I’m stuck.
Single server seems installed properly. Successfully access port 9000 from any domain machine.
No server.log ERRORs.
Several different Windows servers collectors send NXLOG to Graylog.
Content Packs downloaded include Active Directory, DNS, HTTP Web, Security.
Setup some inputs, (Global: GELF TCP, GELF-UDP); (Local: GELF UDP, Syslog UDP, Raw/Plaintext UDP, GELF TCP)
Example:
org.graylog2.inputs.raw.udp.RawUDPInput.5b11aa2fd374f5042eaf57de.emptyMessages
org.graylog2.inputs.raw.udp.RawUDPInput.5b11aa2fd374f5042eaf57de.incomingMessages
Meter
Total: 0 events
Mean: 0 events/second
1 minute avg: 0 events/second
5 minute avg: 0 events/second
15 minute avg: 0 events/second
org.graylog2.inputs.raw.udp.RawUDPInput.5b11aa2fd374f5042eaf57de.org.graylog2.inputs.transports.UdpTransport.worker.executor-service.completed
Meter
Total: 0 events
Mean: 0 events/second
1 minute avg: 0 events/second
5 minute avg: 0 events/second
15 minute avg: 0 events/second
org.graylog2.inputs.raw.udp.RawUDPInput.5b11aa2fd374f5042eaf57de.org.graylog2.inputs.transports.UdpTransport.worker.executor-service.duration
org.graylog2.inputs.raw.udp.RawUDPInput.5b11aa2fd374f5042eaf57de.org.graylog2.inputs.transports.UdpTransport.worker.executor-service.running
org.graylog2.inputs.raw.udp.RawUDPInput.5b11aa2fd374f5042eaf57de.org.graylog2.inputs.transports.UdpTransport.worker.executor-service.submitted
Meter
Total: 8 events
Mean: 0 events/second
1 minute avg: 0 events/second
5 minute avg: 0 events/second
15 minute avg: 0.15 events/second
org.graylog2.inputs.raw.udp.RawUDPInput.5b11aa2fd374f5042eaf57de.rawSize
Need to setup a search and then display on dashboard, but am missing something because I don’t know where to begin from this point. I cannot locate concrete example from which I can extrapolate.