Yes @Joel_Duffield . Before this post I looked for error messages in the graylog subsystem log. I even changed it to “errors” and “debug” to see if it enriched it more… But it didn’t give me any clues.
The error that now appears is this after processing the pipeline:
gl2_processing_error
Replaced invalid timestamp value in message <8a6e1e80-4dc6-11ee-85bf-02420a0a0a07> with current time - Value <2023-09-07T18:36:01-0300> caused exception: Invalid format: "2023-09-07T18:36:01-0300" is malformed at "T18:36:01-0300".
And in the logs, this:
But I think nothing explains here.
2023-09-07 17:26:04,701 INFO : org.graylog2.bootstrap.ServerBootstrap - Graylog server 5.1.4+6fa2de3 starting up
2023-09-07 17:26:04,703 INFO : org.graylog2.bootstrap.ServerBootstrap - JRE: Eclipse Adoptium 17.0.8 on Linux 5.15.0-25-generic
2023-09-07 17:26:04,704 INFO : org.graylog2.bootstrap.ServerBootstrap - Deployment: docker
2023-09-07 17:26:04,705 INFO : org.graylog2.bootstrap.ServerBootstrap - OS: Ubuntu 22.04.2 LTS (jammy)
2023-09-07 17:26:04,706 INFO : org.graylog2.bootstrap.ServerBootstrap - Arch: amd64
2023-09-07 17:26:04,836 INFO : org.graylog2.bootstrap.ServerBootstrap - Running 54 migrations...
2023-09-07 17:26:05,797 INFO : org.graylog2.shared.initializers.PeriodicalsService - Starting 26 periodicals ...
2023-09-07 17:26:05,798 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.ThroughputCalculator] periodical in [0s], polling every [1s].
2023-09-07 17:26:05,827 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog.plugins.pipelineprocessor.periodical.LegacyDefaultStreamMigration] periodical, running forever.
2023-09-07 17:26:05,845 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.BatchedElasticSearchOutputFlushThread] periodical in [0s], polling every [1s].
2023-09-07 17:26:05,858 INFO : org.graylog.plugins.pipelineprocessor.periodical.LegacyDefaultStreamMigration - Legacy default stream has no connections, no migration needed.
2023-09-07 17:26:05,875 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.ClusterHealthCheckThread] periodical in [120s], polling every [20s].
2023-09-07 17:26:05,900 INFO : org.graylog2.shared.initializers.PeriodicalsService - Not starting [org.graylog2.periodical.ContentPackLoaderPeriodical] periodical. Not configured to run on this node.
2023-09-07 17:26:05,901 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.IndexerClusterCheckerThread] periodical in [0s], polling every [30s].
2023-09-07 17:26:05,916 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.IndexBlockCheck] periodical in [0s], polling every [30s].
2023-09-07 17:26:05,992 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.IndexRetentionThread] periodical in [0s], polling every [300s].
2023-09-07 17:26:06,041 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.IndexRotationThread] periodical in [0s], polling every [10s].
2023-09-07 17:26:06,060 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.NodePingThread] periodical in [0s], polling every [1s].
2023-09-07 17:26:06,075 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.VersionCheckThread] periodical in [300s], polling every [1800s].
2023-09-07 17:26:06,088 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.ThrottleStateUpdaterThread] periodical in [1s], polling every [1s].
2023-09-07 17:26:06,098 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.events.ClusterEventPeriodical] periodical in [0s], polling every [1s].
2023-09-07 17:26:06,102 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.events.ClusterEventCleanupPeriodical] periodical in [0s], polling every [86400s].
2023-09-07 17:26:06,111 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.IndexRangesCleanupPeriodical] periodical in [15s], polling every [3600s].
2023-09-07 17:26:06,165 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.TrafficCounterCalculator] periodical in [0s], polling every [1s].
2023-09-07 17:26:06,192 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.indexer.fieldtypes.IndexFieldTypePollerPeriodical] periodical in [0s], polling every [1s].
2023-09-07 17:26:06,208 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog.scheduler.periodicals.ScheduleTriggerCleanUp] periodical in [120s], polling every [86400s].
2023-09-07 17:26:06,224 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.ESVersionCheckPeriodical] periodical in [0s], polling every [30s].
2023-09-07 17:26:06,258 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.periodical.UserSessionTerminationPeriodical] periodical, running forever.
2023-09-07 17:26:06,278 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog2.telemetry.cluster.TelemetryClusterInfoPeriodical] periodical in [0s], polling every [540s].
2023-09-07 17:26:06,280 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog.plugins.sidecar.periodical.PurgeExpiredSidecarsThread] periodical in [0s], polling every [600s].
2023-09-07 17:26:06,282 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog.plugins.sidecar.periodical.PurgeExpiredConfigurationUploads] periodical in [0s], polling every [600s].
2023-09-07 17:26:06,284 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog.plugins.views.search.db.SearchesCleanUpJob] periodical in [3600s], polling every [28800s].
2023-09-07 17:26:06,304 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog.events.periodicals.EventNotificationStatusCleanUp] periodical in [120s], polling every [86400s].
2023-09-07 17:26:06,319 INFO : org.graylog2.periodical.Periodicals - Starting [org.graylog.plugins.collector.periodical.PurgeExpiredCollectorsThread] periodical in [0s], polling every [3600s].
2023-09-07 17:26:08,376 INFO : org.glassfish.grizzly.http.server.NetworkListener - Started listener bound to [0.0.0.0:9000]
2023-09-07 17:26:08,377 INFO : org.glassfish.grizzly.http.server.HttpServer - [HttpServer] Started.
2023-09-07 17:26:08,378 INFO : org.graylog2.shared.initializers.JerseyService - Started REST API at <0.0.0.0:9000>
2023-09-07 17:26:08,379 INFO : org.graylog2.bootstrap.ServerBootstrap - Services started, startup times in ms: {LocalKafkaMessageQueueWriter [RUNNING]=0, PrometheusExporter [RUNNING]=4, UrlWhitelistService [RUNNING]=4, LocalKafkaJournal [RUNNING]=7, OutputSetupService [RUNNING]=8, ConfigurationEtagService [RUNNING]=11, FailureHandlingService [RUNNING]=11, InputSetupService [RUNNING]=12, EtagService [RUNNING]=17, LocalKafkaMessageQueueReader [RUNNING]=19, GracefulShutdownService [RUNNING]=21, UserSessionTerminationService [RUNNING]=24, BufferSynchronizerService [RUNNING]=26, MongoDBProcessingStatusRecorderService [RUNNING]=28, GeoIpDbFileChangeMonitorService [RUNNING]=48, JobSchedulerService [RUNNING]=52, StreamCacheService [RUNNING]=53, LookupTableService [RUNNING]=146, PeriodicalsService [RUNNING]=528, JerseyService [RUNNING]=2587}
2023-09-07 17:26:08,379 INFO : org.graylog2.shared.initializers.ServiceManagerListener - Services are healthy
2023-09-07 17:26:08,383 INFO : org.graylog2.bootstrap.ServerBootstrap - Graylog server up and running.
2023-09-07 17:26:08,384 INFO : org.graylog2.shared.initializers.InputSetupService - Triggering launching persisted inputs, node transitioned from Uninitialized [LB:DEAD] to Running [LB:ALIVE]
2023-09-07 17:26:08,451 INFO : org.graylog2.shared.inputs.InputLauncher - Launching input [Syslog UDP/sfos19/64d658ba5c1b4b3b03d8741f] - desired state is RUNNING
2023-09-07 17:26:08,479 INFO : org.graylog2.shared.inputs.InputLauncher - Launching input [Syslog UDP/fortos7/64f8a32845cec561bdc9c4b8] - desired state is RUNNING
2023-09-07 17:26:08,483 INFO : org.graylog2.inputs.InputStateListener - Input [Syslog UDP/sfos19/64d658ba5c1b4b3b03d8741f] is now STARTING
2023-09-07 17:26:08,487 INFO : org.graylog2.inputs.InputStateListener - Input [Syslog UDP/fortos7/64f8a32845cec561bdc9c4b8] is now STARTING
2023-09-07 17:26:08,722 INFO : org.graylog2.inputs.InputStateListener - Input [Syslog UDP/fortos7/64f8a32845cec561bdc9c4b8] is now RUNNING
2023-09-07 17:26:08,728 INFO : org.graylog2.inputs.InputStateListener - Input [Syslog UDP/sfos19/64d658ba5c1b4b3b03d8741f] is now RUNNING