The server running graylogs/elasticsearch lost its NFS mount where the elasticsearch indicies are stored.
After a reboot of the server, almost everything is working fine, except the following:
DHCP messages are coming in on the input.
I see that the DHCP stream is receiving messages based on the stream page. The number is higher than zero.
When I enter the DHCP stream, there are no messages from after the reboot, but there are messages from before the reboot.
When I check the DHCP index, I see that the number of documents in the DHCP index are increasing.
I created a copy of the DHCP stream as DHCP stream 2. When I enter DHCP stream 2 I can see the current entries that are coming in. I can’t see the old entries, as expected.
How can I fix the original stream so that it shows old and new messages (and I assume all of the messages since the network issue since the messages are making it into the index).