Graylog 5 with Elasticsearch 7.10.2 support

I am in the same relative position you are where my ES is at 7.14 or thereabouts. as are others

I have considered doing a fresh build including all my code because I didn’t know about HTTP Fields — Graylog (GIM) Schema 0.0.1 documentation when I was building it. The current trend with Graylog/Opensearch is that ES is going away so it’s best to get into OpenSearch if you are going to spend the time. The Ubuntu OpenSearch install is via tarballs which makes me hesitate a bit …like maybe I want to wait until they have a proper maintained install… I know once it’s in I won’t worry about it much but after my ES snafu on upgrading…

I am also considering moving old ES data over via curl commands… though I don’t know how well that will go. I did a write up a while ago about correcting field types historically that included some commands for copying templates and curling data around - Someday when things calm down at work…

No matter what you do - keep the community updated - we all appreciate it!

1 Like