Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.
Don’t forget to select tags to help index your topic!
1. Describe your incident:
I am integrating Graylog with wazuh indexer
The indexer working as expected.
2. Describe your environment:
-
OS Information:
hostnamectl
Static hostname: soclab
Icon name: computer-vm
Chassis: vm
Machine ID: b05f434d05e54eb08a2452dfc2b2d5a4
Boot ID: 23c2609e1cf142bf9e2cc033ca7edecd
Virtualization: vmware
Operating System: Ubuntu 20.04.5 LTS
Kernel: Linux 5.4.0-131-generic
Architecture: x86-64 -
Package Version:
-
Service logs, configurations, and environment variables:
3. What steps have you already taken to try and solve the problem?
here is log from graylog
2022-11-06T22:23:19.436Z INFO [ImmutableFeatureFlagsCollector] Following feature flags are used: {}
2022-11-06T22:23:20.672Z INFO [CmdLineTool] Loaded plugin: AWS plugins 4.3.9 [org.graylog.aws.AWSPlugin]
2022-11-06T22:23:20.673Z INFO [CmdLineTool] Loaded plugin: Integrations 4.3.9 [org.graylog.integrations.IntegrationsPlugin]
2022-11-06T22:23:20.675Z INFO [CmdLineTool] Loaded plugin: Collector 4.3.9 [org.graylog.plugins.collector.CollectorPlugin]
2022-11-06T22:23:20.676Z INFO [CmdLineTool] Loaded plugin: Threat Intelligence Plugin 4.3.9 [org.graylog.plugins.threatintel.ThreatIntelPlugin]
2022-11-06T22:23:20.677Z INFO [CmdLineTool] Loaded plugin: Elasticsearch 6 Support 4.3.9+e2c6648 [org.graylog.storage.elasticsearch6.Elasticsearch6Plugin]
2022-11-06T22:23:20.677Z INFO [CmdLineTool] Loaded plugin: Elasticsearch 7 Support 4.3.9+e2c6648 [org.graylog.storage.elasticsearch7.Elasticsearch7Plugin]
2022-11-06T22:23:20.713Z INFO [CmdLineTool] Running with JVM arguments: -Xms1g -Xmx1g -XX:NewRatio=1 -XX:+ResizeTLAB -XX:-OmitStackTraceInFastThrow -Djdk.tls.acknowledgeCloseNotify=true -Dlog4j2.formatMsgNoLookups=true -Djavax.net.ssl.trustStore=/etc/graylog/server/certs/cacerts -Djavax.net.ssl.trustStorePassword=changeit -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -Dlog4j.configurationFile=file:///etc/graylog/server/log4j2.xml -Djava.library.path=/usr/share/graylog-server/lib/sigar -Dgraylog2.installation_source=deb
2022-11-06T22:23:21.285Z INFO [PreflightCheckService] Skipping preflight checks
2022-11-06T22:23:21.427Z INFO [Version] HV000001: Hibernate Validator null
2022-11-06T22:23:24.796Z INFO [InputBufferImpl] Message journal is enabled.
2022-11-06T22:23:24.825Z INFO [NodeId] Node ID: a2a102fe-958d-4e68-93f9-c8d039c2069a
2022-11-06T22:23:25.121Z INFO [LogManager] Loading logs.
2022-11-06T22:23:25.189Z WARN [Log] Found a corrupted index file, /var/lib/graylog-server/journal/messagejournal-0/00000000000000000000.index, deleting and rebuilding index…
2022-11-06T22:23:25.241Z INFO [LogManager] Logs loading complete.
2022-11-06T22:23:25.245Z INFO [LocalKafkaJournal] Initialized Kafka based journal at /var/lib/graylog-server/journal
2022-11-06T22:23:25.288Z INFO [cluster] Cluster created with settings {hosts=[localhost:27017], mode=SINGLE, requiredClusterType=UNKNOWN, serverSelectionTimeout=‘30000 ms’, maxWaitQueueSize=5000}
2022-11-06T22:23:25.345Z INFO [cluster] Cluster description not yet available. Waiting for 30000 ms before timing out
2022-11-06T22:23:25.385Z INFO [connection] Opened connection [connectionId{localValue:1, serverValue:186}] to localhost:27017
2022-11-06T22:23:25.394Z INFO [cluster] Monitor thread successfully connected to server with description ServerDescription{address=localhost:27017, type=STANDALONE, state=CONNECTED, ok=true, version=ServerVersion{versionList=[4, 4, 17]}, minWireVersion=0, maxWireVersion=9, maxDocumentSize=16777216, logicalSessionTimeoutMinutes=30, roundTripTimeNanos=4006426}
2022-11-06T22:23:25.420Z INFO [connection] Opened connection [connectionId{localValue:2, serverValue:187}] to localhost:27017
2022-11-06T22:23:25.689Z INFO [InputBufferImpl] Initialized InputBufferImpl with ring size <65536> and wait strategy , running 2 parallel message handlers.
2022-11-06T22:23:26.065Z INFO [ElasticsearchVersionProvider] Elasticsearch version set to Elasticsearch:7.0.0 - disabling version probe.
2022-11-06T22:23:26.986Z INFO [ProcessBuffer] Initialized ProcessBuffer with ring size <65536> and wait strategy .
2022-11-06T22:23:27.095Z INFO [OutputBuffer] Initialized OutputBuffer with ring size <65536> and wait strategy .
2022-11-06T22:23:27.107Z INFO [connection] Opened connection [connectionId{localValue:3, serverValue:188}] to localhost:27017
2022-11-06T22:23:27.135Z INFO [connection] Opened connection [connectionId{localValue:4, serverValue:189}] to localhost:27017
2022-11-06T22:23:27.219Z INFO [connection] Opened connection [connectionId{localValue:5, serverValue:190}] to localhost:27017
2022-11-06T22:23:27.259Z INFO [connection] Opened connection [connectionId{localValue:6, serverValue:191}] to localhost:27017
2022-11-06T22:23:27.334Z INFO [connection] Opened connection [connectionId{localValue:7, serverValue:192}] to localhost:27017
2022-11-06T22:23:28.830Z INFO [ServerBootstrap] Graylog server 4.3.9+e2c6648 starting up
2022-11-06T22:23:28.843Z INFO [ServerBootstrap] JRE: Ubuntu 11.0.16 on Linux 5.4.0-131-generic
2022-11-06T22:23:28.843Z INFO [ServerBootstrap] Deployment: deb
2022-11-06T22:23:28.844Z INFO [ServerBootstrap] OS: Ubuntu 20.04.5 LTS (focal)
2022-11-06T22:23:28.844Z INFO [ServerBootstrap] Arch: amd64
2022-11-06T22:23:29.057Z INFO [ServerBootstrap] Running 46 migrations…
2022-11-06T22:23:30.501Z WARN [ServerBootstrap] Exception while running migrations
org.graylog.shaded.elasticsearch7.org.elasticsearch.ElasticsearchException: Unable to retrieve cluster information
at org.graylog.storage.elasticsearch7.ElasticsearchClient.exceptionFrom(ElasticsearchClient.java:151) ~[?:?]
at org.graylog.storage.elasticsearch7.ElasticsearchClient.execute(ElasticsearchClient.java:111) ~[?:?]
at org.graylog.storage.elasticsearch7.PlainJsonApi.perform(PlainJsonApi.java:38) ~[?:?]
at org.graylog.storage.elasticsearch7.NodeAdapterES7.version(NodeAdapterES7.java:41) ~[?:?]
at org.graylog2.indexer.cluster.Node.getVersion(Node.java:33) ~[graylog.jar:?]
at org.graylog2.migrations.V20170607164210_MigrateReopenedIndicesToAliases.getReopenedIndices(V20170607164210_MigrateReopenedIndicesToAliases.java:87) ~[graylog.jar:?]
at org.graylog2.migrations.V20170607164210_MigrateReopenedIndicesToAliases.getReopenedIndices(V20170607164210_MigrateReopenedIndicesToAliases.java:137) ~[graylog.jar:?]
at org.graylog2.migrations.V20170607164210_MigrateReopenedIndicesToAliases.lambda$upgrade$0(V20170607164210_MigrateReopenedIndicesToAliases.java:81) ~[graylog.jar:?]
at java.util.stream.ReferencePipeline$7$1.accept(ReferencePipeline.java:271) ~[?:?]
at java.util.stream.ReferencePipeline$3$1.accept(ReferencePipeline.java:195) ~[?:?]
at java.util.Collections$2.tryAdvance(Collections.java:4747) ~[?:?]
at java.util.Collections$2.forEachRemaining(Collections.java:4755) ~[?:?]
at java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:484) ~[?:?]
at java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:474) ~[?:?]
at java.util.stream.ForEachOps$ForEachOp.evaluateSequential(ForEachOps.java:150) ~[?:?]
at java.util.stream.ForEachOps$ForEachOp$OfRef.evaluateSequential(ForEachOps.java:173) ~[?:?]
at java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:234) ~[?:?]
at java.util.stream.ReferencePipeline.forEach(ReferencePipeline.java:497) ~[?:?]
at org.graylog2.migrations.V20170607164210_MigrateReopenedIndicesToAliases.upgrade(V20170607164210_MigrateReopenedIndicesToAliases.java:83) ~[graylog.jar:?]
at org.graylog2.bootstrap.ServerBootstrap.lambda$runMigrations$0(ServerBootstrap.java:264) ~[graylog.jar:?]
at com.google.common.collect.ImmutableList.forEach(ImmutableList.java:422) ~[graylog.jar:?]
at com.google.common.collect.RegularImmutableSortedSet.forEach(RegularImmutableSortedSet.java:88) ~[graylog.jar:?]
at org.graylog2.bootstrap.ServerBootstrap.runMigrations(ServerBootstrap.java:261) ~[graylog.jar:?]
at org.graylog2.bootstrap.ServerBootstrap.startCommand(ServerBootstrap.java:187) [graylog.jar:?]
at org.graylog2.bootstrap.CmdLineTool.run(CmdLineTool.java:312) [graylog.jar:?]
at org.graylog2.bootstrap.Main.main(Main.java:45) [graylog.jar:?]
Caused by: java.io.IOException: Host name ‘soclab.bb.local’ does not match the certificate subject provided by the peer (CN=soclab.bb.local, OU=Wazuh, O=Wazuh, L=California, C=US)
at org.graylog.shaded.elasticsearch7.org.elasticsearch.client.RestClient.extractAndWrapCause(RestClient.java:854) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.elasticsearch.client.RestClient.performRequest(RestClient.java:259) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.elasticsearch.client.RestClient.performRequest(RestClient.java:246) ~[?:?]
at org.graylog.storage.elasticsearch7.PlainJsonApi.lambda$perform$0(PlainJsonApi.java:40) ~[?:?]
at org.graylog.storage.elasticsearch7.ElasticsearchClient.execute(ElasticsearchClient.java:109) ~[?:?]
… 24 more
Caused by: javax.net.ssl.SSLPeerUnverifiedException: Host name ‘soclab.bb.local’ does not match the certificate subject provided by the peer (CN=soclab.bb.local, OU=Wazuh, O=Wazuh, L=California, C=US)
at org.graylog.shaded.elasticsearch7.org.apache.http.nio.conn.ssl.SSLIOSessionStrategy.verifySession(SSLIOSessionStrategy.java:209) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.apache.http.nio.conn.ssl.SSLIOSessionStrategy$1.verify(SSLIOSessionStrategy.java:188) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.apache.http.nio.reactor.ssl.SSLIOSession.doHandshake(SSLIOSession.java:360) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.apache.http.nio.reactor.ssl.SSLIOSession.outboundTransport(SSLIOSession.java:564) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.apache.http.impl.nio.reactor.AbstractIODispatch.outputReady(AbstractIODispatch.java:154) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.apache.http.impl.nio.reactor.BaseIOReactor.writable(BaseIOReactor.java:187) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.apache.http.impl.nio.reactor.AbstractIOReactor.processEvent(AbstractIOReactor.java:341) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.apache.http.impl.nio.reactor.AbstractIOReactor.processEvents(AbstractIOReactor.java:315) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.apache.http.impl.nio.reactor.AbstractIOReactor.execute(AbstractIOReactor.java:276) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.apache.http.impl.nio.reactor.BaseIOReactor.execute(BaseIOReactor.java:104) ~[?:?]
at org.graylog.shaded.elasticsearch7.org.apache.http.impl.nio.reactor.AbstractMultiworkerIOReactor$Worker.run(AbstractMultiworkerIOReactor.java:591) ~[?:?]
at java.lang.Thread.run(Thread.java:829) ~[?:?]
4. How can the community help?
Helpful Posting Tips: Tips for Posting Questions that Get Answers [Hold down CTRL and link on link to open tips documents in a separate tab]