@makarands
Here is graylog-server log “server.log”
2021-01-05T08:46:58.404+01:00 INFO [ServerBootstrap] Graylog server up and running.
2021-01-05T08:46:58.487+01:00 INFO [InputStateListener] Input [Syslog UDP/5fb24ff9c4713e500e05fb40] is now STARTING
2021-01-05T08:46:58.491+01:00 INFO [InputStateListener] Input [Beats/5fb25db31b25d227a81a9b8c] is now STARTING
2021-01-05T08:46:58.492+01:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/5fb25dd51b25d227a81a9c40] is now STARTING
2021-01-05T08:46:58.493+01:00 INFO [InputStateListener] Input [Syslog TCP/5fb25041c4713e500e05fbae] is now STARTING
2021-01-05T08:46:58.493+01:00 INFO [InputStateListener] Input [Syslog UDP/5fb25de71b25d227a81a9ce7] is now STARTING
2021-01-05T08:46:58.494+01:00 INFO [InputStateListener] Input [Syslog UDP/5fb25de71b25d227a81a9d01] is now STARTING
2021-01-05T08:46:58.495+01:00 INFO [InputStateListener] Input [Beats/5fb278a7ddeeb038f1e76f7d] is now STARTING
2021-01-05T08:46:58.495+01:00 INFO [InputStateListener] Input [Syslog TCP/5fc76ce7ab03c4279ef1d1a2] is now STARTING
2021-01-05T08:46:58.501+01:00 INFO [InputStateListener] Input [GELF UDP/5fb25daf1b25d227a81a9b37] is now STARTING
2021-01-05T08:46:58.670+01:00 INFO [InputStateListener] Input [Beats/5fb25db31b25d227a81a9b8c] is now RUNNING
2021-01-05T08:46:58.680+01:00 WARN [AbstractTcpTransport] receiveBufferSize (SO_RCVBUF) for input Beats2Input{title=TCP_WinDNS_1555, type=org.graylog.plugins.beats.Beats2Input, nodeId=null} (channel [id: 0x579b4a95, L:/0:0:0:0:0:0:0:0%0:1555]) should be 1048576 but is 425984.
2021-01-05T08:46:58.681+01:00 WARN [AbstractTcpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogTCPInput{title=Syslog_TCP, type=org.graylog2.inputs.syslog.tcp.SyslogTCPInput, nodeId=54672bc0-337c-4ffc-92ba-fa8419a91009} (channel [id: 0x60017a13, L:/0:0:0:0:0:0:0:0%0:1514]) should be 1048576 but is 425984.
2021-01-05T08:46:58.682+01:00 WARN [AbstractTcpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogTCPInput{title=Vmware_Syslog_TCP, type=org.graylog2.inputs.syslog.tcp.SyslogTCPInput, nodeId=54672bc0-337c-4ffc-92ba-fa8419a91009} (channel [id: 0x0dbae9b9, L:/0:0:0:0:0:0:0:0%0:2514]) should be 1048576 but is 425984.
2021-01-05T08:46:58.682+01:00 INFO [InputStateListener] Input [Beats/5fb278a7ddeeb038f1e76f7d] is now RUNNING
2021-01-05T08:46:58.684+01:00 INFO [InputStateListener] Input [Syslog TCP/5fc76ce7ab03c4279ef1d1a2] is now RUNNING
2021-01-05T08:46:58.686+01:00 WARN [AbstractTcpTransport] receiveBufferSize (SO_RCVBUF) for input Beats2Input{title=BEATS, type=org.graylog.plugins.beats.Beats2Input, nodeId=54672bc0-337c-4ffc-92ba-fa8419a91009} (channel [id: 0x50cceb26, L:/0:0:0:0:0:0:0:0%0:5044]) should be 1048576 but is 425984.
2021-01-05T08:46:58.686+01:00 INFO [InputStateListener] Input [Syslog TCP/5fb25041c4713e500e05fbae] is now RUNNING
2021-01-05T08:46:58.694+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=FortiGate, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=54672bc0-337c-4ffc-92ba-fa8419a91009} (channel [id: 0x55b13d26, L:/0:0:0:0:0:0:0:0%0:15514]) should be 262144 but is 425984.
2021-01-05T08:46:58.695+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog_UDP, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=54672bc0-337c-4ffc-92ba-fa8419a91009} (channel [id: 0xcf26fe81, L:/0:0:0:0:0:0:0:0%0:1514]) should be 1048576 but is 425984.
2021-01-05T08:46:58.697+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x36bc3656, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.697+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=nginx access log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x6de63b49, L:/0:0:0:0:0:0:0:0%0:12304]) should be 1048576 but is 425984.
2021-01-05T08:46:58.715+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=nginx error log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x7aa76e86, L:/0:0:0:0:0:0:0:0%0:12305]) should be 1048576 but is 425984.
2021-01-05T08:46:58.744+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x30da754b, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.747+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=nginx error log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xb116461c, L:/0:0:0:0:0:0:0:0%0:12305]) should be 1048576 but is 425984.
2021-01-05T08:46:58.748+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=FortiGate, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=54672bc0-337c-4ffc-92ba-fa8419a91009} (channel [id: 0xaf62b608, L:/0:0:0:0:0:0:0:0%0:15514]) should be 262144 but is 425984.
2021-01-05T08:46:58.754+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog_UDP, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=54672bc0-337c-4ffc-92ba-fa8419a91009} (channel [id: 0x38252d07, L:/0:0:0:0:0:0:0:0%0:1514]) should be 1048576 but is 425984.
2021-01-05T08:46:58.744+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=nginx access log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xd5833f4c, L:/0:0:0:0:0:0:0:0%0:12304]) should be 1048576 but is 425984.
2021-01-05T08:46:58.757+01:00 INFO [InputStateListener] Input [Syslog UDP/5fb24ff9c4713e500e05fb40] is now RUNNING
2021-01-05T08:46:58.798+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x662ac9f4, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.798+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=FortiGate, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=54672bc0-337c-4ffc-92ba-fa8419a91009} (channel [id: 0xe28a423c, L:/0:0:0:0:0:0:0:0%0:15514]) should be 262144 but is 425984.
2021-01-05T08:46:58.803+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=nginx error log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x3e543db0, L:/0:0:0:0:0:0:0:0%0:12305]) should be 1048576 but is 425984.
2021-01-05T08:46:58.804+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=nginx access log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xc706df56, L:/0:0:0:0:0:0:0:0%0:12304]) should be 1048576 but is 425984.
2021-01-05T08:46:58.806+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=FortiGate, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=54672bc0-337c-4ffc-92ba-fa8419a91009} (channel [id: 0xcf92329a, L:/0:0:0:0:0:0:0:0%0:15514]) should be 262144 but is 425984.
2021-01-05T08:46:58.808+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=nginx access log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xbbd576eb, L:/0:0:0:0:0:0:0:0%0:12304]) should be 1048576 but is 425984.
2021-01-05T08:46:58.807+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0xa4e0542d, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.809+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=nginx error log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x6150967d, L:/0:0:0:0:0:0:0:0%0:12305]) should be 1048576 but is 425984.
2021-01-05T08:46:58.813+01:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/5fb25dd51b25d227a81a9c40] is now RUNNING
2021-01-05T08:46:58.813+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0xcd492521, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.815+01:00 INFO [InputStateListener] Input [Syslog UDP/5fb25de71b25d227a81a9d01] is now RUNNING
2021-01-05T08:46:58.823+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0xd271ddd7, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.825+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x1c585c26, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.827+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x7f96ebe1, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.828+01:00 INFO [InputStateListener] Input [Syslog UDP/5fb25de71b25d227a81a9ce7] is now RUNNING
2021-01-05T08:46:58.832+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0xa21cc579, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.834+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x3e6ce961, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.835+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0xd884074c, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.838+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x2b3ef8eb, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.839+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x2ea29815, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.840+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0xab2b1d94, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.854+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x51ff4d07, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.857+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x4ee51b17, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.858+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0xa1a3f798, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.865+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0xf47dcd6f, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.867+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x3a0d45ee, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.869+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x9d807707, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.870+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0xcdd1c87d, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.875+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0xf244f4ea, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.878+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0x1795c011, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.880+01:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=nginx logs, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} (channel [id: 0xefa409c8, L:/0:0:0:0:0:0:0:0%0:12401]) should be 1048576 but is 425984.
2021-01-05T08:46:58.882+01:00 INFO [InputStateListener] Input [GELF UDP/5fb25daf1b25d227a81a9b37] is now RUNNING
2021-01-05T08:49:29.237+01:00 INFO [connection] Opened connection [connectionId{localValue:8, serverValue:11}] to localhost:27017
2021-01-05T08:49:29.257+01:00 INFO [connection] Opened connection [connectionId{localValue:9, serverValue:12}] to localhost:27017
2021-01-05T08:49:29.269+01:00 INFO [connection] Opened connection [connectionId{localValue:10, serverValue:13}] to localhost:27017
2021-01-06T08:46:32.740+01:00 ERROR [FileInfo] Couldn’t get file info for path: /usr/local/etc/graylog/GeoLite2-City.mmdb
java.nio.file.NoSuchFileException: /usr/local/etc/graylog/GeoLite2-City.mmdb
at sun.nio.fs.UnixException.translateToIOException(UnixException.java:86) ~[?:1.8.0_275]
at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:102) ~[?:1.8.0_275]
at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:107) ~[?:1.8.0_275]
at sun.nio.fs.UnixFileAttributeViews$Basic.readAttributes(UnixFileAttributeViews.java:55) ~[?:1.8.0_275]
at sun.nio.fs.UnixFileSystemProvider.readAttributes(UnixFileSystemProvider.java:144) ~[?:1.8.0_275]
at sun.nio.fs.LinuxFileSystemProvider.readAttributes(LinuxFileSystemProvider.java:99) ~[?:1.8.0_275]
at java.nio.file.Files.readAttributes(Files.java:1737) ~[?:1.8.0_275]
at org.graylog2.plugin.utilities.FileInfo.forPath(FileInfo.java:76) ~[graylog.jar:?]
at org.graylog2.plugin.utilities.FileInfo.checkForChange(FileInfo.java:96) ~[graylog.jar:?]
at org.graylog.plugins.map.geoip.MaxmindDataAdapter.doRefresh(MaxmindDataAdapter.java:123) ~[graylog.jar:?]
at org.graylog2.plugin.lookup.LookupDataAdapter.refresh(LookupDataAdapter.java:109) ~[graylog.jar:?]
at org.graylog2.lookup.LookupDataAdapterRefreshService.lambda$schedule$0(LookupDataAdapterRefreshService.java:142) ~[graylog.jar:?]
at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511) [?:1.8.0_275]
at java.util.concurrent.FutureTask.runAndReset(FutureTask.java:308) [?:1.8.0_275]
at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.access$301(ScheduledThreadPoolExecutor.java:180) [?:1.8.0_275]
at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(ScheduledThreadPoolExecutor.java:294) [?:1.8.0_275]
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) [?:1.8.0_275]
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) [?:1.8.0_275]
at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
2021-01-06T08:46:32.747+01:00 WARN [MaxmindDataAdapter] Unable to load changed database file, leaving old one intact. Error message: /usr/local/etc/graylog/GeoLite2-City.mmdb (No such file or directory)
elastic log “graylog.log”
[2021-01-05T08:46:12,953][INFO ][o.e.n.Node ] [log01.kb.se] JVM arguments [-Xshare:auto, -Des.networkaddress.cache.ttl=60, -Des.networkaddress.cache.negative.ttl=10, -XX:+AlwaysPreTouch, -Xss1m, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djna.nosys=true, -XX:-OmitStackTraceInFastThrow, -XX:+ShowCodeDetailsInExceptionMessages, -Dio.netty.noUnsafe=true, -Dio.netty.noKeySetOptimization=true, -Dio.netty.recycler.maxCapacityPerThread=0, -Dio.netty.allocator.numDirectArenas=0, -Dlog4j.shutdownHookEnabled=false, -Dlog4j2.disable.jmx=true, -Djava.locale.providers=SPI,COMPAT, -Xms8g, -Xmx8g, -XX:+UseG1GC, -XX:G1ReservePercent=25, -XX:InitiatingHeapOccupancyPercent=30, -Djava.io.tmpdir=/tmp/elasticsearch-923087555446056225, -XX:+HeapDumpOnOutOfMemoryError, -XX:HeapDumpPath=/var/lib/elasticsearch, -XX:ErrorFile=/var/log/elasticsearch/hs_err_pid%p.log, -Xlog:gc*,gc+age=trace,safepoint:file=/var/log/elasticsearch/gc.log:utctime,pid,tags:filecount=32,filesize=64m, -XX:MaxDirectMemorySize=4294967296, -Des.path.home=/usr/share/elasticsearch, -Des.path.conf=/etc/elasticsearch, -Des.distribution.flavor=oss, -Des.distribution.type=rpm, -Des.bundled_jdk=true]
[2021-01-05T08:46:14,934][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [aggs-matrix-stats]
[2021-01-05T08:46:14,935][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [analysis-common]
[2021-01-05T08:46:14,935][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [geo]
[2021-01-05T08:46:14,935][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [ingest-common]
[2021-01-05T08:46:14,935][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [ingest-geoip]
[2021-01-05T08:46:14,935][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [ingest-user-agent]
[2021-01-05T08:46:14,936][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [kibana]
[2021-01-05T08:46:14,936][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [lang-expression]
[2021-01-05T08:46:14,936][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [lang-mustache]
[2021-01-05T08:46:14,936][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [lang-painless]
[2021-01-05T08:46:14,936][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [mapper-extras]
[2021-01-05T08:46:14,936][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [parent-join]
[2021-01-05T08:46:14,937][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [percolator]
[2021-01-05T08:46:14,937][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [rank-eval]
[2021-01-05T08:46:14,937][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [reindex]
[2021-01-05T08:46:14,937][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [repository-url]
[2021-01-05T08:46:14,937][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [systemd]
[2021-01-05T08:46:14,937][INFO ][o.e.p.PluginsService ] [log01.kb.se] loaded module [transport-netty4]
[2021-01-05T08:46:14,938][INFO ][o.e.p.PluginsService ] [log01.kb.se] no plugins loaded
[2021-01-05T08:46:14,979][INFO ][o.e.e.NodeEnvironment ] [log01.kb.se] using [1] data paths, mounts [[/ (/dev/mapper/rhel_log01-root)]], net usable_space [461.9gb], net total_space [492.2gb], types [xfs]
[2021-01-05T08:46:14,979][INFO ][o.e.e.NodeEnvironment ] [log01.kb.se] heap size [8gb], compressed ordinary object pointers [true]
[2021-01-05T08:46:15,194][INFO ][o.e.n.Node ] [log01.kb.se] node name [log01.kb.se], node ID [1wwiVxGkRD-l0E0gwYrNhw], cluster name [graylog], roles [master, remote_cluster_client, data, ingest]
[2021-01-05T08:46:18,128][INFO ][o.e.t.NettyAllocator ] [log01.kb.se] creating NettyAllocator with the following configs: [name=elasticsearch_configured, chunk_size=1mb, suggested_max_allocation_size=1mb, factors={es.unsafe.use_netty_default_chunk_and_page_size=false, g1gc_enabled=true, g1gc_region_size=4mb}]
[2021-01-05T08:46:18,188][INFO ][o.e.d.DiscoveryModule ] [log01.kb.se] using discovery type [zen] and seed hosts providers [settings]
[2021-01-05T08:46:18,419][WARN ][o.e.g.DanglingIndicesState] [log01.kb.se] gateway.auto_import_dangling_indices is disabled, dangling indices will not be automatically detected or imported and must be managed manually
[2021-01-05T08:46:18,565][INFO ][o.e.n.Node ] [log01.kb.se] initialized
[2021-01-05T08:46:18,565][INFO ][o.e.n.Node ] [log01.kb.se] starting …
[2021-01-05T08:46:18,669][INFO ][o.e.t.TransportService ] [log01.kb.se] publish_address {127.0.0.1:9300}, bound_addresses {[::1]:9300}, {127.0.0.1:9300}
[2021-01-05T08:46:18,889][INFO ][o.e.c.c.Coordinator ] [log01.kb.se] cluster UUID [D_XeMfbpT5KKq7h2vxZcUg]
[2021-01-05T08:46:19,011][INFO ][o.e.c.s.MasterService ] [log01.kb.se] elected-as-master ([1] nodes joined)[{log01.kb.se}{1wwiVxGkRD-l0E0gwYrNhw}{uyP69rb1Tnqb3FMuELARpw}{127.0.0.1}{127.0.0.1:9300}{dimr} elect leader, BECOME_MASTER_TASK, FINISH_ELECTION], term: 36, version: 659, delta: master node changed {previous , current [{log01.kb.se}{1wwiVxGkRD-l0E0gwYrNhw}{uyP69rb1Tnqb3FMuELARpw}{127.0.0.1}{127.0.0.1:9300}{dimr}]}
[2021-01-05T08:46:19,099][INFO ][o.e.c.s.ClusterApplierService] [log01.kb.se] master node changed {previous , current [{log01.kb.se}{1wwiVxGkRD-l0E0gwYrNhw}{uyP69rb1Tnqb3FMuELARpw}{127.0.0.1}{127.0.0.1:9300}{dimr}]}, term: 36, version: 659, reason: Publication{term=36, version=659}
[2021-01-05T08:46:19,124][INFO ][o.e.h.AbstractHttpServerTransport] [log01.kb.se] publish_address {127.0.0.1:9200}, bound_addresses {[::1]:9200}, {127.0.0.1:9200}
[2021-01-05T08:46:19,125][INFO ][o.e.n.Node ] [log01.kb.se] started
[2021-01-05T08:46:19,453][INFO ][o.e.g.GatewayService ] [log01.kb.se] recovered [7] indices into cluster_state
[2021-01-05T08:46:21,646][INFO ][o.e.c.r.a.AllocationService] [log01.kb.se] Cluster health status changed from [RED] to [GREEN] (reason: [shards started [[graylog_0][0]]]).
elastic graylog_server.json
{“type”: “server”, “timestamp”: “2021-01-05T08:46:12,944+01:00”, “level”: “INFO”, “component”: “o.e.n.Node”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “version[7.10.1], pid[1689], build[oss/rpm/1c34507e66d7db1211f66f3513706fdf548736aa/2020-12-05T01:00:33.671820Z], OS[Linux/4.18.0-240.8.1.el8_3.x86_64/amd64], JVM[AdoptOpenJDK/OpenJDK 64-Bit Server VM/15.0.1/15.0.1+9]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:12,952+01:00”, “level”: “INFO”, “component”: “o.e.n.Node”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “JVM home [/usr/share/elasticsearch/jdk], using bundled JDK [true]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:12,953+01:00”, “level”: “INFO”, “component”: “o.e.n.Node”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “JVM arguments [-Xshare:auto, -Des.networkaddress.cache.ttl=60, -Des.networkaddress.cache.negative.ttl=10, -XX:+AlwaysPreTouch, -Xss1m, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djna.nosys=true, -XX:-OmitStackTraceInFastThrow, -XX:+ShowCodeDetailsInExceptionMessages, -Dio.netty.noUnsafe=true, -Dio.netty.noKeySetOptimization=true, -Dio.netty.recycler.maxCapacityPerThread=0, -Dio.netty.allocator.numDirectArenas=0, -Dlog4j.shutdownHookEnabled=false, -Dlog4j2.disable.jmx=true, -Djava.locale.providers=SPI,COMPAT, -Xms8g, -Xmx8g, -XX:+UseG1GC, -XX:G1ReservePercent=25, -XX:InitiatingHeapOccupancyPercent=30, -Djava.io.tmpdir=/tmp/elasticsearch-923087555446056225, -XX:+HeapDumpOnOutOfMemoryError, -XX:HeapDumpPath=/var/lib/elasticsearch, -XX:ErrorFile=/var/log/elasticsearch/hs_err_pid%p.log, -Xlog:gc*,gc+age=trace,safepoint:file=/var/log/elasticsearch/gc.log:utctime,pid,tags:filecount=32,filesize=64m, -XX:MaxDirectMemorySize=4294967296, -Des.path.home=/usr/share/elasticsearch, -Des.path.conf=/etc/elasticsearch, -Des.distribution.flavor=oss, -Des.distribution.type=rpm, -Des.bundled_jdk=true]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,934+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [aggs-matrix-stats]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,935+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [analysis-common]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,935+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [geo]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,935+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [ingest-common]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,935+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [ingest-geoip]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,935+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [ingest-user-agent]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,936+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [kibana]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,936+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [lang-expression]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,936+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [lang-mustache]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,936+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [lang-painless]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,936+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [mapper-extras]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,936+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [parent-join]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,937+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [percolator]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,937+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [rank-eval]” }
{“type”: “server”, “timestamp”: “2021-01-05T08:46:14,937+01:00”, “level”: “INFO”, “component”: “o.e.p.PluginsService”, “cluster.name”: “graylog”, “node.name”: “log01.kb.se”, “message”: “loaded module [reindex]” }
…