I’m running Graylog 2.4.5 on a CentOS 6.9 server. I’ve gotten to the point where everything seems to be working fine. I spent time to standardize my Fields and also implement GROK patterns for Syslog messages that have various routers/switches sending in.
I would like to purge all previous message data and start fresh while obviously keeping all my extractors and configuration intact. Due to inexperience, I’m unsure and both uncomfortable with some of the options I’ve ready about in other posts using Delete By Queries or the API options.
What is the easiest way to accomplish my start a new on the message data goal?
Also, thought the graylog-ctl scripts were awesome in the OVA I used initially for some testing which everyone recommended against using for production…hence why I built my current system. Anyway to get the graylog-ctl scripts into my non-OVA base graylog build on CentOS6.9?
Thank you in advance for taking time to help me!