firstly, many thanks for care & concern.
i’m very new to graylog & shall try to answer your questions as much as i could.
i installed Centos 7.x minimal
[root@Syslog_Trial ~]# cat /etc/centos-release
CentOS Linux release 7.4.1708 (Core)
–> then installed graylog (conf url below), elasticsearch, mongodb
https://pastebin.com/jGFwnKqu
[root@Syslog_Trial ~]# systemctl status syslog-ng.service
â— syslog-ng.service - System Logger Daemon
Loaded: loaded (/usr/lib/systemd/system/syslog-ng.service; enabled; vendor preset: enabled)
Active: active (running) since Mon 2017-11-20 20:50:16 EET; 1h 13min ago
Docs: man:syslog-ng(8)
Main PID: 12995 (syslog-ng)
CGroup: /system.slice/syslog-ng.service
└─12995 /usr/sbin/syslog-ng -F -p /var/run/syslogd.pid
Nov 20 20:50:16 Syslog_Trial systemd[1]: Starting System Logger Daemon…
Nov 20 20:50:16 Syslog_Trial systemd[1]: Started System Logger Daemon.
[root@Syslog_Trial ~]# /usr/bin/java -version
openjdk version “1.8.0_151”
OpenJDK Runtime Environment (build 1.8.0_151-b12)
OpenJDK 64-Bit Server VM (build 25.151-b12, mixed mode)
[root@Syslog_Trial ~]# systemctl status -l elasticsearch.service
â— elasticsearch.service - Elasticsearch
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: disabled)
Active: active (running) since Wed 2017-11-15 14:20:49 EET; 5 days ago
Docs: http://www.elastic.co
Main PID: 2551 (java)
CGroup: /system.slice/elasticsearch.service
└─2551 /bin/java -Xms2g -Xmx2g -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+AlwaysPreTouch -server -Xss1m -Djava.awt.headless=true -Dfile.encoding=UTF-8 -Djna.nosys=true -Djdk.io.permissionsUseCanonicalPath=true -Dio.netty.noUnsafe=true -Dio.netty.noKeySetOptimization=true -Dio.netty.recycler.maxCapacityPerThread=0 -Dlog4j.shutdownHookEnabled=false -Dlog4j2.disable.jmx=true -Dlog4j.skipJansi=true -XX:+HeapDumpOnOutOfMemoryError -Des.path.home=/usr/share/elasticsearch -cp /usr/share/elasticsearch/lib/* org.elasticsearch.bootstrap.Elasticsearch -p /var/run/elasticsearch/elasticsearch.pid --quiet -Edefault.path.logs=/var/log/elasticsearch -Edefault.path.data=/var/lib/elasticsearch -Edefault.path.conf=/etc/elasticsearch
Nov 15 14:20:49 Syslog_Trial systemd[1]: Starting Elasticsearch…
Nov 15 14:20:49 Syslog_Trial systemd[1]: Started Elasticsearch.
[root@Syslog_Trial ~]# mongod -version
db version v3.2.17
git version: 186656d79574f7dfe0831a7e7821292ab380f667
OpenSSL version: OpenSSL 1.0.1e-fips 11 Feb 2013
allocator: tcmalloc
modules: none
build environment:
distmod: rhel70
distarch: x86_64
target_arch: x86_64
[root@Syslog_Trial ~]# systemctl status -l mongod.service
â— mongod.service - SYSV: Mongo is a scalable, document-oriented database.
Loaded: loaded (/etc/rc.d/init.d/mongod; bad; vendor preset: disabled)
Active: active (running) since Wed 2017-11-15 13:20:53 EET; 5 days ago
Docs: man:systemd-sysv-generator(8)
CGroup: /system.slice/mongod.service
└─1442 /usr/bin/mongod -f /etc/mongod.conf
Nov 15 13:20:48 Syslog_Trial systemd[1]: Starting SYSV: Mongo is a scalable, document-oriented database…
Nov 15 13:20:48 Syslog_Trial runuser[1148]: pam_unix(runuser:session): session opened for user mongod by (uid=0)
Nov 15 13:20:53 Syslog_Trial mongod[1098]: Starting mongod: [ OK ]
Nov 15 13:20:53 Syslog_Trial systemd[1]: Started SYSV: Mongo is a scalable, document-oriented database…