I get the Error Message
"Deflector exists as an index and is not an alias. "
which results in an empty search.
I have seen Threads about this and the way to go is to stop GRAYLOG and delete the index “graylog_deflector”.
I am not sure on how to delete the index graylog_deflector once the GRAYLOG Services are stopped.
You can delete an index named “graylog_deflector” with the following command (replace 127.0.0.1 with the actual IP address or hostname of the Elasticsearch node):
I am confused, entering this command gives me the following Error:
"Failed to connect to IP-ADDRESS port 9200: Connection refused"
I put in the IP of the GRAYLOG Server (on which I access the web-interface).
On elastic.co I see a download option for Elasticsearch. I think I never downloaded / installed Elasticsearch regarding GRAYLOG.
If I don’t have to install Elasticsearch seperately how do I find out the IP-ADRESS?
If you use the OVA/Virtual Appliance that includes all needed software. You would need to push that command on the command line of that server as Elasticsearch is not listening on the public interface.
Hey Jan,
Yes I used the OVA/Virtuel Appliance.
I am on the COmmand Line Interface of the Machine trying to enter the line mentioned above. No luck so far.
Also tried curl -X DELETE 127.0.0.1:9200/graylog_deflector