@baalkchina](https://community.graylog.org/u/baalkchina)\
**Replies:** 3\
**Last updated:** [August 10, 2026, 7:55am UTC](https://community.graylog.org/t/how-to-collect-graylog-server-datanode-logs-using-plugins-or-sidecar/37487 "2026-08-10T07:55:37Z")

</div>

Hello everyone, I have a Graylog cluster and I use syslog or Sidecar to collect logs from switches and servers. However, I did not install Sidecar on the Graylog server and data nodes to collect Graylog’s own logs. Is th…

---

## [Graylog GELF output failure causes logs to stall in journal – is this expected?](https://community.graylog.org/t/graylog-gelf-output-failure-causes-logs-to-stall-in-journal-is-this-expected/37480)

<div class="topic-metadata">

**Author:** [@baalkchina](https://community.graylog.org/u/baalkchina)\
**Replies:** 2\
**Last updated:** [August 1, 2026, 1:27am UTC](https://community.graylog.org/t/graylog-gelf-output-failure-causes-logs-to-stall-in-journal-is-this-expected/37480 "2026-08-01T01:27:33Z")

</div>

Hello everyone, I’m using Graylog Open and currently have some Syslog inputs, each mapped to a corresponding stream. I’ve just added three GELF outputs over TCP. I’ve noticed that if the target endpoint of a GELF output…

---

## [Upgrade from 5.2 to 6.0 Fails](https://community.graylog.org/t/upgrade-from-5-2-to-6-0-fails/37471)

<div class="topic-metadata">

**Author:** [@AutosystemsIT](https://community.graylog.org/u/AutosystemsIT)\
**Replies:** 3\
**Last updated:** [July 27, 2026, 6:08pm UTC](https://community.graylog.org/t/upgrade-from-5-2-to-6-0-fails/37471 "2026-07-27T18:08:40Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Log shows VersionProbe error messages after version 7.1 update](https://community.graylog.org/t/log-shows-versionprobe-error-messages-after-version-7-1-update/37452)

<div class="topic-metadata">

**Author:** [@SichuanPaoCai](https://community.graylog.org/u/SichuanPaoCai)\
**Replies:** 11\
**Last updated:** [July 23, 2026, 11:18pm UTC](https://community.graylog.org/t/log-shows-versionprobe-error-messages-after-version-7-1-update/37452 "2026-07-23T23:18:06Z")

</div>

1. Describe your incident: A few months ago I made a fresh deployment of Graylog Open 6.3 with Docker Compose while following the relevant documentation. I configured the internal Graylog CA and provisioned the Data Nod…

---

## [DataNode Migration stalled in step 3 Provision the Data Node's certificate](https://community.graylog.org/t/datanode-migration-stalled-in-step-3-provision-the-data-nodes-certificate/37432)

<div class="topic-metadata">

**Author:** [@schurd](https://community.graylog.org/u/schurd)\
**Replies:** 6\
**Last updated:** [July 22, 2026, 6:05am UTC](https://community.graylog.org/t/datanode-migration-stalled-in-step-3-provision-the-data-nodes-certificate/37432 "2026-07-22T06:05:43Z")

</div>

1. Describe your incident: I try to do a Data Node Migration from openSearch 1.3.20 to the latest Data Node 7.1.5. Everything runs smooth, but the process stalls in step 3 “Provision the Data Node’s certificate” In th…

---

## [Graylog only retaining 1 month of logs instead of 3 months, no recent configuration changes](https://community.graylog.org/t/graylog-only-retaining-1-month-of-logs-instead-of-3-months-no-recent-configuration-changes/37461)

<div class="topic-metadata">

**Author:** [@Prashant6456](https://community.graylog.org/u/Prashant6456)\
**Replies:** 1\
**Last updated:** [July 21, 2026, 9:55am UTC](https://community.graylog.org/t/graylog-only-retaining-1-month-of-logs-instead-of-3-months-no-recent-configuration-changes/37461 "2026-07-21T09:55:06Z")

</div>

Hi everyone, I’m troubleshooting an issue with our Graylog deployment and would appreciate some guidance. Environment Graylog Version: 6.1.16 Datanode Version: 6.1.16 Operating System: Amazon Linux 2 Storage…

---

## [Not able to upgrade beyond 6.3.11 - Couldn't deserialize value (encrypted\_value and salt must be strings and cannot be missing)](https://community.graylog.org/t/not-able-to-upgrade-beyond-6-3-11-couldnt-deserialize-value-encrypted-value-and-salt-must-be-strings-and-cannot-be-missing/37437)

<div class="topic-metadata">

**Author:** [@ddean](https://community.graylog.org/u/ddean)\
**Replies:** 3\
**Last updated:** [July 20, 2026, 10:52am UTC](https://community.graylog.org/t/not-able-to-upgrade-beyond-6-3-11-couldnt-deserialize-value-encrypted-value-and-salt-must-be-strings-and-cannot-be-missing/37437 "2026-07-20T10:52:30Z")

</div>

1. Describe your incident: When starting a processing node on 6.3.12 or later, the node logs errors that a “decrypted\_value and salt must be strings and cannot be missing” and then restarts. The cluster runs on version …

---

## [Missing Permissions on 7.1.5 for Reader Role](https://community.graylog.org/t/missing-permissions-on-7-1-5-for-reader-role/37431)

<div class="topic-metadata">

**Author:** [@rodney\_vdw](https://community.graylog.org/u/rodney_vdw)\
**Replies:** 1\
**Last updated:** [July 14, 2026, 8:12am UTC](https://community.graylog.org/t/missing-permissions-on-7-1-5-for-reader-role/37431 "2026-07-14T08:12:37Z")

</div>

after upgrading to Graylog 7.1.5, users (with Reader permission) can see and search messages in streams shared with them as per usual, but clicking on a message “permalink” results in a permission denied error. Has some…

---

## [Pipeline does not work anymore after upgrade to 7.1.3 from 7.0](https://community.graylog.org/t/pipeline-does-not-work-anymore-after-upgrade-to-7-1-3-from-7-0/37403)

<div class="topic-metadata">

**Author:** [@schurd](https://community.graylog.org/u/schurd)\
**Replies:** 4\
**Last updated:** [July 13, 2026, 7:55am UTC](https://community.graylog.org/t/pipeline-does-not-work-anymore-after-upgrade-to-7-1-3-from-7-0/37403 "2026-07-13T07:55:23Z")

</div>

Hello, a complex pipeline with 4 stages and 5 rules does not work like before in Graylog 7.0.8. In stage 4 a rule is applied to a newly created field (created in stage 2, there is no stage 3). The rule is applied only …

---

## [ NEWBIE QUESTION: Server currently unavailable ](https://community.graylog.org/t/newbie-question-server-currently-unavailable/37414)

<div class="topic-metadata">

**Author:** [@martl](https://community.graylog.org/u/martl)\
**Replies:** 3\
**Last updated:** [July 8, 2026, 10:44am UTC](https://community.graylog.org/t/newbie-question-server-currently-unavailable/37414 "2026-07-08T10:44:43Z")

</div>

Hello dear Helpers, I am new to Graylog and took this servers from another guy, but I cannot ask him about this. Can you help me figure out how to fix the problem, what do I need to do? Please write for newbies not for p…

---

## [Blocked if accessing help links from the web UI by Cloudflare](https://community.graylog.org/t/blocked-if-accessing-help-links-from-the-web-ui-by-cloudflare/37415)

<div class="topic-metadata">

**Author:** [@luca](https://community.graylog.org/u/luca)\
**Replies:** 0\
**Last updated:** [July 3, 2026, 6:39am UTC](https://community.graylog.org/t/blocked-if-accessing-help-links-from-the-web-ui-by-cloudflare/37415 "2026-07-03T06:39:12Z")

</div>

If I click on one the help links which are at the top of most pages in graylog’s UI, for instance Pipeline documentation, or Dashboard documentation (links below), I get a Cloudflare block: Cloudflare Ray ID: a142009b08…

---

## [Graylog no longer works following an upgrade to Graylog Server 7.1.4](https://community.graylog.org/t/graylog-no-longer-works-following-an-upgrade-to-graylog-server-7-1-4/37409)

<div class="topic-metadata">

**Author:** [@reni](https://community.graylog.org/u/reni)\
**Replies:** 8\
**Last updated:** [July 2, 2026, 10:39am UTC](https://community.graylog.org/t/graylog-no-longer-works-following-an-upgrade-to-graylog-server-7-1-4/37409 "2026-07-02T10:39:40Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

[Next page](https://community.graylog.org/latest.md?page=1)
