Here’s an update from a fresh VM:
SYSTEMD outputs:
ubuntu@ip-172-31-2-181:~$ sudo systemctl status graylog-server
● graylog-server.service - Graylog server
Loaded: loaded (/usr/lib/systemd/system/graylog-server.service; enabled; vendor preset: enabled)
Active: active (running) since Mon 2018-01-08 21:06:40 UTC; 7min ago
Docs: http://docs.graylog.org/
Main PID: 29305 (graylog-server)
Tasks: 118
Memory: 642.8M
CPU: 34.905s
CGroup: /system.slice/graylog-server.service
├─29305 /bin/sh /usr/share/graylog-server/bin/graylog-server
└─29307 /usr/bin/java -jar -Dlog4j.configurationFile=file:///etc/graylog/server/log4j2.xml -Djava.library.path=/usr/share/graylog-server/lib/sigar -Dgraylog2.installation_source=deb /usr/share/graylog-server/graylog.jar server -f /etc/graylog/server/server.conf -np
Jan 08 21:06:55 ip-172-31-2-181 graylog-server[29305]: 21:06:55.655 [JerseyService STARTING] INFO org.glassfish.grizzly.http.server.HttpServer - [HttpServer] Started.
Jan 08 21:06:55 ip-172-31-2-181 graylog-server[29305]: 21:06:55.655 [JerseyService STARTING] INFO org.graylog2.shared.initializers.JerseyService - Started REST API at <http://0.0.0.0:12900/api/>
Jan 08 21:06:55 ip-172-31-2-181 graylog-server[29305]: 21:06:55.657 [JerseyService STARTING] INFO org.graylog2.shared.initializers.JerseyService - Enabling CORS for HTTP endpoint
Jan 08 21:06:57 ip-172-31-2-181 graylog-server[29305]: 21:06:57.659 [JerseyService STARTING] INFO org.glassfish.grizzly.http.server.NetworkListener - Started listener bound to [0.0.0.0:9000]
Jan 08 21:06:57 ip-172-31-2-181 graylog-server[29305]: 21:06:57.659 [JerseyService STARTING] INFO org.glassfish.grizzly.http.server.HttpServer - [HttpServer-1] Started.
Jan 08 21:06:57 ip-172-31-2-181 graylog-server[29305]: 21:06:57.660 [JerseyService STARTING] INFO org.graylog2.shared.initializers.JerseyService - Started Web Interface at <http://0.0.0.0:9000/>
Jan 08 21:06:57 ip-172-31-2-181 graylog-server[29305]: 21:06:57.660 [JerseyService STARTING] INFO org.graylog2.shared.initializers.ServiceManagerListener - Services are healthy
Jan 08 21:06:57 ip-172-31-2-181 graylog-server[29305]: 21:06:57.661 [main] INFO org.graylog2.bootstrap.ServerBootstrap - Services started, startup times in ms: {KafkaJournal [RUNNING]=18, OutputSetupService [RUNNING]=20, JournalReader [RUNNING]=20, InputSetupService [RUNNING]=20, BufferSynchronizerServic
Jan 08 21:06:57 ip-172-31-2-181 graylog-server[29305]: 21:06:57.662 [main] INFO org.graylog2.bootstrap.ServerBootstrap - Graylog server up and running.
Jan 08 21:06:57 ip-172-31-2-181 graylog-server[29305]: 21:06:57.663 [eventbus-handler-1] INFO org.graylog2.shared.initializers.InputSetupService - Triggering launching persisted inputs, node transitioned from Uninitialized?[LB:DEAD] to Running?[LB:ALIVE]
ubuntu@ip-172-31-2-181:~$ sudo systemctl status elasticsearch
● elasticsearch.service - Elasticsearch
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled)
Active: active (running) since Mon 2018-01-08 21:04:16 UTC; 12min ago
Docs: http://www.elastic.co
Main PID: 28161 (java)
Tasks: 37
Memory: 2.1G
CPU: 13.937s
CGroup: /system.slice/elasticsearch.service
└─28161 /usr/bin/java -Xms1975m -Xmx1975m -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+AlwaysPreTouch -server -Xss1m -Djava.awt.headless=true -Dfile.encoding=UTF-8 -Djna.nosys=true -Djdk.io.permissionsUseCanonicalPath=true -Dio.netty.noUn
Jan 08 21:04:16 ip-172-31-2-181 systemd[1]: Starting Elasticsearch...
Jan 08 21:04:16 ip-172-31-2-181 systemd[1]: Started Elasticsearch.
Log Files:
root@ip-172-31-2-181:/home/ubuntu# cat /var/log/elasticsearch/graylog.log
[2018-01-08T21:04:18,298][INFO ][o.e.n.Node ] [graylog-test] initializing ...
[2018-01-08T21:04:18,415][INFO ][o.e.e.NodeEnvironment ] [graylog-test] using [1] data paths, mounts [[/ (/dev/xvda1)]], net usable_space [5.4gb], net total_space [7.6gb], spins? [no], types [ext4]
[2018-01-08T21:04:18,415][INFO ][o.e.e.NodeEnvironment ] [graylog-test] heap size [1.9gb], compressed ordinary object pointers [true]
[2018-01-08T21:04:18,416][INFO ][o.e.n.Node ] [graylog-test] node name [graylog-test], node ID [oOd-h3mlTwWDR8c-fqSmeQ]
[2018-01-08T21:04:18,417][INFO ][o.e.n.Node ] [graylog-test] version[5.6.2], pid[28161], build[57e20f3/2017-09-23T13:16:45.703Z], OS[Linux/4.4.0-1041-aws/amd64], JVM[Oracle Corporation/OpenJDK 64-Bit Server VM/1.8.0_151/25.151-b12]
[2018-01-08T21:04:18,417][INFO ][o.e.n.Node ] [graylog-test] JVM arguments [-Xms1975m, -Xmx1975m, -XX:+UseConcMarkSweepGC, -XX:CMSInitiatingOccupancyFraction=75, -XX:+UseCMSInitiatingOccupancyOnly, -XX:+AlwaysPreTouch, -Xss1m, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djna.nosys=true, -Djdk.io.permissionsUseCanonicalPath=true, -Dio.netty.noUnsafe=true, -Dio.netty.noKeySetOptimization=true, -Dio.netty.recycler.maxCapacityPerThread=0, -Dlog4j.shutdownHookEnabled=false, -Dlog4j2.disable.jmx=true, -Dlog4j.skipJansi=true, -XX:+HeapDumpOnOutOfMemoryError, -Des.path.home=/usr/share/elasticsearch]
[2018-01-08T21:04:19,687][INFO ][o.e.p.PluginsService ] [graylog-test] loaded module [aggs-matrix-stats]
[2018-01-08T21:04:19,687][INFO ][o.e.p.PluginsService ] [graylog-test] loaded module [ingest-common]
[2018-01-08T21:04:19,687][INFO ][o.e.p.PluginsService ] [graylog-test] loaded module [lang-expression]
[2018-01-08T21:04:19,688][INFO ][o.e.p.PluginsService ] [graylog-test] loaded module [lang-groovy]
[2018-01-08T21:04:19,688][INFO ][o.e.p.PluginsService ] [graylog-test] loaded module [lang-mustache]
[2018-01-08T21:04:19,688][INFO ][o.e.p.PluginsService ] [graylog-test] loaded module [lang-painless]
[2018-01-08T21:04:19,688][INFO ][o.e.p.PluginsService ] [graylog-test] loaded module [parent-join]
[2018-01-08T21:04:19,688][INFO ][o.e.p.PluginsService ] [graylog-test] loaded module [percolator]
[2018-01-08T21:04:19,689][INFO ][o.e.p.PluginsService ] [graylog-test] loaded module [reindex]
[2018-01-08T21:04:19,689][INFO ][o.e.p.PluginsService ] [graylog-test] loaded module [transport-netty3]
[2018-01-08T21:04:19,689][INFO ][o.e.p.PluginsService ] [graylog-test] loaded module [transport-netty4]
[2018-01-08T21:04:19,689][INFO ][o.e.p.PluginsService ] [graylog-test] no plugins loaded
[2018-01-08T21:04:22,513][INFO ][o.e.d.DiscoveryModule ] [graylog-test] using discovery type [zen]
[2018-01-08T21:04:22,991][INFO ][o.e.n.Node ] [graylog-test] initialized
[2018-01-08T21:04:22,991][INFO ][o.e.n.Node ] [graylog-test] starting ...
[2018-01-08T21:04:23,160][INFO ][o.e.t.TransportService ] [graylog-test] publish_address {172.31.2.181:9300}, bound_addresses {[::]:9300}
[2018-01-08T21:04:23,170][INFO ][o.e.b.BootstrapChecks ] [graylog-test] bound or publishing to a non-loopback or non-link-local address, enforcing bootstrap checks
[2018-01-08T21:04:26,231][INFO ][o.e.c.s.ClusterService ] [graylog-test] new_master {graylog-test}{oOd-h3mlTwWDR8c-fqSmeQ}{6AFja72GTBunbjXKLMyWiw}{172.31.2.181}{172.31.2.181:9300}, reason: zen-disco-elected-as-master ([0] nodes joined)
[2018-01-08T21:04:26,261][INFO ][o.e.g.GatewayService ] [graylog-test] recovered [0] indices into cluster_state
[2018-01-08T21:04:26,263][INFO ][o.e.h.n.Netty4HttpServerTransport] [graylog-test] publish_address {172.31.2.181:9200}, bound_addresses {[::]:9200}
[2018-01-08T21:04:26,263][INFO ][o.e.n.Node ] [graylog-test] started
[2018-01-08T21:06:47,793][INFO ][o.e.c.m.MetaDataCreateIndexService] [graylog-test] [graylog_0] creating index, cause [api], templates [graylog-internal], shards [1]/[0], mappings [message]
[2018-01-08T21:06:48,149][INFO ][o.e.c.r.a.AllocationService] [graylog-test] Cluster health status changed from [YELLOW] to [GREEN] (reason: [shards started [[graylog_0][0]] ...]).
root@ip-172-31-2-181:/home/ubuntu# cat /var/log/graylog/collector-sidecar/collector_sidecar.log
time="2018-01-08T21:05:25Z" level=info msg="Starting signal distributor"
time="2018-01-08T21:05:25Z" level=info msg="[filebeat] Starting (exec driver)"
time="2018-01-08T21:05:26Z" level=error msg="[filebeat] Backend finished unexpectedly, trying to restart 1/3."
time="2018-01-08T21:05:26Z" level=info msg="[filebeat] Stopping"
time="2018-01-08T21:05:28Z" level=info msg="[filebeat] Starting (exec driver)"
time="2018-01-08T21:05:29Z" level=error msg="[filebeat] Backend finished unexpectedly, trying to restart 2/3."
time="2018-01-08T21:05:29Z" level=info msg="[filebeat] Stopping"
time="2018-01-08T21:05:31Z" level=info msg="[filebeat] Starting (exec driver)"
time="2018-01-08T21:05:32Z" level=error msg="[filebeat] Backend finished unexpectedly, trying to restart 3/3."
time="2018-01-08T21:05:32Z" level=info msg="[filebeat] Stopping"
time="2018-01-08T21:05:34Z" level=info msg="[filebeat] Starting (exec driver)"
time="2018-01-08T21:05:35Z" level=error msg="[RequestConfiguration] Fetching configuration failed: Get http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9?tags=%5B%22linux%22%2C%22apache%22%5D: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:05:35Z" level=error msg="[filebeat] Unable to start collector after 3 tries, giving up!"
time="2018-01-08T21:05:35Z" level=error msg="[UpdateRegistration] Failed to report collector status to server: Put http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/collectors/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:05:45Z" level=error msg="[RequestConfiguration] Fetching configuration failed: Get http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9?tags=%5B%22linux%22%2C%22apache%22%5D: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:05:45Z" level=error msg="[UpdateRegistration] Failed to report collector status to server: Put http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/collectors/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:05:55Z" level=error msg="[RequestConfiguration] Fetching configuration failed: Get http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9?tags=%5B%22linux%22%2C%22apache%22%5D: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:05:55Z" level=error msg="[UpdateRegistration] Failed to report collector status to server: Put http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/collectors/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:06:05Z" level=error msg="[RequestConfiguration] Fetching configuration failed: Get http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9?tags=%5B%22linux%22%2C%22apache%22%5D: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:06:05Z" level=error msg="[UpdateRegistration] Failed to report collector status to server: Put http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/collectors/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:06:15Z" level=error msg="[RequestConfiguration] Fetching configuration failed: Get http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9?tags=%5B%22linux%22%2C%22apache%22%5D: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:06:15Z" level=error msg="[UpdateRegistration] Failed to report collector status to server: Put http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/collectors/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:06:25Z" level=error msg="[RequestConfiguration] Fetching configuration failed: Get http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9?tags=%5B%22linux%22%2C%22apache%22%5D: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:06:25Z" level=error msg="[UpdateRegistration] Failed to report collector status to server: Put http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/collectors/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:06:35Z" level=error msg="[RequestConfiguration] Fetching configuration failed: Get http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9?tags=%5B%22linux%22%2C%22apache%22%5D: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:06:35Z" level=error msg="[UpdateRegistration] Failed to report collector status to server: Put http://127.0.0.1:9000/api/plugins/org.graylog.plugins.collector/collectors/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9: dial tcp 127.0.0.1:9000: getsockopt: connection refused"
time="2018-01-08T21:06:40Z" level=info msg="Stopping signal distributor"
time="2018-01-08T21:06:40Z" level=info msg="Starting signal distributor"
time="2018-01-08T21:06:40Z" level=info msg="[filebeat] Starting (exec driver)"
time="2018-01-08T21:06:41Z" level=error msg="[filebeat] Backend finished unexpectedly, trying to restart 1/3."
time="2018-01-08T21:06:41Z" level=info msg="[filebeat] Stopping"
time="2018-01-08T21:06:43Z" level=info msg="[filebeat] Starting (exec driver)"
time="2018-01-08T21:06:44Z" level=error msg="[filebeat] Backend finished unexpectedly, trying to restart 2/3."
time="2018-01-08T21:06:44Z" level=info msg="[filebeat] Stopping"
time="2018-01-08T21:06:46Z" level=info msg="[filebeat] Starting (exec driver)"
time="2018-01-08T21:06:47Z" level=error msg="[filebeat] Backend finished unexpectedly, trying to restart 3/3."
time="2018-01-08T21:06:47Z" level=info msg="[filebeat] Stopping"
time="2018-01-08T21:06:49Z" level=info msg="[filebeat] Starting (exec driver)"
time="2018-01-08T21:06:50Z" level=error msg="[RequestConfiguration] Fetching configuration failed: Get http://0.0.0.0:9000/api/plugins/org.graylog.plugins.collector/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9?tags=%5B%22linux%22%5D: dial tcp 0.0.0.0:9000: getsockopt: connection refused"
time="2018-01-08T21:06:50Z" level=error msg="[UpdateRegistration] Failed to report collector status to server: Put http://0.0.0.0:9000/api/plugins/org.graylog.plugins.collector/collectors/d58353f9-f3ad-4a5f-8e7a-e470b67ab6b9: dial tcp 0.0.0.0:9000: getsockopt: connection refused"
time="2018-01-08T21:06:50Z" level=error msg="[filebeat] Unable to start collector after 3 tries, giving up!"