Hi all guys:
I’ve the following environment: 2 graylog-server , 3 Elastic-Search , 1 MongoDB. I’ve a strange behaviour: I created some inputs but in some of them I loose messages.
I did some checks:
1/ take with tcpdump the traffic coming from external devices, all of them appears (seeing the source).
2/ from Graylog UI these messages are not shown.
3/ from elastic I did;
curl -H 'Content-Type: application/json' -X GET http://localhost:9200/ads__0/_search?pretty |grep source
and it shows just from one source.
I don’t know what the next to check but I will be crazy with this issue
Thanks in advance.
Note: Graylog 3.0.2