Output for All Events stream is not working

Hi there,

We are running Graylog 4.1 with Splunk plugin configured as an output. We can forward messages from custom created streams to Splunk (as output); however, messages from “All Events” stream cannot be forwarded.
Is the “All Events” stream special and cannot be used for forwarding alerts through an output?

Hello && Welcome

I did a quick look and created an Output on All Events. Should be good and nothing special. Only thing that would be special is the Output with Enterprise next to it.

Hope that helps

We can create an output as well; however, it is not forwarding any alerts. We have installed the Splunk plugin and it can forward messages from any custom streams but not from “All Events” stream.

Moreover, I noticed that if I create a custom stream (clone of All Events) with index set to “Graylog Events” the new stream is not getting any alerts - even with All Events stopped.

Hmmmm, it seems there may be an issue with the plugin (see Graylog Splunk Plugin 0.4.0 with Graylog 3.2.2 not working) . I would recommend opening an issue on the repo with all of your deployment details.

I have the exact same issue - even using a normal Gelf output. No errors, but also nothing being sent to the output.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.