I just have installed a new plain graylog server on CentOS 7.4 (selinux and firewall disabled) based on the documentation here: http://docs.graylog.org/en/2.4/pages/installation/os/centos.html
I configured a plaintext input to send syslogs by test to create the correct extractor.
- With tcpdump I can see incoming messages,
- I see the messages in the messagejournal log
- The Default Index (System/Indices) set says: 1 Index 12,657 documents, 6.1MB
- The input shows incoming messages
But when I click in the Inputs on the input to Show received messages, it lasts forever and shows nothing!!!
When I click on “Manage extractors”/“Getting started”/Load Message"
I get only the error: Input did not return a recent message.
When I search all messages with star (enabled wildcard search in server.conf), nothing is returned.
Nothing in the logs. No error, or anything else. Based on the logs everything should be fine!
WHERE ARE ALL THESE MESSAGES!!!
Sorry, but I’m quite angry.
I hoped so that graylog is a professional product which works out of the box as expected, but I spendt the last hours in troubleshooting, although I had to do something completely different.