Hi everyone, I have some issues with graylog sidecar. I connected domain controller to my graylog it is working and DC is sending messages via winlogbeat to graylog. However when I am checking graylog sidecar status on terminal it shows Failed.
Not sure I understand the approach here. What does the Graylog Sidecar service in the Graylog server has to do with the Domain Controller ?
If you have Sidecar installed on the domain controller, then you should check the Sidecar client logs on the Domain Controller (not the Graylog server).
per @H2Cyber’s point, you described connecting your Domain Controller to Graylog but you are showing sidecar information from the Graylog server…The sidecar installation only needs to be installed on the Domain Controller, it is not required on the Graylog server unless you are monitoring log files on the Graylog server.