# Graylog indices

**URL:** <https://community.graylog.org/t/graylog-indices/5689>\
**Category:** Graylog Central (peer support)\
**Created:** [June 21, 2018, 9:00am UTC](https://community.graylog.org/t/graylog-indices/5689 "2018-06-21T09:00:30Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 21, 2018, 9:00am UTC](https://community.graylog.org/t/graylog-indices/5689/1 "2018-06-21T09:00:30Z")

</div>

Hi,  
Launched new server for graylog, I am not getting an option to create indices .

i am seeing an option as maintenance, what could be the issue.

Regards  
Sateesh

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 21, 2018, 2:44pm UTC](https://community.graylog.org/t/graylog-indices/5689/2 "2018-06-21T14:44:57Z")

</div>

please rephrase your question - it is not clear what you have done and what is not working like you expect it.

---

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 22, 2018, 6:02am UTC](https://community.graylog.org/t/graylog-indices/5689/3 "2018-06-22T06:02:51Z")

</div>

Under System -Indices- i am not seeing an option here to create index set,

I am not seeing above option. Create Index.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/83925e7c4a3d664e86128e1285f50282fc478c1f.png)

I am seeing option as mantinance

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/b/b314bb77f1749c16bc5b8e6328364fa8470a302b.png)

Regards  
Sateesh

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 22, 2018, 8:02am UTC](https://community.graylog.org/t/graylog-indices/5689/4 "2018-06-22T08:02:50Z")

</div>

If elasticsearch is available Graylog will create the default indices without the need of user interaction.

So make Elasticsearch available and restart Graylog will solve your issue.

Jan

---

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 22, 2018, 11:28am UTC](https://community.graylog.org/t/graylog-indices/5689/5 "2018-06-22T11:28:32Z")

</div>

Now . i am seeting the below error in graylog portal  
There are Elasticsearch nodes in the cluster that have a too low open file limit (current limit: 4096 on ip-x.x.x.x; should be at least 64000) This will be causing problems that can be hard to diagnose. Read how to raise the maximum number of open files in

Where this option is set

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 22, 2018, 12:45pm UTC](https://community.graylog.org/t/graylog-indices/5689/6 "2018-06-22T12:45:55Z")

</div>

> **[LMGTFY](http://lmgtfy.com/?q=elasticsearch+5.6+open+file+limit)**
>
> LMGTFY

Will give you (for example) this link: [https://www.elastic.co/guide/en/elasticsearch/reference/5.6/file-descriptors.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.6/file-descriptors.html)

Fix your Elasticsearch issues and Graylog will be working.

---

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 25, 2018, 11:32am UTC](https://community.graylog.org/t/graylog-indices/5689/7 "2018-06-25T11:32:08Z")

</div>

Hi, i am getting still not able to connect from graylog to elasticsearch server.

[zen] [grayloga35d9d88-7ceb-481c-92e4-262812b7478f] failed to send join request to master [{Legion}{}{10.223.0.4}{1.0.0.4:9300}], reason [RemoteTransportException[[Legion][1.0.0.4:9300][internal:discovery/zen/join]]; nested: ConnectTransportException[[grayloga35d9d88-77478f][127.0.0.1:9350] connect\_timeout[30s]]; nested: NotSerializableExceptionWrapper[connect\_exception: Connection refused: /127.0.0.1:9350]; ]

On graylog server if i do telnet its able to communicate, not sure what causing issue

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 25, 2018, 12:30pm UTC](https://community.graylog.org/t/graylog-indices/5689/8 "2018-06-25T12:30:32Z")

</div>

What is your `elasticsearch_host` configuration in Graylog?

> <https://github.com/Graylog2/graylog2-server/blob/2.4/misc/graylog.conf#L171-L172>

What is your elasticsearch configuration file content?

---

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 25, 2018, 12:41pm UTC](https://community.graylog.org/t/graylog-indices/5689/9 "2018-06-25T12:41:39Z")

</div>

elasticsearch\_discovery\_zen\_ping\_unicast\_hosts = 10.1.1.0.4:9300  
able to telnet from graylog to elastic search

---

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 25, 2018, 1:09pm UTC](https://community.graylog.org/t/graylog-indices/5689/10 "2018-06-25T13:09:57Z")

</div>

In Graylog i can see the below error

connect\_timeout[30s]]; nested: NotSerializableExceptionWrapper[connect\_exception: Connection refused: /127.0.0.1:9350]; ]  
2018-06-25T11:03:54.083Z ERROR [AnyExceptionClassMapper] Unhandled exception in REST resource  
org.elasticsearch.discovery.MasterNotDiscoveredException  
at org.elasticsearch.action.support.master.TransportMasterNodeAction$AsyncSingleAction$5.onTimeout(TransportMasterNodeAction.java:226) ~[graylog.jar:?]  
at org.elasticsearch.cluster.ClusterStateObserver$ObserverClusterStateListener.onTimeout(ClusterStateObserver.java:236) ~[graylog.jar:?]  
at org.elasticsearch.cluster.service.InternalClusterService$NotifyTimeout.run(InternalClusterService.java:804) ~[graylog.jar:?]  
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) [?:1.8.0\_171]  
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) [?:1.8.0\_171]  
at java.lang.Thread.run(Thread.java:748) [?:1.8.0\_171]

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 25, 2018, 2:49pm UTC](https://community.graylog.org/t/graylog-indices/5689/11 "2018-06-25T14:49:35Z")

</div>

what you gives me does not answer my two questions.

but, what Graylog Version did you have? and in addition my two questions above are not yet answered.

---

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 25, 2018, 4:45pm UTC](https://community.graylog.org/t/graylog-indices/5689/12 "2018-06-25T16:45:49Z")

</div>

I am using graylog version Graylog v2.1

elastic search hostname i have defined as below elasticsearch\_discovery\_zen\_ping\_unicast\_hosts = 10.1.1.0.4:9300  
elasticsearch\_hosts = [http://x.x.x.x:9300](http://x.x.x.x:9300),  
able to telnet from graylog to elastic search

---

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 25, 2018, 5:07pm UTC](https://community.graylog.org/t/graylog-indices/5689/13 "2018-06-25T17:07:22Z")

</div>

Basically issue with not able to connect from ES to Graylog by 9350 port  
nested: ConnectTransportException[[grayloga35d9d88478f][127.0.0.1:9350] connect\_timeout[30s]]; nested: NotSerializableExceptionWrapper[connect\_exception: Connection refused: /127.0.0.1:9350];  
tcp6 0 0 ::1:25 :::\* LISTEN 977/master  
tcp6 0 0 127.0.0.1:9350 :::\* LISTEN 29335/java  
tcp6 0 0 ::1:9350 :::\* LISTEN 29335/java  
[root@ server]#

---

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 25, 2018, 5:26pm UTC](https://community.graylog.org/t/graylog-indices/5689/14 "2018-06-25T17:26:22Z")

</div>

This issue resolved communication issue, able to communicate from Graylog to ES, still not able to see an option under system–\> Indices- create indices and default indices option is not showing

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 26, 2018, 9:12am UTC](https://community.graylog.org/t/graylog-indices/5689/15 "2018-06-26T09:12:11Z")

</div>

depending on your ES configuration you might have choosen the wrong port for the communication.

Your Graylog Version 2.1 does not contain the option to create different indices. This was introduced with 2.2 ( [https://www.graylog.org/post/announcing-graylog-v2-2-0](https://www.graylog.org/post/announcing-graylog-v2-2-0) ).

You should really update the the latest release - which is 2.4.5 at time of writing this.

---

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 26, 2018, 12:14pm UTC](https://community.graylog.org/t/graylog-indices/5689/16 "2018-06-26T12:14:19Z")

</div>

I have installed with 2.4, default index is not created and input GELF TCP is not starting the process.

---

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 26, 2018, 12:58pm UTC](https://community.graylog.org/t/graylog-indices/5689/17 "2018-06-26T12:58:24Z")

</div>

Could not retrieve index sets.  
Fetching index sets list failed: Unable to read information for indices [graylog\_\*]

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [June 26, 2018, 1:06pm UTC](https://community.graylog.org/t/graylog-indices/5689/18 "2018-06-26T13:06:21Z")

</div>

if you update your Graylog, what is your configuration of Graylog (server.conf) what is your Elasticsearch configuration (elasticsearch.yml) and what Version of Elasticsearch did you run?

---

<div class="post-metadata">

**Author:** ![sateesh](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@sateesh](https://community.graylog.org/u/sateesh)\
**Post date:** [June 26, 2018, 3:34pm UTC](https://community.graylog.org/t/graylog-indices/5689/19 "2018-06-26T15:34:57Z")

</div>

Graylog v2.3.2+3df951e elasticsearch version 5  
any command to check config output

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [June 26, 2018, 3:43pm UTC](https://community.graylog.org/t/graylog-indices/5689/20 "2018-06-26T15:43:14Z")

</div>

You have problems with your IP addresses. Your snippets tell you use

- 10.1.1.0.4 (which is not a valid IPv4 address)
- 127.0.0.1 (which is a loopback device)
- x.x.x.x (which you are not revealing)

You should select either the loopback interface or an eth interface and use it consistently.

[Next page](https://community.graylog.org/t/graylog-indices/5689.md?page=2)
