# Data Node not showing up in Graylog 6.3 Preflight Configuration

**URL:** <https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965>\
**Category:** Graylog Central (peer support)\
**Tags:** data-node\
**Created:** [July 8, 2025, 1:38pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965 "2025-07-08T13:38:08Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![douglas\_ns](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@douglas\_ns](https://community.graylog.org/u/douglas_ns)\
**Post date:** [July 8, 2025, 1:38pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/1 "2025-07-08T13:38:09Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.  
**Don’t forget to select tags to help index your topic!**

**1. Describe your incident:**  
I’m setting up a Graylog 6.3 environment with a separate Data Node. However, the Data Node does not appear in the Graylog Server’s preflight configuration interface. Both servers can communicate with each other, MongoDB is correctly configured and accessible, and all services are running, but the Data Node is still not detected in the UI.

**2. Describe your environment:**  
\*Ubuntu 24

- Package Version:  
6.3
- Service logs, configurations, and environment variables:  
server.log  
========================================================================================================

It seems you are starting Graylog for the first time. To set up a fresh install, a setup interface has  
been started. You must log in to it to perform the initial configuration and continue.

Initial configuration is accessible at 192.168.200.253:9000, with username ‘admin’ and password ‘SLiwAgnYxj’.  
Try clicking on http ://admin:SLiwAgnYxj@192.168.200.253:9000

========================================================================================================

(END)  
datanode  
2025-07-08T10:14:53.352-03:00 INFO [JerseyService] Starting Data node REST API  
2025-07-08T10:14:53.352-03:00 INFO [DatanodeBootstrap] Services started, startup times in ms: {GracefulShutdownService [RUNNING]=0, OpensearchProcessService [RUNNING]=0, PeriodicalsService [RUNNING]=68, OpensearchConfigurationService [RUNNING]=106}  
2025-07-08T10:14:53.353-03:00 INFO [DatanodeBootstrap] Graylog DataNode datanode up and running.  
2025-07-08T10:14:53.857-03:00 INFO [Version] HV000001: Hibernate Validator 8.0.2.Final  
2025-07-08T10:14:54.119-03:00 INFO [NetworkListener] Started listener bound to [192.168.200.252:8999]  
2025-07-08T10:14:54.121-03:00 INFO [HttpServer] [HttpServer] Started.  
2025-07-08T10:14:54.121-03:00 INFO [JerseyService] Started REST API at \<192.168.200.252:8999\>

Curl from graylog-server node to datanode port 8999 returns  
curl http ://elastick:8999  
root@graylog:/var/log/graylog-server# curl http ://elastick:8999  
{“operating\_system”:{“os\_name”:“Linux”,“os\_version”:“5.15.0-143-generic”,“java\_version”:“17.0.15”,“user\_name”:“graylog-datanode”},“opensearch”:{“opensearch\_version”:“2.15.0”,“node”:{“node\_name”:“elastick”,“state”:“WAITING\_FOR\_CONFIGURATION”,“rest\_base\_url”:“”,“process”:{“pid”:-1,“alive”:false,“started”:null}}},“datanode\_directories”:{“data\_target\_dir”:“file:///var/lib/graylog-datanode/opensearch/data/”,“logs\_target\_dir”:“file:///var/log/graylog-datanode/opensearch/”,“configuration\_source\_dir”:“file:///etc/graylog/datanode/”,“configuration\_target\_dir”:“file:///var/lib/graylog-datanode/opensearch/config/”},“dto”:{“status”:“UNCONFIGURED”,“error\_msg”:null,“cert\_valid\_until”:null,“data\_node\_status”:“UNCONFIGURED”,“cert\_valid\_until”:null,“cluster\_address”:“elastick:9300”,“rest\_api\_address”:“[http://elastick:8999](http://elastick:8999)”,“action\_queue”:null,“datanode\_version”:“6.3.1+7bd8532”,“opensearch\_roles”:,“configuration\_warnings”:,“version\_compatible”:true,“id”:“a1bd9815-d3ee-4b81-a156-c50312e4b001”,“is\_leader”:false,“node\_id”:“a1bd9815-d3ee-4b81-a156-c50312e4b001”,“short\_node\_id”:“a1bd9815”,“transport\_address”:“”,“hostname”:“elastick”,“last\_seen”:“2025-07-08T13:34:38.000Z”,“object\_id”:“686d19cd4e2a9face703102c”,“is\_master”:false},“data\_node\_version”:“6.3.1+7bd8532”}root@graylog:/var/log/graylog-server#

---

<div class="post-metadata">

**Author:** ![Tdvorak](https://avatars.discourse-cdn.com/v4/letter/t/a88e57/32.png) [@Tdvorak](https://community.graylog.org/u/Tdvorak)\
**Post date:** [July 9, 2025, 6:22am UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/2 "2025-07-09T06:22:30Z")

</div>

Hi @douglas_ns,  
If you don’t see any error messages, both services are running fine and the only symptom is that the datanode is not displayed in the preflight, then I’d suggest checking if both services are connected to the same mongodb server and the same database (=identical connection string).

The link between those two is always the mongodb, so if they happen to connect to different databases, they both think that they are alone in the cluster.

---

<div class="post-metadata">

**Author:** ![douglas\_ns](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@douglas\_ns](https://community.graylog.org/u/douglas_ns)\
**Post date:** [July 9, 2025, 11:13am UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/3 "2025-07-09T11:13:21Z")

</div>

Hi Tomas,  
Thanks for your quick reply!

Here is my environment:

```
VM1: Graylog Server + MongoDB
IP: 192.168.200.253

VM2: Graylog Datanode
IP: 192.168.200.252

```

Both firewalls are disabled.

The MongoDB connection string is correctly set on both /etc/graylog/datanode/datanode.conf and /etc/graylog/server/server.conf as:

mongodb\_uri = mongodb://192.168.200.253:27017/graylog

There are no errors in the logs on either machine.

When I run db.datanodes.find().pretty() in MongoDB, I get the following output:

[  
{  
\_id: ObjectId(‘686d7b554e2a9face705adcb’),  
node\_id: ‘a1bd9815-d3ee-4b81-a156-c50312e4b001’,  
datanode\_status: ‘UNCONFIGURED’,  
hostname: ‘elastick’,  
is\_leader: false,  
last\_seen: Timestamp({ t: 1752059203, i: 1 }),  
transport\_address: ‘’,  
cluster\_address: ‘elastick:9300’,  
configuration\_warnings: ,  
datanode\_version: ‘6.3.1+7bd8532’,  
opensearch\_roles: ,  
rest\_api\_address: ‘hxxp://elastick:8999’  
}  
]

The hostname elastick resolves correctly to 192.168.200.252 from the Graylog server, and graylog resolves to 192.168.200.253 from the Datanode:

root@graylog:~# ping elastick  
PING elastick (192.168.200.252) 56(84) bytes of data.  
64 bytes from elastick (192.168.200.252): icmp\_seq=1 ttl=64 time=9.29 ms  
64 bytes from elastick (192.168.200.252): icmp\_seq=2 ttl=64 time=10.2 ms

I even tried a fresh installation, removing both applications and the database, but the same issue happens again:  
The datanode does not appear in the preflight configuration screen, and there are still no errors in the logs.

Any ideas on what might be missing?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Tdvorak](https://avatars.discourse-cdn.com/v4/letter/t/a88e57/32.png) [@Tdvorak](https://community.graylog.org/u/Tdvorak)\
**Post date:** [July 10, 2025, 8:51am UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/4 "2025-07-10T08:51:33Z")

</div>

Thank you for debugging. This all seems correct and working fine. Let’s focus on your browser. Can you check if you have any errors in the browser console? Anything blocked by the browser? Does the /api/data\_nodes call return anything? Can you post a screenshot of the preflight page?

Thanks!

---

<div class="post-metadata">

**Author:** ![douglas\_ns](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@douglas\_ns](https://community.graylog.org/u/douglas_ns)\
**Post date:** [July 10, 2025, 11:28am UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/5 "2025-07-10T11:28:31Z")

</div>

Hi Tomas,

Thanks again!

I checked the browser console and there are **no errors or blocked requests** showing up.

Below are the screenshots of the **preflight page** as requested.

Let me know if there’s anything else I can check or provide.

Thanks!

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/7/9/790f188a8c94f70c9e747e81a9041dd3e713726f.png)  
curl -u admin:\*\*\*\*\* [http://graylog:9000/api/data\_nodes](http://graylog:9000/api/data_nodes)

Return:

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/a/9/a9bbe84781436e18d52f134981f32fb2f8e89e9d.png)

I have a feeling it might be something simple that I’m overlooking. 😅

Thanks!

---

<div class="post-metadata">

**Author:** ![Tdvorak](https://avatars.discourse-cdn.com/v4/letter/t/a88e57/32.png) [@Tdvorak](https://community.graylog.org/u/Tdvorak)\
**Post date:** [July 10, 2025, 12:11pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/6 "2025-07-10T12:11:22Z")

</div>

This is indeed strange 🙂

I’d double check both graylog and datanode logs. If there is nothing wrong, I’d try to run the same mongo query from the graylog server. We know that datanode can reach it and store its information there, we want to verify that the server can too.

You can check if the `cluster_config` collection contains an entry with `org.graylog2.bootstrap.preflight.PreflightEncryptedSecret` type. This one is created by the server. So if both are connected to the same DB, you’ll see an entry in the `datanode` collection and an the encrypted secret in the `cluster_config` collection.

You can also observe if the `last_seen` field of the datanode entry gets updated - if the datanode is running and pinging/updating the db.

Just to be sure - what mongodb version are you using?

---

<div class="post-metadata">

**Author:** ![Tdvorak](https://avatars.discourse-cdn.com/v4/letter/t/a88e57/32.png) [@Tdvorak](https://community.graylog.org/u/Tdvorak)\
**Post date:** [July 10, 2025, 12:21pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/7 "2025-07-10T12:21:24Z")

</div>

One more question - which version of the graylog server are you running, please?

---

<div class="post-metadata">

**Author:** ![douglas\_ns](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@douglas\_ns](https://community.graylog.org/u/douglas_ns)\
**Post date:** [July 10, 2025, 12:57pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/8 "2025-07-10T12:57:38Z")

</div>

mongodb version is 7.0.21

server.log

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/1/3/133f14abf4fafe8aee9290d0902bb78ccb1f30bb.png)  
datanode.log  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/8/9/895da64e149ba2f25c77bc269ceb984be38e6598.png)

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/3/4/346886bd76b5d0cf425d92c9557aa6ede9b7c0cd.png)

Hi Tomas,

Thanks again for your help!

I followed your suggestions and connected to MongoDB using mongosh from the Graylog Server. Here are the results:

✅ The cluster\_config collection contains the entry of type org.graylog2.bootstrap.preflight.PreflightEncryptedSecret, created by the server:

{  
type: “org.graylog2.bootstrap.preflight.PreflightEncryptedSecret”,  
last\_updated\_by: “a1bd9815-d3ee-4b81-a156-c50312e4b001”  
}

✅ The datanodes collection also contains the expected entry.  
The last\_seen field is being updated, indicating the datanode is alive and communicating with MongoDB.  
However, it seems that the last\_seen has not been updated for some time.

{  
node\_id: “a1bd9815-d3ee-4b81-a156-c50312e4b001”,  
datanode\_status: “UNCONFIGURED”,  
last\_seen: Timestamp({ t: 1752151703, i: 1 }), // corresponds to 2025-07-09 08:28:23 (GMT-3)  
hostname: “elastick”,  
rest\_api\_address: “[http://elastick:8999](http://elastick:8999)”  
}

So it appears that both the server and the datanode are connected to the same MongoDB database and are writing data correctly.

Please let me know if there is anything else I should check. Thanks again for your help!

---

<div class="post-metadata">

**Author:** ![Tdvorak](https://avatars.discourse-cdn.com/v4/letter/t/a88e57/32.png) [@Tdvorak](https://community.graylog.org/u/Tdvorak)\
**Post date:** [July 10, 2025, 1:38pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/9 "2025-07-10T13:38:19Z")

</div>

Thanks, I think we are getting close. The `last_seen` timestamp should be fairly recent - the datanode should update its data every second with a periodical task. If it’s really outdated, then maybe the task/datanode stopped running? Your logs in the screenshots show old timestamps too, is it just an old screenshot or are there really no new logs?

If the `last_seen` is that outdated, it will be considered invalid and ignored in the preflight, where we consider only recent entries.

I’d try to restart the datanode service and check if the `last_seen` is getting updated.

---

<div class="post-metadata">

**Author:** ![douglas\_ns](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@douglas\_ns](https://community.graylog.org/u/douglas_ns)\
**Post date:** [July 10, 2025, 1:46pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/10 "2025-07-10T13:46:30Z")

</div>

Hi Tomas,

I restarted the Datanode as suggested, and checked the `last_seen` field again.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/f/3/f3be967fd548c7f6d020084c05f5223395754579.png)

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/0/c03f5f168bf6b62c2f91b456cc86d1fb7422a39d.png)

---

<div class="post-metadata">

**Author:** ![Tdvorak](https://avatars.discourse-cdn.com/v4/letter/t/a88e57/32.png) [@Tdvorak](https://community.graylog.org/u/Tdvorak)\
**Post date:** [July 10, 2025, 1:52pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/11 "2025-07-10T13:52:10Z")

</div>

Ok, that looks good, the periodical is running, the timestamp is getting updated, logs are having recent timestamp as well. Does it help? Do you see the datanode in the preflight now?

---

<div class="post-metadata">

**Author:** ![douglas\_ns](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@douglas\_ns](https://community.graylog.org/u/douglas_ns)\
**Post date:** [July 10, 2025, 2:03pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/12 "2025-07-10T14:03:13Z")

</div>

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/2/1/219e7eedf5adf15671c771a1e2840b3dd1ab58ab.png)  
Hi Tomas,

Thanks for the follow-up!

The `last_seen` timestamp is indeed updating now, and the logs are showing recent entries — so the periodic task seems to be working properly.

**However, the datanode still does not appear in the preflight UI.**

At this point, I’m considering reinstalling both VMs from scratch with a different operating system, just to rule out any OS-level issue or misconfiguration.

Before I go down that path — is there anything else we can try or verify?

Thanks again for your continued support!

---

<div class="post-metadata">

**Author:** ![Tdvorak](https://avatars.discourse-cdn.com/v4/letter/t/a88e57/32.png) [@Tdvorak](https://community.graylog.org/u/Tdvorak)\
**Post date:** [July 10, 2025, 2:27pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/13 "2025-07-10T14:27:43Z")

</div>

One more question - based on the look of the logo in the preflight setup, it seems that you are running an older version of the server. Can you please verify that your graylog server is also 6.3 version?

---

<div class="post-metadata">

**Author:** ![douglas\_ns](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@douglas\_ns](https://community.graylog.org/u/douglas_ns)\
**Post date:** [July 10, 2025, 2:39pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/14 "2025-07-10T14:39:29Z")

</div>

Hi Tomas,

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/3/1/3127311353197c44930cc23ee63e3810557d8921.png)

Strangely, the Graylog Server version installed is **5.2.12** ☹

I followed this guide for the installation:

> **[Ubuntu Installation: Single Graylog Node](https://go2docs.graylog.org/current/downloading_and_installing_graylog/ubuntu_installation.htm)**
>
> Install Graylog on Ubuntu with a single-node setup. This comprehensive guide covers the installation of Graylog, MongoDB, and Data Node, with expert tips for configuration and troubleshooting.

I apologize for not noticing this earlier. Anyway, you have identified the problem, and I’m grateful for your attention and help.

---

<div class="post-metadata">

**Author:** ![Tdvorak](https://avatars.discourse-cdn.com/v4/letter/t/a88e57/32.png) [@Tdvorak](https://community.graylog.org/u/Tdvorak)\
**Post date:** [July 10, 2025, 2:49pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/15 "2025-07-10T14:49:18Z")

</div>

Good to hear that we found the problem!

One of my QA colleagues, @vadym.vasylenko, noticed the old logo and asked about the sever version. Thanks Vadym!

With the latest 6.3 version, does your datanode appear in the preflight, as it should?

---

<div class="post-metadata">

**Author:** ![douglas\_ns](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@douglas\_ns](https://community.graylog.org/u/douglas_ns)\
**Post date:** [July 10, 2025, 3:42pm UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/16 "2025-07-10T15:42:43Z")

</div>

Yes, after installing version 6.3, everything is working perfectly — the datanode now shows up in the preflight just as expected.

Huge thanks to you, Tomas, and @vadym.vasylenko for your time, patience, and for spotting the version mismatch.

Apologies for the confusion — I’m honestly a bit embarrassed 😅  
But I truly learned a lot from this experience. Thank you again!

---

<div class="post-metadata">

**Author:** ![Tdvorak](https://avatars.discourse-cdn.com/v4/letter/t/a88e57/32.png) [@Tdvorak](https://community.graylog.org/u/Tdvorak)\
**Post date:** [July 11, 2025, 6:26am UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/17 "2025-07-11T06:26:30Z")

</div>

Thank you for the confirmation @douglas_ns! No need to be embarrassed, it was a tricky situation. We are also learning from your experience, so thank you too!

Best regards,  
Tomas

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 25, 2025, 6:27am UTC](https://community.graylog.org/t/data-node-not-showing-up-in-graylog-6-3-preflight-configuration/35965/18 "2025-07-25T06:27:07Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
