[Graylog_2.3.2] No result in search


(alias) #1

Hi,

I have green state (curl _cluster/health, curl _cat/indices?v, system overview) on the graylog multi node setup.

I have 10 hosts which send his logging activity (SSH) to a TCP Syslog Input.
I see it on the right top page (In/out eps) but when I search it, no result.

2 methods:

  • With the classic research request;
  • With the Input search button (with gl2_source_input:ID).

When I force the new event, I check with curl _cat/indices?v, I see the docs.count up (example: 3639, generate SSH event on one host, 3650 after.)

Someone have an idea ?

Thanks


#2

one possibility is that the timestamp value is interpreted wrongly and the messages are not in your search interval; you could try to search in all messages. The syslog input can be picky; you might need to make a raw input to parse the timestamps yourself.


(alias) #3

Hi @jtkarvo

I’ve also try to search with the input search button which use all message parameter, and I’ve not message.


(alias) #4

Hi

I’ve updated the greaylog cluster into 2.4 version to try if it resolv the search bug.

The master node have an error LookupDataAdapter : Couldn't start data adapter abuse-ch-ransomware-domains and the slaves nodes have NodePingThred Did not find meta info of this node. Re-registering.


(Jan Doberstein) #5

@alias

two different issue.

The second one - did you check if the time is the same on all nodes?

The first - the data adapter is part of the thread intel plugin. If you do not need that, you can ignore it.


(alias) #6

hi @jan

I check it and it’s OK, and I resync all nodes with the ntp server.

Ok for the thread intel. It try to access to internet ? I’m in a DMZ.


(alias) #7

The master node have an error LookupDataAdapter : Couldn’t start data adapter abuse-ch-ransomware-domains and the slaves nodes have NodePingThred Did not find meta info of this node. Re-registering.

This errors are resolved.

I send logs on the second node.

Now, if I search events into WebUI Node 01 (master) or slaves, I’ve no results.

In tcpdump or top right WebUI, I see incoming logs.

Someone have an idea ? :frowning:


(alias) #8

I recalculate index ranges, and it’s OK.

Thanks


(system) #9

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.