Recently updated to the newest Graylog version 2.3.1, running ES 5.6 and I can not longer search past 23:23 CST. I can see the indices are growing, there aren’t any errors in elasticsearch logs (cluster is green), nothing in graylog, nothing in the journal, and I can event see the logs being processed and can manually perform a query and see that graylog is shipping the logs into the indices. For whatever reason though, the last log I am able to see is at 23:23. I’ve seen it before where it was a time zone issue, but if I go back 8 hours, and turn on live updates, i’m not even getting new messages popping in. The side bar where it states how many total messages were found in the past 8 hours is growing, but no new messages pop up into the messages feed. I’m assuming it has something to do with having to manually clear out the sessions from my MongoDB because I was getting the timeout error that doesn’t appear to have a solution to, referenced here https://github.com/Graylog2/graylog2-server/issues/2559.
Is there a point of reference/file that is telling graylog that message x is the last available message to search for or something?