[Graylog_2.3.2] No result in search

Hi,

I have green state (curl _cluster/health, curl _cat/indices?v, system overview) on the graylog multi node setup.

I have 10 hosts which send his logging activity (SSH) to a TCP Syslog Input.
I see it on the right top page (In/out eps) but when I search it, no result.

2 methods:

  • With the classic research request;
  • With the Input search button (with gl2_source_input:ID).

When I force the new event, I check with curl _cat/indices?v, I see the docs.count up (example: 3639, generate SSH event on one host, 3650 after.)

Someone have an idea ?

Thanks

one possibility is that the timestamp value is interpreted wrongly and the messages are not in your search interval; you could try to search in all messages. The syslog input can be picky; you might need to make a raw input to parse the timestamps yourself.

Hi @jtkarvo

I’ve also try to search with the input search button which use all message parameter, and I’ve not message.

Hi

I’ve updated the greaylog cluster into 2.4 version to try if it resolv the search bug.

The master node have an error LookupDataAdapter : Couldn't start data adapter abuse-ch-ransomware-domains and the slaves nodes have NodePingThred Did not find meta info of this node. Re-registering.

@alias

two different issue.

The second one - did you check if the time is the same on all nodes?

The first - the data adapter is part of the thread intel plugin. If you do not need that, you can ignore it.

hi @jan

I check it and it’s OK, and I resync all nodes with the ntp server.

Ok for the thread intel. It try to access to internet ? I’m in a DMZ.

The master node have an error LookupDataAdapter : Couldn’t start data adapter abuse-ch-ransomware-domains and the slaves nodes have NodePingThred Did not find meta info of this node. Re-registering.

This errors are resolved.

I send logs on the second node.

Now, if I search events into WebUI Node 01 (master) or slaves, I’ve no results.

In tcpdump or top right WebUI, I see incoming logs.

Someone have an idea ? :frowning:

I recalculate index ranges, and it’s OK.

Thanks

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.