I just startet working graylog at the moment I try 5/min
2019-09-17T09:41:03.085Z INFO [InputStateListener] Input [Random HTTP message generator/5d80aa2ed2ab0e04ff8f7700] is now STARTING
2019-09-17T09:41:03.108Z INFO [InputStateListener] Input [Random HTTP message generator/5d80aa2ed2ab0e04ff8f7700] is now RUNNING
2019-09-17T09:41:03.249Z INFO [connection] Opened connection [connectionId{localValue:15, serverValue:34}] to localhost:27017
2019-09-17T09:41:03.249Z INFO [connection] Opened connection [connectionId{localValue:16, serverValue:35}] to localhost:27017
2019-09-17T09:41:03.250Z INFO [connection] Opened connection [connectionId{localValue:12, serverValue:31}] to localhost:27017
2019-09-17T09:41:03.250Z INFO [connection] Opened connection [connectionId{localValue:14, serverValue:33}] to localhost:27017
2019-09-17T09:41:03.250Z INFO [connection] Opened connection [connectionId{localValue:11, serverValue:30}] to localhost:27017
2019-09-17T09:41:03.250Z INFO [connection] Opened connection [connectionId{localValue:13, serverValue:32}] to localhost:27017
2019-09-17T09:43:12.072Z INFO [InputStateListener] Input [Random HTTP message generator/5d80aa2ed2ab0e04ff8f7700] is now STOPPING
2019-09-17T09:43:12.107Z INFO [InputStateListener] Input [Random HTTP message generator/5d80aa2ed2ab0e04ff8f7700] is now TERMINATED
2019-09-17T09:43:12.108Z INFO [InputStateListener] Input [Random HTTP message generator/5d80aa2ed2ab0e04ff8f7700] is now STOPPED
2019-09-17T09:43:12.112Z INFO [InputStateListener] Input [Random HTTP message generator/5d80aa2ed2ab0e04ff8f7700] is now STARTING
2019-09-17T09:43:12.115Z INFO [InputStateListener] Input [Random HTTP message generator/5d80aa2ed2ab0e04ff8f7700] is now RUNNING
output:
root@logsrv01:/home/hh# echo ‘db.processing_status.find()’ | mongo
MongoDB shell version v4.0.12
connecting to: mongodb://127.0.0.1:27017/?gssapiServiceName=mongodb
Implicit session: session { “id” : UUID(“dcc342a0-47c8-480f-80e8-cf7d662e3797”) }
MongoDB server version: 4.0.12
bye
root@logsrv01:/home/hh#
Yeah i see them when i search way back to the 12th. (we are now at 13th)
regarding the 1 minute chunks … any way to speed this up ? or delete them all?
We are aware that this is problem and will address this sooner or later.
I think the easiest way to make it catch up, is to delete the Event Definition and create a new identical one.
That one should start processing from the current time onwards.
Heay
I did what you asked. There are no events in alert page but sometimes I get emails and sometimes not.
Is there any Graylag version in the past for Debian, which everything worked without problem (Version 2.X)? if yes do you have installitions url
Thanhs
Having the same issue as well on 3.1.2. Alerts were working when we did initial testing with Graylog at version 3.0 a couple months back. We will receive email notifications for our alerts at random times or just not at all.
@datamans could you please open a new thread - on such a long conversation just adding “I have the same issue” without writing what workarounds that are already given you have tried already and what your current status is does not help at all.
@kzimmerm what exactly did you already tried and what is the current result? For you the same as @datamans. while you could reference this posting in your own it does not really is helpful - because how should anybody from the outside know what your current state is and what you have already tried?
I have tried adding message_journal_enabled = false to the idle nodes but no dice.
I’ve tried processing_status_journal_write_rate_threshold = 0 and that did not help.
Should both of those parameters only exist on the master graylog node?
We have a 4 node cluster on CentOS 7.5.
Mongodb 4.0.12-1
Elasticsearch 6.8.3-1
Graylog 3.1.2
Right now we are building out a test cluster with version 3.0 until this can be resolved.
I guess that it is more that you do not have enough messages in the test cluster that the alerting is not triggered because of the low ingest rate in the test cluster @kzimmerm