Graylog log store location

(john walker) #1

can any tell me where does graylog store logs of client on base of rsyslog in centos

(Jochen) #2

All log messages ingested by Graylog are indexed (and thus stored) in Elasticsearch.

(john walker) #3

can it be this (/var/log/elasticsearch/)

(john walker) #4

if i am stopping elasticsearch service , can i be able to see the logs or not and how can i restore the logs


Elasticsearch is a database, and in default it compress the logs, and may be store it in shards. so you can’t read the logs.
Here is the official Bacup and restore Doc.

If you make a snapshot, you also won’t see the logs. It is not an export tool/solution.

(Jochen) #6

You might want to take a look at the Graylog Enterprise Archiving plugin:

(john walker) #7

can any one explain me this ?

(Jochen) #8

What exactly do you want to know?

(john walker) #9

indices , document , and size concepts
how many size will it take and all vaule which are their

(Jochen) #10

Shards and Replicas are terms from Elasticsearch, see for details.
The number of documents, indices, and the size on disk should be pretty self-explanatory.

Also make sure to read for details about how Graylog is using Elasticsearch and what the concept of index sets means.

(john walker) #11

can u tell approx 15 to 20 linux and windows server logs required how much size on graylog server

(Jochen) #12

No, a generic answer for that is not possible.

(john walker) #13

how can i setup a dashboard with only 0 & 1 level and it should send a mail on basics 0 & 1 and alert on that base

(john walker) #14

Can anyone tell me how to setup graylog with logstash and elasticsearch i.e (elg) or share any docs related to it

(Jochen) #15

Please don’t hijack old topics.

You can find step-by-step installation guides in the official Graylog documentation:

