I set up graylog virtual image and trying to get the DNS queries as I have setup sinkhole. However when I am going to set up dashboard it consistently shows error as IP address already in use and unable to see any data on dashboard as connector does not start.
Even then I tried building from scratch on CentOS 7 and its the same issue.
Not sure why this happening, Can someone pls help?
My apologies for delay in response, we have a community based DNS Sink hole appliance and they have built their own plugins to import the data into Graylog but somehow I am still getting error as specified above, It says IP address is already assigned. I tried multiple desktops, multiple variants but one thing is I have tried on vmware workstation since I do not have physical machine.
Nope …I am network expert and I am 200% sure that I have not configured ip address which is already used.
This is showing the same error with Virtual appliance as well as when installed on CentOS 7.
BTW just off this chat. Can I use Graylog for SIEM kind of a fucntion? That means collect logs from firewall, syslog, IDS, OSSEC correlate and present it into good dashboard? Or is it just a log management solution?