I’m running Graylog 2.4.4+4659dbe and have done the recommended steps:
- Stop Graylog
- Delete the graylog_delector using: curl -X DELETE ‘127.0.0.1:9200/graylog_deflector’
The index is removed but as soon as I start Graylog, the graylog_deflector is recreated:
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
yellow open graylog_deflector 5wrUelgMRXWB0N2dBEoaNA 5 1 1274 0 1.7mb 1.7mb
I have the elasticsearch_discovery_enabled set to false in the server.conf
As soon as I start Graylog, the “Deflector exists as an index and is not an alias” error is shown immediately.
I am receiving messages but obviously can’t see them in the stream and can’t search on them.
Any help would be appreciated.