Ok here are the logs:
2022-04-08T14:36:55.300-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRotationThread] periodical in [0s], polling every [10s].
2022-04-08T14:36:55.300-04:00 INFO [LegacyDefaultStreamMigration] Legacy default stream has no connections, no migration needed.
2022-04-08T14:36:55.301-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.NodePingThread] periodical in [0s], polling every [1s].
2022-04-08T14:36:55.302-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.VersionCheckThread] periodical in [300s], polling every [1800s].
2022-04-08T14:36:55.303-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.ThrottleStateUpdaterThread] periodical in [1s], polling every [1s].
2022-04-08T14:36:55.303-04:00 INFO [Periodicals] Starting [org.graylog2.events.ClusterEventPeriodical] periodical in [0s], polling every [1s].
2022-04-08T14:36:55.306-04:00 INFO [Periodicals] Starting [org.graylog2.events.ClusterEventCleanupPeriodical] periodical in [0s], polling every [86400s].
2022-04-08T14:36:55.311-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.ClusterIdGeneratorPeriodical] periodical, running forever.
2022-04-08T14:36:55.311-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRangesMigrationPeriodical] periodical, running forever.
2022-04-08T14:36:55.312-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRangesCleanupPeriodical] periodical in [15s], polling every [3600s].
2022-04-08T14:36:55.336-04:00 INFO [connection] Opened connection [connectionId{localValue:5, serverValue:5}] to localhost:27017
2022-04-08T14:36:55.341-04:00 INFO [connection] Opened connection [connectionId{localValue:4, serverValue:4}] to localhost:27017
2022-04-08T14:36:55.361-04:00 INFO [connection] Opened connection [connectionId{localValue:7, serverValue:7}] to localhost:27017
2022-04-08T14:36:55.374-04:00 INFO [IndexRetentionThread] Elasticsearch cluster not available, skipping index retention checks.
2022-04-08T14:36:55.374-04:00 INFO [connection] Opened connection [connectionId{localValue:6, serverValue:6}] to localhost:27017
2022-04-08T14:36:55.375-04:00 INFO [connection] Opened connection [connectionId{localValue:9, serverValue:9}] to localhost:27017
2022-04-08T14:36:55.376-04:00 INFO [PeriodicalsService] Not starting [org.graylog2.periodical.UserPermissionMigrationPeriodical] periodical. Not configured to run on this node.
2022-04-08T14:36:55.376-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.AlarmCallbacksMigrationPeriodical] periodical, running forever.
2022-04-08T14:36:55.380-04:00 INFO [connection] Opened connection [connectionId{localValue:10, serverValue:10}] to localhost:27017
2022-04-08T14:36:55.382-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.ConfigurationManagementPeriodical] periodical, running forever.
2022-04-08T14:36:55.387-04:00 ERROR [Cluster] Couldn't read cluster health for indices [graylog_*] (Could not connect to http://127.0.0.1:9200)
2022-04-08T14:36:55.391-04:00 INFO [IndexerClusterCheckerThread] Indexer not fully initialized yet. Skipping periodic cluster check.
2022-04-08T14:36:55.400-04:00 INFO [connection] Opened connection [connectionId{localValue:8, serverValue:8}] to localhost:27017
2022-04-08T14:36:55.410-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.LdapGroupMappingMigration] periodical, running forever.
2022-04-08T14:36:55.411-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexFailuresPeriodical] periodical, running forever.
2022-04-08T14:36:55.422-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.TrafficCounterCalculator] periodical in [0s], polling every [1s].
2022-04-08T14:36:55.430-04:00 INFO [Periodicals] Starting [org.graylog2.indexer.fieldtypes.IndexFieldTypePollerPeriodical] periodical in [0s], polling every [3600s].
2022-04-08T14:36:55.433-04:00 INFO [Periodicals] Starting [org.graylog.plugins.sidecar.periodical.PurgeExpiredSidecarsThread] periodical in [0s], polling every [600s].
2022-04-08T14:36:55.433-04:00 INFO [IndexFieldTypePollerPeriodical] Cluster not connected yet, delaying index field type initialization until it is reachable.
2022-04-08T14:36:55.434-04:00 INFO [Periodicals] Starting [org.graylog.plugins.sidecar.periodical.PurgeExpiredConfigurationUploads] periodical in [0s], polling every [600s].
2022-04-08T14:36:55.437-04:00 INFO [Periodicals] Starting [org.graylog.plugins.collector.periodical.PurgeExpiredCollectorsThread] periodical in [0s], polling every [3600s].
2022-04-08T14:36:55.519-04:00 INFO [V20161130141500_DefaultStreamRecalcIndexRanges] Cluster not connected yet, delaying migration until it is reachable.
2022-04-08T14:36:55.764-04:00 INFO [JerseyService] Enabling CORS for HTTP endpoint
2022-04-08T14:37:05.873-04:00 ERROR [AlertScanner] Skipping alert check <Tor Detection/d854d24c-42b6-40f8-8263-c72da0f2a1b8>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:05.979-04:00 ERROR [AlertScanner] Skipping alert check <Domain Controller Status/c53a101d-b92c-4225-939a-412ce7768ea0>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:06.021-04:00 ERROR [AlertScanner] Skipping alert check <Firewall status/cccb6a57-afd9-4c64-a8d7-2afc6d907d91>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:06.069-04:00 ERROR [AlertScanner] Skipping alert check <DHCP - Status/5175aa2c-fa4e-401a-89e6-f4947add68cf>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:06.144-04:00 ERROR [AlertScanner] Skipping alert check <DNS01 - Status/32c2a59d-e782-405c-b48c-2b082636442e>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:06.184-04:00 ERROR [AlertScanner] Skipping alert check <HBSS01 - Status/424014d8-2a3f-478e-9b1e-5640eaba2cd0>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:06.211-04:00 ERROR [AlertScanner] Skipping alert check <DNS02 - Status/f43baf2c-a799-4d03-8347-cacf6506ed08>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:06.266-04:00 ERROR [AlertScanner] Skipping alert check <DNS03 - Status/608b707e-9c69-4669-b99d-690621bd2fb6>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:06.288-04:00 ERROR [AlertScanner] Skipping alert check <DNS04 - Status/7dec668a-9ef8-4a2c-b2d9-b5965ee9f0a8>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:06.328-04:00 ERROR [AlertScanner] Skipping alert check <AD01 - Status/fb5a3db2-359d-4a98-a1a3-1b55537953fe>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:06.378-04:00 ERROR [AlertScanner] Skipping alert check <AD02 - Status/541f241c-20f3-4c39-86f3-b9bf926f7be8>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:06.441-04:00 ERROR [AlertScanner] Skipping alert check <AD03 - Status/5f211d0f-07b7-4a98-b432-ef53e90a83bc>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:06.500-04:00 ERROR [AlertScanner] Skipping alert check <AD04 - Status/613f7904-6787-49fe-bbe1-5b8b307292dd>: Unable to perform count query
{"root_cause":[],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[]} (ElasticsearchException)
2022-04-08T14:37:10.350-04:00 INFO [IndexRangesCleanupPeriodical] Skipping index range cleanup because the Elasticsearch cluster is unreachable or unhealthy
2022-04-08T14:37:25.059-04:00 INFO [NetworkListener] Started listener bound to [graylogFQDN:9000]
2022-04-08T14:37:25.061-04:00 INFO [HttpServer] [HttpServer] Started.
2022-04-08T14:37:25.062-04:00 INFO [JerseyService] Started REST API at <graylogFQDN:9000>
2022-04-08T14:37:25.064-04:00 INFO [ServiceManagerListener] Services are healthy
2022-04-08T14:37:25.066-04:00 INFO [ServerBootstrap] Services started, startup times in ms: {InputSetupService [RUNNING]=2, GracefulShutdownService [RUNNING]=37, BufferSynchronizerService [RUNNING]=41, ConfigurationEtagService [RUNNING]=41, JournalReader [RUNNING]=42, OutputSetupService [RUNNING]=60, EtagService [RUNNING]=60, KafkaJournal [RUNNING]=73, LookupTableService [RUNNING]=221, StreamCacheService [RUNNING]=225, PeriodicalsService [RUNNING]=240, JerseyService [RUNNING]=29822}
2022-04-08T14:37:25.068-04:00 INFO [InputSetupService] Triggering launching persisted inputs, node transitioned from Uninitialized [LB:DEAD] to Running [LB:ALIVE]
2022-04-08T14:37:25.131-04:00 INFO [ServerBootstrap] Graylog server up and running.
2022-04-08T14:37:25.212-04:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/5cf1398829fbc65472f9e760] is now STARTING
2022-04-08T14:37:25.247-04:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/5cf13c1329fbc65472f9ea2a] is now STARTING
2022-04-08T14:37:25.265-04:00 INFO [InputStateListener] Input [Syslog TCP/5cf13c2e29fbc65472f9ea4a] is now STARTING
2022-04-08T14:37:25.271-04:00 INFO [InputStateListener] Input [GELF TCP/5cf13a5629fbc65472f9e843] is now STARTING
2022-04-08T14:37:25.272-04:00 INFO [InputStateListener] Input [Syslog UDP/5cf13c4629fbc65472f9ea68] is now STARTING
2022-04-08T14:37:25.419-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=APC Logs, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0x191cd255, L:/0.0.0.0:12201]) should be 262144 but is 425984.
2022-04-08T14:37:25.420-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Firewall, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0x156c1807, L:/0.0.0.0:1514]) should be 262144 but is 425984.
2022-04-08T14:37:25.433-04:00 WARN [AbstractTcpTransport] receiveBufferSize (SO_RCVBUF) for input GELFTCPInput{title=Windows Event Logs, type=org.graylog2.inputs.gelf.tcp.GELFTCPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0xef1484ac, L:/0.0.0.0:12201]) should be 1048576 but is 425984.
2022-04-08T14:37:25.443-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=FirePOWER, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0xade74359, L:/0.0.0.0:5140]) should be 262144 but is 425984.
2022-04-08T14:37:25.453-04:00 INFO [InputStateListener] Input [GELF TCP/5cf13a5629fbc65472f9e843] is now RUNNING
2022-04-08T14:37:25.462-04:00 WARN [AbstractTcpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogTCPInput{title=COC Infrastructure, type=org.graylog2.inputs.syslog.tcp.SyslogTCPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0xb41f9572, L:/0.0.0.0:1514]) should be 1048576 but is 425984.
2022-04-08T14:37:25.463-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Firewall, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0xcfc38ad1, L:/0.0.0.0:1514]) should be 262144 but is 425984.
2022-04-08T14:37:25.466-04:00 INFO [InputStateListener] Input [Syslog TCP/5cf13c2e29fbc65472f9ea4a] is now RUNNING
2022-04-08T14:37:25.497-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=APC Logs, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0xedc6a6e0, L:/0.0.0.0:12201]) should be 262144 but is 425984.
2022-04-08T14:37:25.506-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=FirePOWER, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0x7cb5600d, L:/0.0.0.0:5140]) should be 262144 but is 425984.
2022-04-08T14:37:25.559-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Firewall, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0x925a0f84, L:/0.0.0.0:1514]) should be 262144 but is 425984.
2022-04-08T14:37:25.628-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=APC Logs, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0x5d2b0905, L:/0.0.0.0:12201]) should be 262144 but is 425984.
2022-04-08T14:37:25.660-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Firewall, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0x020fa2f5, L:/0.0.0.0:1514]) should be 262144 but is 425984.
2022-04-08T14:37:25.670-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=FirePOWER, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0x84ce32b2, L:/0.0.0.0:5140]) should be 262144 but is 425984.
2022-04-08T14:37:25.746-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=APC Logs, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0x9c601073, L:/0.0.0.0:12201]) should be 262144 but is 425984.
2022-04-08T14:37:25.769-04:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/5cf1398829fbc65472f9e760] is now RUNNING
2022-04-08T14:37:25.780-04:00 INFO [InputStateListener] Input [Syslog UDP/5cf13c4629fbc65472f9ea68] is now RUNNING
2022-04-08T14:37:25.703-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=FirePOWER, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=9e804424-96fe-42c8-a79a-051fc7fb0963} (channel [id: 0x0d3478cd, L:/0.0.0.0:5140]) should be 262144 but is 425984.
2022-04-08T14:37:25.815-04:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/5cf13c1329fbc65472f9ea2a] is now RUNNING
2022-04-08T14:37:55.482-04:00 WARN [IndexFieldTypePollerPeriodical] Interrupted or timed out waiting for Elasticsearch cluster, checking again.
2022-04-08T14:37:55.537-04:00 WARN [V20161130141500_DefaultStreamRecalcIndexRanges] Interrupted or timed out waiting for Elasticsearch cluster, checking again.
2022-04-08T14:38:26.489-04:00 ERROR [Messages] Caught exception during bulk indexing: java.net.SocketTimeoutException: Read timed out, retrying (attempt #1).
2022-04-08T14:38:28.026-04:00 ERROR [Messages] Caught exception during bulk indexing: java.net.SocketTimeoutException: Read timed out, retrying (attempt #1).
2022-04-08T14:38:55.483-04:00 WARN [IndexFieldTypePollerPeriodical] Interrupted or timed out waiting for Elasticsearch cluster, checking again.
2022-04-08T14:38:55.537-04:00 WARN [V20161130141500_DefaultStreamRecalcIndexRanges] Interrupted or timed out waiting for Elasticsearch cluster, checking again.
2022-04-08T14:38:57.918-04:00 INFO [Messages] Bulk indexing finally successful (attempt #2).
2022-04-08T14:38:59.061-04:00 INFO [Messages] Bulk indexing finally successful (attempt #2).
2022-04-10T17:57:35.310-04:00 INFO [AbstractRotationStrategy] Deflector index <Default index set> (index set <graylog_260>) should be rotated, Pointing deflector to new index now!
2022-04-10T17:57:35.318-04:00 INFO [MongoIndexSet] Cycling from <graylog_260> to <graylog_261>.
2022-04-10T17:57:35.318-04:00 INFO [MongoIndexSet] Creating target index <graylog_261>.
2022-04-10T17:57:35.378-04:00 INFO [Indices] Successfully created index template graylog-internal
2022-04-10T17:57:35.612-04:00 INFO [MongoIndexSet] Waiting for allocation of index <graylog_261>.
2022-04-10T17:57:35.738-04:00 INFO [MongoIndexSet] Index <graylog_261> has been successfully allocated.
2022-04-10T17:57:35.738-04:00 INFO [MongoIndexSet] Pointing index alias <graylog_deflector> to new index <graylog_261>.
2022-04-10T17:57:35.827-04:00 INFO [SystemJobManager] Submitted SystemJob <3b14c2a0-b919-11ec-b2b8-0050568bf8e7> [org.graylog2.indexer.indices.jobs.SetIndexReadOnlyAndCalculateRangeJob]
2022-04-10T17:57:35.827-04:00 INFO [MongoIndexSet] Successfully pointed index alias <graylog_deflector> to index <graylog_261>.
2022-04-10T17:58:05.850-04:00 INFO [SetIndexReadOnlyJob] Flushing old index <graylog_260>.
2022-04-10T17:58:06.176-04:00 INFO [SetIndexReadOnlyJob] Setting old index <graylog_260> to read-only.
2022-04-10T17:58:06.237-04:00 INFO [SystemJobManager] Submitted SystemJob <4d362dc0-b919-11ec-b2b8-0050568bf8e7> [org.graylog2.indexer.indices.jobs.OptimizeIndexJob]
2022-04-10T17:58:06.290-04:00 INFO [CreateNewSingleIndexRangeJob] Calculating ranges for index graylog_260.
2022-04-10T17:58:06.291-04:00 INFO [OptimizeIndexJob] Optimizing index <graylog_260>.
2022-04-10T17:58:08.462-04:00 INFO [MongoIndexRangeService] Calculated range of [graylog_260] in [2169ms].
2022-04-10T17:58:08.464-04:00 INFO [CreateNewSingleIndexRangeJob] Created ranges for index graylog_260.
2022-04-10T17:58:08.474-04:00 INFO [SystemJobManager] SystemJob <3b14c2a0-b919-11ec-b2b8-0050568bf8e7> [org.graylog2.indexer.indices.jobs.SetIndexReadOnlyAndCalculateRangeJob] finished in 2647ms.
2022-04-10T18:00:53.601-04:00 INFO [SystemJobManager] SystemJob <4d362dc0-b919-11ec-b2b8-0050568bf8e7> [org.graylog2.indexer.indices.jobs.OptimizeIndexJob] finished in 167363ms.
2022-04-10T18:01:55.349-04:00 INFO [AbstractIndexCountBasedRetentionStrategy] Number of indices (21) higher than limit (20). Running retention for 1 indices.
2022-04-10T18:01:55.417-04:00 INFO [AbstractIndexCountBasedRetentionStrategy] Running retention strategy [org.graylog2.indexer.retention.strategies.DeletionRetentionStrategy] for index <graylog_241>
2022-04-10T18:01:55.617-04:00 INFO [DeletionRetentionStrategy] Finished index retention strategy [delete] for index <graylog_241> in 198ms.