Hi, today my GL installation stop to process message. I cant find anything from the last days in the log search. I’ve try to update GL to last 3.1.* stable version with no luck.
Elastichsearch status is ok, i can query old index message, but new message are not processed. Click on start or stop process message does nothing:
@matteolavaggi your journal has hit the full watermark, so Graylog won’t process any additional messages. What’s your disk utilization look like? I’m assuming it’s full, or very near full.
Hi, yesterday was full but i’ve rotate some index (es is on the same machine, i know is not a big setup but this is a temporary setup), but after rotating disk is not full:
Hello @matteolavaggi, just to be sure, is that space in the word “allow” in “read_only_allow_delete” there in the command you’re pasting into CLI? If so it’s not going to do what it should. Easy to overlook with tired eyes.
There is a node without any running inputs. (triggered 17 minutes ago)
There is a node without any running inputs. This means that you are not receiving any messages from this node at this point in time. This is most probably an indication of an error or misconfiguration. You can click here to solve this.
Port 1514 is not listening for income log . any idea?
You’re journal is 96% full with 67 million messages in it. the oldest is 15 minutes old… that means you are getting about 75k message per second. But you have 1GB of heap. you need more RAM… possibly more CPUs, but most likely both.
Message rate is not so high, i think this is an error on how graylog show the total message in journal and the oldest data count. Log rate is about 3-4 k every minutes
Also i found that 2/3 of total error related to log message come from ES read only option / allow delete. Why dont include a fix for this directly in graylog gui?