Elasticsearch:
018-03-28T09:30:40.113+02:00 INFO [CmdLineTool] Loaded plugin: AWS plugins 2.4.3 [org.graylog.aws.plugin.AWSPlugin]
2018-03-28T09:30:40.115+02:00 INFO [CmdLineTool] Loaded plugin: Elastic Beats Input 2.4.3 [org.graylog.plugins.beats.BeatsInputPlugin]
2018-03-28T09:30:40.115+02:00 INFO [CmdLineTool] Loaded plugin: CEF Input 1.0.0 [org.graylog.plugins.cef.CEFInputPlugin]
2018-03-28T09:30:40.115+02:00 INFO [CmdLineTool] Loaded plugin: Collector 2.4.3 [org.graylog.plugins.collector.CollectorPlugin]
2018-03-28T09:30:40.116+02:00 INFO [CmdLineTool] Loaded plugin: Enterprise Integration Plugin 2.4.3 [org.graylog.plugins.enterprise_integration.EnterpriseIntegrationPlugin]
2018-03-28T09:30:40.117+02:00 INFO [CmdLineTool] Loaded plugin: Internal Logs plugin 2.4.0 [org.graylog.plugins.internallogs.InternalLogsInputPlugin]
2018-03-28T09:30:40.117+02:00 INFO [CmdLineTool] Loaded plugin: MapWidgetPlugin 2.4.3 [org.graylog.plugins.map.MapWidgetPlugin]
2018-03-28T09:30:40.117+02:00 INFO [CmdLineTool] Loaded plugin: NetFlow Plugin 2.4.3 [org.graylog.plugins.netflow.NetFlowPlugin]
2018-03-28T09:30:40.122+02:00 INFO [CmdLineTool] Loaded plugin: Pipeline Processor Plugin 2.2.0 [org.graylog.plugins.pipelineprocessor.ProcessorPlugin]
2018-03-28T09:30:40.123+02:00 INFO [CmdLineTool] Loaded plugin: Threat Intelligence Plugin 2.4.3 [org.graylog.plugins.threatintel.ThreatIntelPlugin]
2018-03-28T09:30:40.123+02:00 INFO [CmdLineTool] Loaded plugin: SnmpPlugin 0.3.0 [org.graylog.snmp.SnmpPlugin]
2018-03-28T09:30:40.366+02:00 INFO [CmdLineTool] Running with JVM arguments: -Xms15g -Xmx15g -XX:NewRatio=1 -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow -Dlog4j.configurationFile=file:///etc/graylog/server/log4j2.xml -Djava.library.path=/usr/share/graylog-server/lib/sigar -Dgraylog2.installation_source=deb
2018-03-28T09:30:40.526+02:00 INFO [Version] HV000001: Hibernate Validator 5.1.3.Final
2018-03-28T09:30:42.298+02:00 INFO [InputBufferImpl] Message journal is enabled.
2018-03-28T09:30:42.313+02:00 INFO [NodeId] Node ID: 689bbe87-2d30-46b1-b1b0-bab46e8f5e0d
2018-03-28T09:30:42.475+02:00 INFO [LogManager] Loading logs.
2018-03-28T09:30:42.507+02:00 WARN [Log] Found a corrupted index file, /var/lib/graylog-server/journal/messagejournal-0/00000000002887846478.index, deleting and rebuilding index...
2018-03-28T09:30:43.021+02:00 INFO [LogManager] Logs loading complete.
2018-03-28T09:30:43.022+02:00 INFO [KafkaJournal] Initialized Kafka based journal at /var/lib/graylog-server/journal
2018-03-28T09:30:43.049+02:00 INFO [InputBufferImpl] Initialized InputBufferImpl with ring size <65536> and wait strategy <BlockingWaitStrategy>, running 20 parallel message handlers.
2018-03-28T09:30:43.068+02:00 INFO [cluster] Cluster created with settings {hosts=[localhost:27017], mode=SINGLE, requiredClusterType=UNKNOWN, serverSelectionTimeout='30000 ms', maxWaitQueueSize=5000}
2018-03-28T09:30:43.117+02:00 INFO [cluster] No server chosen by ReadPreferenceServerSelector{readPreference=primary} from cluster description ClusterDescription{type=UNKNOWN, connectionMode=SINGLE, serverDescriptions=[ServerDescription{address=localhost:27017, type=UNKNOWN, state=CONNECTING}]}. Waiting for 30000 ms before timing out
2018-03-28T09:30:43.138+02:00 INFO [connection] Opened connection [connectionId{localValue:1, serverValue:1}] to localhost:27017
2018-03-28T09:30:43.140+02:00 INFO [cluster] Monitor thread successfully connected to server with description ServerDescription{address=localhost:27017, type=STANDALONE, state=CONNECTED, ok=true, version=ServerVersion{versionList=[2, 6, 10]}, minWireVersion=0, maxWireVersion=2, maxDocumentSize=16777216, roundTripTimeNanos=487680}
2018-03-28T09:30:43.153+02:00 INFO [connection] Opened connection [connectionId{localValue:2, serverValue:2}] to localhost:27017
2018-03-28T09:30:43.469+02:00 INFO [AbstractJestClient] Setting server pool to a list of 1 servers: [http://127.0.0.1:9200]
2018-03-28T09:30:43.470+02:00 INFO [JestClientFactory] Using multi thread/connection supporting pooling connection manager
2018-03-28T09:30:43.525+02:00 INFO [JestClientFactory] Using custom ObjectMapper instance
2018-03-28T09:30:43.525+02:00 INFO [JestClientFactory] Node Discovery disabled...
2018-03-28T09:30:43.525+02:00 INFO [JestClientFactory] Idle connection reaping disabled...
2018-03-28T09:30:43.730+02:00 INFO [ProcessBuffer] Initialized ProcessBuffer with ring size <131072> and wait strategy <BlockingWaitStrategy>.
2018-03-28T09:30:45.295+02:00 INFO [RulesEngineProvider] Using rules: /etc/graylog/server/rules.drl
2018-03-28T09:30:45.552+02:00 INFO [OutputBuffer] Initialized OutputBuffer with ring size <131072> and wait strategy <BlockingWaitStrategy>.
2018-03-28T09:30:45.774+02:00 INFO [connection] Opened connection [connectionId{localValue:3, serverValue:3}] to localhost:27017
2018-03-28T09:31:01.535+02:00 INFO [ServerBootstrap] Graylog server 2.4.3+2c41897 starting up
2018-03-28T09:31:01.536+02:00 INFO [ServerBootstrap] JRE: Oracle Corporation 1.8.0_151 on Linux 4.4.0-116-generic
2018-03-28T09:31:01.536+02:00 INFO [ServerBootstrap] Deployment: deb
2018-03-28T09:31:01.536+02:00 INFO [ServerBootstrap] OS: Ubuntu 16.04.4 LTS (xenial)
2018-03-28T09:31:01.536+02:00 INFO [ServerBootstrap] Arch: amd64
2018-03-28T09:31:01.539+02:00 WARN [DeadEventLoggingListener] Received unhandled event of type <org.graylog2.plugin.lifecycles.Lifecycle> from event bus <AsyncEventBus{graylog-eventbus}>
2018-03-28T09:31:01.564+02:00 INFO [PeriodicalsService] Starting 25 periodicals ...
2018-03-28T09:31:01.565+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.ThroughputCalculator] periodical in [0s], polling every [1s].
2018-03-28T09:31:01.571+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.AlertScannerThread] periodical in [10s], polling every [60s].
2018-03-28T09:31:01.585+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.BatchedElasticSearchOutputFlushThread] periodical in [0s], polling every [1s].
2018-03-28T09:31:01.590+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.ClusterHealthCheckThread] periodical in [120s], polling every [20s].
2018-03-28T09:31:01.591+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.ContentPackLoaderPeriodical] periodical, running forever.
2018-03-28T09:31:01.595+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.GarbageCollectionWarningThread] periodical, running forever.
2018-03-28T09:31:01.597+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexerClusterCheckerThread] periodical in [0s], polling every [30s].
2018-03-28T09:31:01.599+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRetentionThread] periodical in [0s], polling every [300s].
2018-03-28T09:31:01.602+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRotationThread] periodical in [0s], polling every [10s].
2018-03-28T09:31:01.605+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.NodePingThread] periodical in [0s], polling every [1s].
2018-03-28T09:31:01.607+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.VersionCheckThread] periodical in [300s], polling every [1800s].
2018-03-28T09:31:01.607+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.ThrottleStateUpdaterThread] periodical in [1s], polling every [1s].
2018-03-28T09:31:01.609+02:00 INFO [Periodicals] Starting [org.graylog2.events.ClusterEventPeriodical] periodical in [0s], polling every [1s].
2018-03-28T09:31:01.609+02:00 INFO [Periodicals] Starting [org.graylog2.events.ClusterEventCleanupPeriodical] periodical in [0s], polling every [86400s].
2018-03-28T09:31:01.614+02:00 INFO [connection] Opened connection [connectionId{localValue:4, serverValue:4}] to localhost:27017
2018-03-28T09:31:01.614+02:00 INFO [connection] Opened connection [connectionId{localValue:5, serverValue:5}] to localhost:27017
2018-03-28T09:31:01.614+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.ClusterIdGeneratorPeriodical] periodical, running forever.
2018-03-28T09:31:01.615+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRangesMigrationPeriodical] periodical, running forever.
2018-03-28T09:31:01.617+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRangesCleanupPeriodical] periodical in [15s], polling every [3600s].
2018-03-28T09:31:01.631+02:00 INFO [connection] Opened connection [connectionId{localValue:7, serverValue:6}] to localhost:27017
2018-03-28T09:31:01.631+02:00 INFO [connection] Opened connection [connectionId{localValue:6, serverValue:7}] to localhost:27017
2018-03-28T09:31:01.657+02:00 INFO [PeriodicalsService] Not starting [org.graylog2.periodical.UserPermissionMigrationPeriodical] periodical. Not configured to run on this node.
2018-03-28T09:31:01.658+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.AlarmCallbacksMigrationPeriodical] periodical, running forever.
2018-03-28T09:31:01.658+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.ConfigurationManagementPeriodical] periodical, running forever.
2018-03-28T09:31:01.678+02:00 INFO [PeriodicalsService] Not starting [org.graylog2.periodical.LdapGroupMappingMigration] periodical. Not configured to run on this node.
2018-03-28T09:31:01.679+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexFailuresPeriodical] periodical, running forever.
2018-03-28T09:31:01.679+02:00 INFO [Periodicals] Starting [org.graylog2.periodical.TrafficCounterCalculator] periodical in [0s], polling every [1s].
2018-03-28T09:31:01.682+02:00 INFO [Periodicals] Starting [org.graylog.plugins.pipelineprocessor.periodical.LegacyDefaultStreamMigration] periodical, running forever.
2018-03-28T09:31:01.682+02:00 INFO [Periodicals] Starting [org.graylog.plugins.collector.periodical.PurgeExpiredCollectorsThread] periodical in [0s], polling every [3600s].
2018-03-28T09:31:01.686+02:00 INFO [LegacyDefaultStreamMigration] Legacy default stream has no connections, no migration needed.
2018-03-28T09:31:01.717+02:00 INFO [LookupTableService] Data Adapter otx-api-domain/5a786bdacd455e047f8b5148 [@27a16870] STARTING
2018-03-28T09:31:01.728+02:00 INFO [LookupTableService] Data Adapter otx-api-ip/5a786bdacd455e047f8b5146 [@2229c67a] STARTING
2018-03-28T09:31:01.729+02:00 WARN [OTXDataAdapter] OTX API key is missing. Make sure to add the key to allow higher request limits.
2018-03-28T09:31:01.729+02:00 WARN [OTXDataAdapter] OTX API key is missing. Make sure to add the key to allow higher request limits.
2018-03-28T09:31:01.738+02:00 INFO [LookupTableService] Data Adapter whois/5a786bdacd455e047f8b5142 [@4a1f78b6] STARTING
2018-03-28T09:31:01.741+02:00 INFO [LookupTableService] Data Adapter tor-exit-node/5a786bdacd455e047f8b5143 [@2b732eca] STARTING
2018-03-28T09:31:01.741+02:00 INFO [LookupTableService] Data Adapter whois/5a786bdacd455e047f8b5142 [@4a1f78b6] RUNNING
2018-03-28T09:31:01.744+02:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5a786bdacd455e047f8b5149 [@4712eade] STARTING
2018-03-28T09:31:01.746+02:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5a786bdacd455e047f8b5145 [@502d6653] STARTING
2018-03-28T09:31:01.750+02:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5a786bdacd455e047f8b5144 [@5deeda51] STARTING
2018-03-28T09:31:01.757+02:00 INFO [LookupTableService] Data Adapter otx-api-ip/5a786bdacd455e047f8b5146 [@2229c67a] RUNNING
2018-03-28T09:31:01.757+02:00 INFO [LookupTableService] Data Adapter otx-api-domain/5a786bdacd455e047f8b5148 [@27a16870] RUNNING
2018-03-28T09:31:01.781+02:00 INFO [LookupTableService] Cache whois-cache/5a786bdacd455e047f8b513e [@55dd6f0c] STARTING
2018-03-28T09:31:01.788+02:00 INFO [LookupTableService] Cache otx-api-domain-cache/5a786bdacd455e047f8b513f [@6f093caa] STARTING
2018-03-28T09:31:01.790+02:00 INFO [LookupTableService] Cache whois-cache/5a786bdacd455e047f8b513e [@55dd6f0c] RUNNING
2018-03-28T09:31:01.793+02:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5a786bdacd455e047f8b5141 [@1a442e3c] STARTING
2018-03-28T09:31:01.794+02:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5a786bdacd455e047f8b5141 [@1a442e3c] RUNNING
2018-03-28T09:31:01.793+02:00 INFO [LookupTableService] Cache otx-api-domain-cache/5a786bdacd455e047f8b513f [@6f093caa] RUNNING
2018-03-28T09:31:01.793+02:00 INFO [LookupTableService] Cache otx-api-ip-cache/5a786bdacd455e047f8b513d [@83d8ea2] STARTING
2018-03-28T09:31:01.794+02:00 INFO [LookupTableService] Cache otx-api-ip-cache/5a786bdacd455e047f8b513d [@83d8ea2] RUNNING
2018-03-28T09:31:01.793+02:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5a786bdacd455e047f8b5140 [@5380ae08] STARTING
2018-03-28T09:31:01.794+02:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5a786bdacd455e047f8b5140 [@5380ae08] RUNNING
2018-03-28T09:31:01.922+02:00 INFO [IndexRetentionThread] Elasticsearch cluster not available, skipping index retention checks.
2018-03-28T09:31:02.100+02:00 INFO [JerseyService] Enabling CORS for HTTP endpoint
2018-03-28T09:31:02.333+02:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5a786bdacd455e047f8b5145 [@502d6653] RUNNING
2018-03-28T09:31:02.333+02:00 INFO [LookupDataAdapterRefreshService] Adding job for <abuse-ch-ransomware-ip/5a786bdacd455e047f8b5145/@502d6653> [interval=150000ms]
2018-03-28T09:31:02.347+02:00 INFO [LookupDataAdapterRefreshService] Adding job for <spamhaus-drop/5a786bdacd455e047f8b5149/@4712eade> [interval=43200000ms]
2018-03-28T09:31:02.346+02:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5a786bdacd455e047f8b5149 [@4712eade] RUNNING
2018-03-28T09:31:02.358+02:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5a786bdacd455e047f8b5144 [@5deeda51] RUNNING
2018-03-28T09:31:02.358+02:00 INFO [LookupDataAdapterRefreshService] Adding job for <abuse-ch-ransomware-domains/5a786bdacd455e047f8b5144/@5deeda51> [interval=150000ms]
2018-03-28T09:31:02.647+02:00 INFO [LookupTableService] Data Adapter tor-exit-node/5a786bdacd455e047f8b5143 [@2b732eca] RUNNING
2018-03-28T09:31:02.647+02:00 INFO [LookupDataAdapterRefreshService] Adding job for <tor-exit-node/5a786bdacd455e047f8b5143/@2b732eca> [interval=3600000ms]
2018-03-28T09:31:02.655+02:00 INFO [LookupTableService] Starting lookup table otx-api-ip/5a786bdacd455e047f8b514a [@4fdbd9f6] using cache otx-api-ip-cache/5a786bdacd455e047f8b513d [@83d8ea2], data adapter otx-api-ip/5a786bdacd455e047f8b5146 [@2229c67a]
2018-03-28T09:31:02.656+02:00 INFO [LookupTableService] Starting lookup table otx-api-domain/5a786bdacd455e047f8b514b [@5c4993] using cache otx-api-domain-cache/5a786bdacd455e047f8b513f [@6f093caa], data adapter otx-api-domain/5a786bdacd455e047f8b5148 [@27a16870]
2018-03-28T09:31:02.656+02:00 INFO [LookupTableService] Starting lookup table abuse-ch-ransomware-domains/5a786bdacd455e047f8b514c [@29a27563] using cache threat-intel-uncached-adapters/5a786bdacd455e047f8b5141 [@1a442e3c], data adapter abuse-ch-ransomware-domains/5a786bdacd455e047f8b5144 [@5deeda51]
2018-03-28T09:31:02.656+02:00 INFO [LookupTableService] Starting lookup table whois/5a786bdacd455e047f8b514d [@47699322] using cache whois-cache/5a786bdacd455e047f8b513e [@55dd6f0c], data adapter whois/5a786bdacd455e047f8b5142 [@4a1f78b6]
2018-03-28T09:31:02.657+02:00 INFO [LookupTableService] Starting lookup table abuse-ch-ransomware-ip/5a786bdacd455e047f8b514e [@566cf650] using cache threat-intel-uncached-adapters/5a786bdacd455e047f8b5141 [@1a442e3c], data adapter abuse-ch-ransomware-ip/5a786bdacd455e047f8b5145 [@502d6653]
2018-03-28T09:31:02.657+02:00 INFO [LookupTableService] Starting lookup table tor-exit-node-list/5a786bdacd455e047f8b514f [@341e2ddf] using cache threat-intel-uncached-adapters/5a786bdacd455e047f8b5141 [@1a442e3c], data adapter tor-exit-node/5a786bdacd455e047f8b5143 [@2b732eca]
2018-03-28T09:31:02.657+02:00 INFO [LookupTableService] Starting lookup table spamhaus-drop/5a786bdacd455e047f8b5150 [@e2d5f52] using cache spamhaus-e-drop-cache/5a786bdacd455e047f8b5140 [@5380ae08], data adapter spamhaus-drop/5a786bdacd455e047f8b5149 [@4712eade]
2018-03-28T09:31:10.079+02:00 INFO [NetworkListener] Started listener bound to [172.16.2.119:9000]
2018-03-28T09:31:10.081+02:00 INFO [HttpServer] [HttpServer] Started.
2018-03-28T09:31:10.081+02:00 INFO [JerseyService] Started REST API at <http://172.16.2.119:9000/api/>
2018-03-28T09:31:10.081+02:00 INFO [JerseyService] Started Web Interface at <http://172.16.2.119:9000/>
2018-03-28T09:31:10.083+02:00 INFO [ServiceManagerListener] Services are healthy
2018-03-28T09:31:10.083+02:00 INFO [ServerBootstrap] Services started, startup times in ms: {InputSetupService [RUNNING]=4, JournalReader [RUNNING]=4, OutputSetupService [RUNNING]=7, ConfigurationEtagService [RUNNING]=14, BufferSynchronizerService [RUNNING]=16, KafkaJournal [RUNNING]=20, StreamCacheService [RUNNING]=90, PeriodicalsService [RUNNING]=123, LookupTableService [RUNNING]=1091, JerseyService [RUNNING]=8519}
2018-03-28T09:31:10.084+02:00 INFO [InputSetupService] Triggering launching persisted inputs, node transitioned from Uninitialized [LB:DEAD] to Running [LB:ALIVE]
2018-03-28T09:31:10.089+02:00 INFO [ServerBootstrap] Graylog server up and running.
2018-03-28T09:31:10.123+02:00 INFO [InputStateListener] Input [GELF UDP/599dc721cd455e354f2727e3] is now STARTING
2018-03-28T09:31:10.124+02:00 INFO [InputStateListener] Input [Syslog UDP/598c1eaccd455e75ef7ef4f0] is now STARTING
2018-03-28T09:31:10.126+02:00 INFO [InputStateListener] Input [CEF TCP Input/5ab21ad8cd455e22b63da370] is now STARTING
2018-03-28T09:31:10.127+02:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/5a86a2d6cd455e22b60e8489] is now STARTING
2018-03-28T09:31:10.127+02:00 INFO [InputStateListener] Input [GELF TCP/599d1056cd455e2a5b920def] is now STARTING
2018-03-28T09:31:10.129+02:00 INFO [InputStateListener] Input [SNMP UDP/5a546250cd455e228c318e5e] is now STARTING
2018-03-28T09:31:10.130+02:00 INFO [InputStateListener] Input [Syslog TCP/598c1e8ecd455e75ef7ef4ca] is now STARTING
2018-03-28T09:31:11.011+02:00 WARN [NettyTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog UDP, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} should be 262144 but is 212992.
2018-03-28T09:31:11.013+02:00 WARN [NettyTransport] receiveBufferSize (SO_RCVBUF) for input GELFUDPInput{title=Windows Events GELF UDP, type=org.graylog2.inputs.gelf.udp.GELFUDPInput, nodeId=null} should be 262144 but is 212992.
2018-03-28T09:31:11.177+02:00 WARN [NettyTransport] receiveBufferSize (SO_RCVBUF) for input CEFTCPInput{title=TCP CEF , type=org.graylog.plugins.cef.input.CEFTCPInput, nodeId=null} should be 1048576 but is 212992.
2018-03-28T09:31:11.177+02:00 WARN [NettyTransport] receiveBufferSize (SO_RCVBUF) for input SyslogTCPInput{title=Syslog TCP , type=org.graylog2.inputs.syslog.tcp.SyslogTCPInput, nodeId=null} should be 1048576 but is 212992.
2018-03-28T09:31:11.177+02:00 WARN [NettyTransport] receiveBufferSize (SO_RCVBUF) for input GELFTCPInput{title=Windows Events GELF TCP, type=org.graylog2.inputs.gelf.tcp.GELFTCPInput, nodeId=null} should be 1048576 but is 212992.
2018-03-28T09:31:11.182+02:00 INFO [InputStateListener] Input [GELF UDP/599dc721cd455e354f2727e3] is now RUNNING
2018-03-28T09:31:11.184+02:00 INFO [InputStateListener] Input [CEF TCP Input/5ab21ad8cd455e22b63da370] is now RUNNING
2018-03-28T09:31:11.526+02:00 WARN [NettyTransport] receiveBufferSize (SO_RCVBUF) for input SnmpUDPInput{title=SNMP Trap, type=org.graylog.snmp.input.SnmpUDPInput, nodeId=null} should be 262144 but is 212992.
2018-03-28T09:31:11.527+02:00 WARN [NettyTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Network Event Firewall, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=null} should be 262144 but is 212992.
2018-03-28T09:31:11.539+02:00 INFO [InputStateListener] Input [Syslog TCP/598c1e8ecd455e75ef7ef4ca] is now RUNNING
2018-03-28T09:31:11.546+02:00 INFO [InputStateListener] Input [Syslog UDP/598c1eaccd455e75ef7ef4f0] is now RUNNING
2018-03-28T09:31:11.547+02:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/5a86a2d6cd455e22b60e8489] is now RUNNING
2018-03-28T09:31:11.550+02:00 INFO [InputStateListener] Input [SNMP UDP/5a546250cd455e228c318e5e] is now RUNNING
2018-03-28T09:31:11.551+02:00 INFO [InputStateListener] Input [GELF TCP/599d1056cd455e2a5b920def] is now RUNNING
2018-03-28T09:31:24.093+02:00 ERROR [DecodingProcessor] Unable to decode raw message RawMessage{id=71db3aa1-3252-11e8-9161-f403433d1b68, journalOffset=2887087277, codec=syslog, payloadSize=920, timestamp=2018-03-28T06:37:11.370Z, remoteAddress=/172.16.2.237:48001} on input <598c1eaccd455e75ef7ef4f0>.
2018-03-28T09:31:24.101+02:00 ERROR [DecodingProcessor] Unable to decode raw message RawMessage{id=71db3aa3-3252-11e8-9161-f403433d1b68, journalOffset=2887087279, codec=syslog, payloadSize=920, timestamp=2018-03-28T06:37:11.370Z, remoteAddress=/172.16.2.237:48001} on input <598c1eaccd455e75ef7ef4f0>.
2018-03-28T09:31:24.101+02:00 ERROR [DecodingProcessor] Error processing message RawMessage{id=71db3aa3-3252-11e8-9161-f403433d1b68, journalOffset=2887087279, codec=syslog, payloadSize=920, timestamp=2018-03-28T06:37:11.370Z, remoteAddress=/172.16.2.237:48001}
java.lang.IllegalArgumentException: Invalid format: "922-21a0-0017a4770004/" is malformed at "a0-0017a4770004/"
at org.joda.time.format.DateTimeFormatter.parseDateTime(DateTimeFormatter.java:945) ~[graylog.jar:?]
at org.joda.time.DateTime.parse(DateTime.java:160) ~[graylog.jar:?]
at org.joda.time.DateTime.parse(DateTime.java:149) ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.SyslogServerEvent.parseDate(SyslogServerEvent.java:108) ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.SyslogServerEvent.parsePriority(SyslogServerEvent.java:136) ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.SyslogServerEvent.parse(SyslogServerEvent.java:152) ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.SyslogServerEvent.<init>(SyslogServerEvent.java:50) ~[graylog.jar:?]
at org.graylog2.inputs.codecs.SyslogCodec.parse(SyslogCodec.java:132) ~[graylog.jar:?]
at org.graylog2.inputs.codecs.SyslogCodec.decode(SyslogCodec.java:96) ~[graylog.jar:?]
at org.graylog2.shared.buffers.processors.DecodingProcessor.processMessage(DecodingProcessor.java:150) ~[graylog.jar:?]
at org.graylog2.shared.buffers.processors.DecodingProcessor.onEvent(DecodingProcessor.java:91) [graylog.jar:?]
at org.graylog2.shared.buffers.processors.ProcessBufferProcessor.onEvent(ProcessBufferProcessor.java:74) [graylog.jar:?]
at org.graylog2.shared.buffers.processors.ProcessBufferProcessor.onEvent(ProcessBufferProcessor.java:42) [graylog.jar:?]
at com.lmax.disruptor.WorkProcessor.run(WorkProcessor.java:143) [graylog.jar:?]
at com.codahale.metrics.InstrumentedThreadFactory$InstrumentedRunnable.run(InstrumentedThreadFactory.java:66) [graylog.jar:?]
at java.lang.Thread.run(Thread.java:748) [?:1.8.0_151]
2018-03-28T09:31:24.095+02:00 ERROR [DecodingProcessor] Error processing message RawMessage{id=71db3aa1-3252-11e8-9161-f403433d1b68, journalOffset=2887087277, codec=syslog, payloadSize=920, timestamp=2018-03-28T06:37:11.370Z, remoteAddress=/172.16.2.237:48001}
java.lang.IllegalArgumentException: Invalid format: "2c4-5920094a-0d1a-0017a4" is malformed at "c4-5920094a-0d1a-0017a4"
at org.joda.time.format.DateTimeFormatter.parseDateTime(DateTimeFormatter.java:945) ~[graylog.jar:?]
at org.joda.time.DateTime.parse(DateTime.java:160) ~[graylog.jar:?]
at org.joda.time.DateTime.parse(DateTime.java:149) ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.SyslogServerEvent.parseDate(SyslogServerEvent.java:108) ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.SyslogServerEvent.parsePriority(SyslogServerEvent.java:136) ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.SyslogServerEvent.parse(SyslogServerEvent.java:152) ~[graylog.jar:?]
at org.graylog2.syslog4j.server.impl.event.SyslogServerEvent.<init>(SyslogServerEvent.java:50) ~[graylog.jar:?]
at org.graylog2.inputs.codecs.SyslogCodec.parse(SyslogCodec.java:132) ~[graylog.jar:?]
at org.graylog2.inputs.codecs.SyslogCodec.decode(SyslogCodec.java:96) ~[graylog.jar:?]
at org.graylog2.shared.buffers.processors.DecodingProcessor.processMessage(DecodingProcessor.java:150) ~[graylog.jar:?]
at org.graylog2.shared.buffers.processors.DecodingProcessor.onEvent(DecodingProcessor.java:91) [graylog.jar:?]
at org.graylog2.shared.buffers.processors.ProcessBufferProcessor.onEvent(ProcessBufferProcessor.java:74) [graylog.jar:?]
at org.graylog2.shared.buffers.processors.ProcessBufferProcessor.onEvent(ProcessBufferProcessor.java:42) [graylog.jar:?]
at com.lmax.disruptor.WorkProcessor.run(WorkProcessor.java:143) [graylog.jar:?]
at com.codahale.metrics.InstrumentedThreadFactory$InstrumentedRunnable.run(InstrumentedThreadFactory.java:66) [graylog.jar:?]
at java.lang.Thread.run(Thread.java:748) [?:1.8.0_151]
2018-03-28T09:32:12.986+02:00 ERROR [Messages] Caught exception during bulk indexing: java.net.SocketTimeoutException: Read timed out, retrying (attempt #1).
2018-03-28T09:32:13.441+02:00 ERROR [Messages] Caught exception during bulk indexing: java.net.SocketTimeoutException: Read timed out, retrying (attempt #1).
2018-03-28T09:33:04.287+02:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/5a86a2d6cd455e22b60e8489] is now STOPPING
2018-03-28T09:33:04.320+02:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/5a86a2d6cd455e22b60e8489] is now STOPPED
2018-03-28T09:33:04.321+02:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/5a86a2d6cd455e22b60e8489] is now TERMINATED
2018-03-28T09:33:04.994+02:00 INFO [InputStateListener] Input [SNMP UDP/5a546250cd455e228c318e5e] is now STOPPING
2018-03-28T09:33:05.017+02:00 INFO [InputStateListener] Input [SNMP UDP/5a546250cd455e228c318e5e] is now STOPPED
2018-03-28T09:33:05.018+02:00 INFO [InputStateListener] Input [SNMP UDP/5a546250cd455e228c318e5e] is now TERMINATED
2018-03-28T09:33:05.537+02:00 INFO [InputStateListener] Input [Syslog TCP/598c1e8ecd455e75ef7ef4ca] is now STOPPING
2018-03-28T09:33:05.557+02:00 INFO [InputStateListener] Input [Syslog TCP/598c1e8ecd455e75ef7ef4ca] is now STOPPED
2018-03-28T09:33:05.558+02:00 INFO [InputStateListener] Input [Syslog TCP/598c1e8ecd455e75ef7ef4ca] is now TERMINATED
2018-03-28T09:33:06.695+02:00 INFO [InputStateListener] Input [Syslog UDP/598c1eaccd455e75ef7ef4f0] is now STOPPING
2018-03-28T09:33:06.713+02:00 INFO [InputStateListener] Input [Syslog UDP/598c1eaccd455e75ef7ef4f0] is now STOPPED
2018-03-28T09:33:06.713+02:00 INFO [InputStateListener] Input [Syslog UDP/598c1eaccd455e75ef7ef4f0] is now TERMINATED
2018-03-28T09:33:07.847+02:00 INFO [InputStateListener] Input [GELF TCP/599d1056cd455e2a5b920def] is now STOPPING