facyber
November 25, 2019, 9:45am
1
Hi everyone,
Can someone explain me what are Graylog Events and Graylog System Events indices that keeps creating automatically even after I delete them? Also streams All events and All system events ? There are no logs tho in these streams.
I think I did noticed first time when I tried setting up Sidecars, but I removed all Sidecars configurations.
Thanks,
facyber
shoothub
(Shoothub)
November 25, 2019, 9:55am
2
I think it is self explanatory, it’s system events, created by graylog.
For example All events are all events created by alert system:
https://docs.graylog.org/en/3.1/pages/streams/alerts.html#all-events-stream
facyber
November 25, 2019, 10:22am
3
So they will always be created no mater if you have Alerts or not? I don’t have any alerts nor Events Definitions configured.
jan
(Jan Doberstein)
November 25, 2019, 12:01pm
4
So they will always be created no mater if you have Alerts or not? I don’t have any alerts nor Events Definitions configured.
That is correct - because that is part of the base function of the system. The system ensure that all parts can be used without a problem.
1 Like
facyber
November 25, 2019, 12:14pm
5
I see. I am generally reading carefully every changelog of Graylog updates, but I guess I didn’t understood this one.
Thank you all for explanation, I will leave it as it is then.
Cheers!
system
(system)
Closed
December 9, 2019, 12:14pm
6
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.