Graylog log store location


(john walker) #1

Hi
can any tell me where does graylog store logs of client on base of rsyslog in centos


(Jochen) #2

All log messages ingested by Graylog are indexed (and thus stored) in Elasticsearch.


(john walker) #3

location
can it be this (/var/log/elasticsearch/)


(john walker) #4

if i am stopping elasticsearch service , can i be able to see the logs or not and how can i restore the logs


#5

Elasticsearch is a database, and in default it compress the logs, and may be store it in shards. so you can’t read the logs.
Here is the official Bacup and restore Doc.
https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-snapshots.html

If you make a snapshot, you also won’t see the logs. It is not an export tool/solution.


(Jochen) #6

You might want to take a look at the Graylog Enterprise Archiving plugin:
http://docs.graylog.org/en/2.4/pages/archiving.html


(john walker) #7

can any one explain me this ?


(Jochen) #8

What exactly do you want to know?


(john walker) #9

indices , document , and size concepts
how many size will it take and all vaule which are their


(Jochen) #10

Shards and Replicas are terms from Elasticsearch, see https://www.elastic.co/guide/en/elasticsearch/reference/5.6/_basic_concepts.html#getting-started-shards-and-replicas for details.
The number of documents, indices, and the size on disk should be pretty self-explanatory.

Also make sure to read http://docs.graylog.org/en/2.4/pages/configuration/index_model.html for details about how Graylog is using Elasticsearch and what the concept of index sets means.


(john walker) #11

can u tell approx 15 to 20 linux and windows server logs required how much size on graylog server


(Jochen) #12

No, a generic answer for that is not possible.


(john walker) #13

Hi
how can i setup a dashboard with only 0 & 1 level and it should send a mail on basics 0 & 1 and alert on that base


(john walker) #14

Hi
Can anyone tell me how to setup graylog with logstash and elasticsearch i.e (elg) or share any docs related to it


(Jochen) #15

Please don’t hijack old topics.

You can find step-by-step installation guides in the official Graylog documentation: http://docs.graylog.org/en/2.4/


(Jochen) #16