I have tried this twice now, but had to revert back to snap shots
After the upgrade from 2,2,3 , the server starts up ok, but when a new indice is required a error appears in the graylog server.log , reported by java saying that it cant create a new indice.
I don’t have a copy of the logs as had to revert to snapshot however here is all the facts I have available
the server.conf wasn’t replaced during upgrade, it created one called server.conf.rpm.new however when it happened , I copied over the sha keys, to the file and swapped them over.
my build (centos7, java 1,8, elasticsearch 2.3.3, MongoD v3.2.12),
I did notice in the new Graylog server.conf there appears to be a lot more elasticsearch settings
However I noticed missing the reference to the elasticsearch.yml location
also no mention of the cluster name
I assumed this was deliberate, so didn’t put these lines in (I think I tried on the first occasion this happened and Graylog wouldn’t start up, so all I put in was the KEY)
I checked that the indices where owned by elasticsearch
I tried to touch the new indice to see if manually creating it would allow it to work, but same error saying cant create
Up until the point when the indice needed a new one creating and a rotation taking place, graylog was running fine.
Diskspace is 65%, I even deleted a couple of indices from the GUI, but no joy.
I cycled the deflector.
Nothing would would create a new indice, and no new messages were being appended after it hit this problem.