# Graylog 2.3 new

**URL:** <https://community.graylog.org/t/graylog-2-3-new/2052>\
**Category:** Graylog Central (peer support)\
**Created:** [August 10, 2017, 1:19pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052 "2017-08-10T13:19:51Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![shachbo](https://avatars.discourse-cdn.com/v4/letter/s/a88e57/32.png) [@shachbo](https://community.graylog.org/u/shachbo)\
**Post date:** [August 10, 2017, 1:19pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052/1 "2017-08-10T13:19:51Z")

</div>

i installed the new graylog version 2.3 and configured it but it doesnt show messages from my older elasticksearch node.  
i have another graylog server node 2.2.3 witch can read data from the same ES node. any ideas?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [August 10, 2017, 1:23pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052/2 "2017-08-10T13:23:15Z")

</div>

What’s the configuration of your Graylog and Elasticsearch nodes?  
What’s in the logs of your Graylog and Elasticsearch nodes?

---

<div class="post-metadata">

**Author:** ![shachbo](https://avatars.discourse-cdn.com/v4/letter/s/a88e57/32.png) [@shachbo](https://community.graylog.org/u/shachbo)\
**Post date:** [August 10, 2017, 1:40pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052/3 "2017-08-10T13:40:21Z")

</div>

server conf is this (i see its new for this version)  
elasticsearch\_hosts = [http://172.25.231.43:9200](http://172.25.231.43:9200)  
elasticsearch\_discovery\_enabled = true

ES conf is this  
discovery.zen.ping.unicast.hosts: [“172.25.231.30:9300”,“172.25.231.31:9300”]  
network.host: 172.25.231.43

172.25.231.30:9300 can see the log  
172.25.231.31:9300 can not see the logs

no errors

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [August 10, 2017, 1:43pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052/4 "2017-08-10T13:43:10Z")

</div>

Is `http://172.25.231.43:9200` the address of the Elasticsearch HTTP API of an Elasticsearch node?  
Do the Elasticsearch nodes advertise the correct addresses in the Elasticsearch cluster state?

---

<div class="post-metadata">

**Author:** ![shachbo](https://avatars.discourse-cdn.com/v4/letter/s/a88e57/32.png) [@shachbo](https://community.graylog.org/u/shachbo)\
**Post date:** [August 10, 2017, 2:04pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052/5 "2017-08-10T14:04:05Z")

</div>

[http://172.25.231.43:9200](http://172.25.231.43:9200) is correct

---

<div class="post-metadata">

**Author:** ![shachbo](https://avatars.discourse-cdn.com/v4/letter/s/a88e57/32.png) [@shachbo](https://community.graylog.org/u/shachbo)\
**Post date:** [August 10, 2017, 2:32pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052/6 "2017-08-10T14:32:06Z")

</div>

in the working server node i can see the logs belongs to the new server (internal logs) witch means that the new server can send the logs to ES but cant read them.  
why?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [August 10, 2017, 4:36pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052/7 "2017-08-10T16:36:18Z")

</div>

> [@shachbo](#):
>
> 172.25.231.30:9300 can see the log
> 
> 172.25.231.31:9300 can not see the logs

What does this mean exactly?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [August 10, 2017, 4:37pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052/8 "2017-08-10T16:37:14Z")

</div>

Please post the _complete_ configuration and logs of _all_ Graylog and Elasticsearch nodes.

---

<div class="post-metadata">

**Author:** ![shachbo](https://avatars.discourse-cdn.com/v4/letter/s/a88e57/32.png) [@shachbo](https://community.graylog.org/u/shachbo)\
**Post date:** [August 13, 2017, 7:02am UTC](https://community.graylog.org/t/graylog-2-3-new/2052/9 "2017-08-13T07:02:11Z")

</div>

## graylog conf (new version)

is\_master = true

node\_id\_file = /var/opt/graylog/graylog-server-node-id

password\_secret = 3094e356cc0f26de799229b56c75192eef3bf6e1d85788c1878d6f3b6c0c5b74c1898b4a2f296e93f36d455ff2cfa7458fc230f3dfbe744cfe474755d45585fa

root\_username = admin

root\_password\_sha2 = 8c6976e5b5410415bde908bd4dee15dfb167a9c873fc4bb8a81f6f2ab448a918

root\_timezone = Etc/UTC

plugin\_dir = /opt/graylog/plugin

rest\_listen\_uri = [http://0.0.0.0:9000/api](http://0.0.0.0:9000/api)

web\_listen\_uri = [http://0.0.0.0:9000/](http://0.0.0.0:9000/)

rest\_enable\_cors = true

elasticsearch\_shards = 4  
elasticsearch\_replicas = 1

elasticsearch\_index\_prefix = graylog  
allow\_leading\_wildcard\_searches = true

allow\_highlighting = true

elasticsearch\_hosts = [http://172.25.232.43:9200](http://172.25.232.43:9200)

elasticsearch\_max\_total\_connections = 20

elasticsearch\_max\_total\_connections\_per\_route = 2

elasticsearch\_discovery\_enabled = true

elasticsearch\_analyzer = standard

output\_batch\_size = 500

output\_flush\_interval = 1

output\_fault\_count\_threshold = 5  
output\_fault\_penalty\_seconds = 30

processbuffer\_processors = 5  
outputbuffer\_processors = 3

processor\_wait\_strategy = blocking

ring\_size = 65536

inputbuffer\_ring\_size = 65536  
inputbuffer\_processors = 2  
inputbuffer\_wait\_strategy = blocking

message\_journal\_enabled = true

message\_journal\_dir = /var/opt/graylog/data/journal

message\_journal\_max\_size = 1gb

async\_eventbus\_processors = 2

lb\_recognition\_period\_seconds = 3

alert\_check\_interval = 60

mongodb\_uri = mongodb://172.25.231.31:27017/graylog

mongodb\_max\_connections = 100

mongodb\_threads\_allowed\_to\_block\_multiplier = 5

transport\_email\_enabled = false  
transport\_email\_hostname =  
transport\_email\_port = 587  
transport\_email\_use\_auth = false  
transport\_email\_use\_tls = true  
transport\_email\_use\_ssl = true  
transport\_email\_auth\_username =  
transport\_email\_auth\_password =  
transport\_email\_subject\_prefix = [graylog]  
transport\_email\_from\_email =

transport\_email\_web\_interface\_url =

dashboard\_widget\_default\_cache\_time = 10s

content\_packs\_loader\_enabled = true

content\_packs\_dir = /opt/graylog/contentpacks

content\_packs\_auto\_load = grok-patterns.json,content\_pack\_appliance.json

## ES conf

[cluster.name](http://cluster.name): graylog

[node.name](http://node.name): “Franz Kafka”

index.number\_of\_shards: 1

index.number\_of\_replicas: 0

path.data: /var/opt/graylog/data/elasticsearch

path.logs: /var/log/graylog/elasticsearch/

network.host: 172.25.232.43

discovery.zen.ping.timeout: 10s

discovery.zen.ping.multicast.enabled: false  
discovery.zen.ping.unicast.hosts: [“172.25.232.31:9300”]

---

<div class="post-metadata">

**Author:** ![shachbo](https://avatars.discourse-cdn.com/v4/letter/s/a88e57/32.png) [@shachbo](https://community.graylog.org/u/shachbo)\
**Post date:** [August 14, 2017, 8:10am UTC](https://community.graylog.org/t/graylog-2-3-new/2052/10 "2017-08-14T08:10:29Z")

</div>

problem solved.  
i reconfigured graylog 2.3 as a backend. and compared the .yml files to my old data node and found that  
this parameter “discovery.zen.ping\_timeout: 10s” in the new version is different then the old version  
"discovery.zen.ping.timeout: 10s"  
after changing it i can finally see all the logs using the new graylog sever.

thanks for the help and support

---

<div class="post-metadata">

**Author:** ![shachbo](https://avatars.discourse-cdn.com/v4/letter/s/a88e57/32.png) [@shachbo](https://community.graylog.org/u/shachbo)\
**Post date:** [August 14, 2017, 8:12am UTC](https://community.graylog.org/t/graylog-2-3-new/2052/11 "2017-08-14T08:12:49Z")

</div>

oops  
it didnt solve the problem.  
so i am steel stuck.

---

<div class="post-metadata">

**Author:** ![noudAndi](https://avatars.discourse-cdn.com/v4/letter/n/f05b48/32.png) [@noudAndi](https://community.graylog.org/u/noudAndi)\
**Post date:** [August 15, 2017, 12:10pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052/12 "2017-08-15T12:10:36Z")

</div>

> [@shachbo](#):
>
> /var/opt/graylog/data/elasticsearch

What is the contents of your elasticsearch data folder (/var/opt/graylog/data/elasticsearch) ?

On my docker-installation, the data folder was like:

./node ← new  
./graylog/node ← old

So the data is put into node instead of graylog/node. So I stopped elastic, moved the folder and started again. This worked for me.

---

<div class="post-metadata">

**Author:** ![li555li](https://avatars.discourse-cdn.com/v4/letter/l/e9bcb4/32.png) [@li555li](https://community.graylog.org/u/li555li)\
**Post date:** [August 15, 2017, 9:29pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052/13 "2017-08-15T21:29:39Z")

</div>

I ran into the same problem. It was caused by me forgetting to set “elasticsearch\_hosts” in graylog 2.3 configuration. The old “elasticsearch\_discovery\_zen\_ping\_unicast\_hosts” parameter is no longer working as Graylog 2.3 switches to Elasticsearch HTTP client. Once I got that set correctly, my 2.3 node can “see” the old indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 29, 2017, 9:40pm UTC](https://community.graylog.org/t/graylog-2-3-new/2052/14 "2017-08-29T21:40:16Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
