I configured a plaintext input to send syslogs by test to create the correct extractor.
With tcpdump I can see incoming messages,
I see the messages in the messagejournal log
The Default Index (System/Indices) set says: 1 Index 12,657 documents, 6.1MB
The input shows incoming messages
But when I click in the Inputs on the input to Show received messages, it lasts forever and shows nothing!!!
When I click on “Manage extractors”/“Getting started”/Load Message"
I get only the error: Input did not return a recent message.
When I search all messages with star (enabled wildcard search in server.conf), nothing is returned.
Nothing in the logs. No error, or anything else. Based on the logs everything should be fine!
WHERE ARE ALL THESE MESSAGES!!!
Sorry, but I’m quite angry.
I hoped so that graylog is a professional product which works out of the box as expected, but I spendt the last hours in troubleshooting, although I had to do something completely different.
I would start by checking the date and time on both the Graylog server and the server sending messages to Graylog, since wrong times may sometimes set “wrong” timestamps either in the past or future that may not show up in searches. You could also try looking for those messages by using an absolute timerange and being quite generous with both from and to time ranges.
In case that doesn’t help, please share with us example messages you are sending to Graylog, as well as Graylog and ES logs that appear while those messages are being sent to the server. In that way we have more information to be able to help with the issue you are experiencing.
Opend Browser Console an got the follwoing javascript error when go to System/Inputs and click on show received inputs:
[Sorry, I would like to give you the trace but Your system says: New Users are allowed only to send two Links in a post], and uploading a text file is also not allowed!
Just tried it with the ovf appliance. Same result.
I think I stop this experiment here. Seems not to make sense to spend another lot of time just to get it initially running.