# Graylog Nodes "Drop" After Bringing Up Node on WAN

**URL:** <https://community.graylog.org/t/graylog-nodes-drop-after-bringing-up-node-on-wan/25314>\
**Category:** Graylog Central (peer support)\
**Tags:** documentation\
**Created:** [August 16, 2022, 5:21pm UTC](https://community.graylog.org/t/graylog-nodes-drop-after-bringing-up-node-on-wan/25314 "2022-08-16T17:21:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cameron](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/cameron/32/11429_2.png) [@Cameron](https://community.graylog.org/u/Cameron)\
**Post date:** [August 16, 2022, 5:21pm UTC](https://community.graylog.org/t/graylog-nodes-drop-after-bringing-up-node-on-wan/25314/1 "2022-08-16T17:21:18Z")

</div>

Has anyone experienced something like this, and what did you do to resolve?

**1. Describe your incident:**

Bringing up additional Graylog nodes at a second physical location causes all nodes to “drop” from the cluster entirely and processing halts. Stopping the graylog service on the new node allows the others to resume.

**2. Describe your environment:**

Three node cluster at Site1 and attempting to bring up nodes at Site2.  
Two physical network locations separated by SD-WAN.  
Two subnets under the same broadcast domain.

- Package Version:

4.3.5+32fa802 (Debian 11.0.16 on Linux 5.10.0-16-amd64)

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [August 17, 2022, 2:43pm UTC](https://community.graylog.org/t/graylog-nodes-drop-after-bringing-up-node-on-wan/25314/2 "2022-08-17T14:43:45Z")

</div>

Hello && welcome!

Not a lot to go on other than the Graylog version… Here are some tips on how to make your question clearer [here](https://community.graylog.org/t/tips-for-posting-questions-that-get-answers/21828) and [here](https://community.graylog.org/t/how-to-post-a-question-in-the-community-that-gets-responses/20879).

Have you looked in the Graylog logs? What are the server.conf files? The tips I posted show how to get the server.conf data with out all the comments… make sure to obfuscate where needed… they also show how to use the \</\> forum tool when posting code/logs to make it easily readable…

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [August 17, 2022, 10:28pm UTC](https://community.graylog.org/t/graylog-nodes-drop-after-bringing-up-node-on-wan/25314/3 "2022-08-17T22:28:53Z")

</div>

Hello and Welcome @Cameron

Adding on to what @tmacgbay Suggested.

By chance does both Elasticsearch clusters have the same name?  
Also do you have any discoveries enable in GL config file?

---

<div class="post-metadata">

**Author:** ![Cameron](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/cameron/32/11429_2.png) [@Cameron](https://community.graylog.org/u/Cameron)\
**Post date:** [August 18, 2022, 2:46pm UTC](https://community.graylog.org/t/graylog-nodes-drop-after-bringing-up-node-on-wan/25314/4 "2022-08-18T14:46:29Z")

</div>

I’m happy to report that I’ve found the issue and everything appears to be working now!

It turns out that our WAN link was just laggy enough to cause a timeout for the Master Node. After a bit of digging I found the `stale_master_timeout` setting in `server.conf` bumped it up a few seconds instead of two, and bam - problem solved!

Hopefully this post can help someone else in the future! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 1, 2022, 2:47pm UTC](https://community.graylog.org/t/graylog-nodes-drop-after-bringing-up-node-on-wan/25314/5 "2022-09-01T14:47:02Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
