# GrayLog Nginx Reverse Proxy Https

**URL:** <https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969>\
**Category:** Graylog Central (peer support)\
**Created:** [April 14, 2020, 3:32pm UTC](https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969 "2020-04-14T15:32:34Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![polinafrolov](https://avatars.discourse-cdn.com/v4/letter/p/5daacb/32.png) [@polinafrolov](https://community.graylog.org/u/polinafrolov)\
**Post date:** [April 14, 2020, 3:32pm UTC](https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969/1 "2020-04-14T15:32:34Z")

</div>

Hi everyone!  
I am new with Graylog Server  
And for now I have Biggets probmle.  
I installed graylog on my VPS (Ubuntu 18.04) all be fine, but when I want to use some loader balance behind graylog as nginx reverse proxy with https, I have error, my graylog server started all ok, but sometimes when I work with my graylog server I have some errors - “The connection has timed out”, “api does not respond” and other…  
Where I had mistake???  
My craylog server.conf is very simple and default:  
# Default: 127.0.0.1:9000  
http\_bind\_address = 127.0.0.1:9000  
# Default: $http\_publish\_uri  
#http\_external\_uri = $http\_publish\_uri  
My nginx reverse proxy config (I want to use https for graylog web-interface) is:  
server {  
listen 443 ssl http2;  
listen [::]:443 ssl http2;  
server\_name [mydomen.com](http://mydomen.com);  
ssl on;  
ssl\_certificate /etc/letsencrypt/live/mydomen.com/fullchain.pem;  
ssl\_certificate\_key /etc/letsencrypt/live/mydomen.com/privkey.pem;  
ssl\_session\_timeout 1d;  
ssl\_session\_cache shared:MozSSL:10m; # about 40000 sessions  
ssl\_session\_tickets off;

```
    # intermediate configuration
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:sECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
    ssl_prefer_server_ciphers off;

    # HSTS (ngx_http_headers_module is required) (63072000 seconds)
    add_header Strict-Transport-Security "max-age=63072000" always;
    location /
    { 
      proxy_set_header Host $http_host;
      proxy_set_header X-Forwarded-Host $host;
      proxy_set_header X-Forwarded-Server $host;
      proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
      proxy_set_header X-Graylog-Server-URL https://$server_name/;
      proxy_pass http://127.0.0.1:9000;
    }
}
server {
    listen 80;
    listen [::]:80;
    server_name mydomen.com;
    return 301 https://$host$request_uri;
}

```

Is it correct config for graylog server when I use ngixn reverse proxy https  
I read this manuals:  
[https://docs.graylog.org/en/3.2/pages/configuration/web\_interface.html#configuring-webif-nginx](https://docs.graylog.org/en/3.2/pages/configuration/web_interface.html#configuring-webif-nginx)  
Do I change http\_external\_uri from default to my domen name?  
And What is correct config for this  
Thx

---

<div class="post-metadata">

**Author:** ![macko003](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/macko003/32/3175_2.png) [@macko003](https://community.graylog.org/u/macko003)\
**Post date:** [April 15, 2020, 9:59am UTC](https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969/2 "2020-04-15T09:59:14Z")

</div>

> [@polinafrolov](#):
>
> Where I had mistake???

Forget to read forum’s rules. Check it, and format you message.

> [@polinafrolov](#):
>
> http\_bind\_address = 127.0.0.1:9000

Does you graylog and nginx are on the same server?

I suggest start a basic nginx config, and if it’s working start to add extras. Check graylog docs for basic config.  
You don’t need any special thing in graylog config.  
Check your nginx logs, and tcpdump on port 9000.

---

<div class="post-metadata">

**Author:** ![polinafrolov](https://avatars.discourse-cdn.com/v4/letter/p/5daacb/32.png) [@polinafrolov](https://community.graylog.org/u/polinafrolov)\
**Post date:** [April 15, 2020, 11:10am UTC](https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969/3 "2020-04-15T11:10:22Z")

</div>

> [@macko003](#):
>
> Does you graylog and nginx are on the same server?
> 
> I suggest start a basic nginx config, and if it’s working start to add extras. Check graylog docs for basic config.  
> You don’t need any special thing in graylog config.  
> Check your nginx logs, and tcpdump on port 9000.

Thx for your answer  
Yes, Graylog and nginx onthe same server  
Do I must change http\_bind\_address or $http\_publish\_uri ?

---

<div class="post-metadata">

**Author:** ![macko003](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/macko003/32/3175_2.png) [@macko003](https://community.graylog.org/u/macko003)\
**Post date:** [April 15, 2020, 11:11am UTC](https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969/4 "2020-04-15T11:11:46Z")

</div>

Honestly, I don’t know 🙂  
I use every time the http\_bind\_address only, and It is working with nginx without problem.

---

<div class="post-metadata">

**Author:** ![polinafrolov](https://avatars.discourse-cdn.com/v4/letter/p/5daacb/32.png) [@polinafrolov](https://community.graylog.org/u/polinafrolov)\
**Post date:** [April 15, 2020, 11:12am UTC](https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969/5 "2020-04-15T11:12:48Z")

</div>

Ok  
In my situation I must use 127.0.0.1:9000?

---

<div class="post-metadata">

**Author:** ![macko003](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/macko003/32/3175_2.png) [@macko003](https://community.graylog.org/u/macko003)\
**Post date:** [April 15, 2020, 11:13am UTC](https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969/6 "2020-04-15T11:13:20Z")

</div>

it should be ok.  
That tells the tcpdump?

---

<div class="post-metadata">

**Author:** ![polinafrolov](https://avatars.discourse-cdn.com/v4/letter/p/5daacb/32.png) [@polinafrolov](https://community.graylog.org/u/polinafrolov)\
**Post date:** [April 16, 2020, 7:45am UTC](https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969/7 "2020-04-16T07:45:08Z")

</div>

Thx  
All is done  
Work  
But sometimes I have this errors:  
PRD end of file and other, which comunicate with SSL config

---

<div class="post-metadata">

**Author:** ![polinafrolov](https://avatars.discourse-cdn.com/v4/letter/p/5daacb/32.png) [@polinafrolov](https://community.graylog.org/u/polinafrolov)\
**Post date:** [April 17, 2020, 9:53am UTC](https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969/8 "2020-04-17T09:53:31Z")

</div>

@macko003  
Can you help me, for now I have this kind of error:

#### Server currently unavailable

[https://mydomen.com/api/cluster/metrics/multiple](https://mydomen.com/api/cluster/metrics/multiple)  
And all is top, but after few minutes all is great and working !

---

<div class="post-metadata">

**Author:** ![macko003](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/macko003/32/3175_2.png) [@macko003](https://community.graylog.org/u/macko003)\
**Post date:** [April 17, 2020, 10:06am UTC](https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969/9 "2020-04-17T10:06:41Z")

</div>

First. it is a community support. I did this in my spare time…

Check this with and without proxy.  
And use google or community search. There were some bug ith metrics, but I’m not sure which version related, and what is the status, and this error is related or not.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [May 1, 2020, 10:06am UTC](https://community.graylog.org/t/graylog-nginx-reverse-proxy-https/14969/10 "2020-05-01T10:06:42Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
