# WARN ProxiedRessource

**URL:** <https://community.graylog.org/t/warn-proxiedressource/3509>\
**Category:** Graylog Central (peer support)\
**Created:** [December 14, 2017, 4:08pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509 "2017-12-14T16:08:51Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Manuu](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@Manuu](https://community.graylog.org/u/Manuu)\
**Post date:** [December 14, 2017, 4:08pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/1 "2017-12-14T16:08:51Z")

</div>

Hello,

I have some problems configuring graylog and elasticsearch,

Graylog System information is unavailable and jvm 500 couldn’t load histogram data when I check api

My graylog log show this :

> WARN [ProxiedResource] Unable to call [http://GraylogIP:9000/api/system](http://GraylogIP:9000/api/system) on node \<e???-GraylogNode-???-???f\>  
> java.net.SocketTimeoutException: timeout  
> at okio.Okio$4.newTimeoutException(Okio.java:230) ~[graylog.jar:?]  
> at okio.AsyncTimeout.exit(AsyncTimeout.java:285) ~[graylog.jar:?]  
> at okio.AsyncTimeout$2.read(AsyncTimeout.java:241) ~[graylog.jar:?]  
> at okio.RealBufferedSource.indexOf(RealBufferedSource.java:345) ~[graylog.jar:?]  
> at okio.RealBufferedSource.readUtf8LineStrict(RealBufferedSource.java:217) ~[graylog.jar:?]  
> at okio.RealBufferedSource.readUtf8LineStrict(RealBufferedSource.java:211) ~[graylog.jar:?]  
> at okhttp3.internal.http1.Http1Codec.readResponseHeaders(Http1Codec.java:189) ~[graylog.jar:?]  
> at okhttp3.internal.http.CallServerInterceptor.intercept(CallServerInterceptor.java:75) ~[graylog.jar:?]  
> at okhttp3.internal.http.RealInterceptorChain.proceed(RealInterceptorChain.java:92) ~[graylog.jar:?]  
> at okhttp3.internal.connection.ConnectInterceptor.intercept(ConnectInterceptor.java:45) ~[graylog.jar:?]  
> at okhttp3.internal.http.RealInterceptorChain.proceed(RealInterceptorChain.java:92) ~[graylog.jar:?]  
> at okhttp3.internal.http.RealInterceptorChain.proceed(RealInterceptorChain.java:67) ~[graylog.jar:?]  
> at okhttp3.internal.cache.CacheInterceptor.intercept(CacheInterceptor.java:93) ~[graylog.jar:?]  
> at okhttp3.internal.http.RealInterceptorChain.proceed(RealInterceptorChain.java:92) ~[graylog.jar:?]  
> at okhttp3.internal.http.RealInterceptorChain.proceed(RealInterceptorChain.java:67) ~[graylog.jar:?]  
> at okhttp3.internal.http.BridgeInterceptor.intercept(BridgeInterceptor.java:93) ~[graylog.jar:?]  
> at okhttp3.internal.http.RealInterceptorChain.proceed(RealInterceptorChain.java:92) ~[graylog.jar:?]  
> at okhttp3.internal.http.RetryAndFollowUpInterceptor.intercept(RetryAndFollowUpInterceptor.java:120) ~[graylog.jar:?]  
> at okhttp3.internal.http.RealInterceptorChain.proceed(RealInterceptorChain.java:92) ~[graylog.jar:?]  
> at okhttp3.internal.http.RealInterceptorChain.proceed(RealInterceptorChain.java:67) ~[graylog.jar:?]  
> at org.graylog2.rest.RemoteInterfaceProvider.lambda$get$0(RemoteInterfaceProvider.java:59) ~[graylog.jar:?]  
> at okhttp3.internal.http.RealInterceptorChain.proceed(RealInterceptorChain.java:92) ~[graylog.jar:?]  
> at okhttp3.internal.http.RealInterceptorChain.proceed(RealInterceptorChain.java:67) ~[graylog.jar:?]  
> at okhttp3.RealCall.getResponseWithInterceptorChain(RealCall.java:185) ~[graylog.jar:?]  
> at okhttp3.RealCall.execute(RealCall.java:69) ~[graylog.jar:?]  
> at retrofit2.OkHttpCall.execute(OkHttpCall.java:180) ~[graylog.jar:?]  
> at org.graylog2.shared.rest.resources.ProxiedResource.lambda$getForAllNodes$0(ProxiedResource.java:76) ~[graylog.jar:?]  
> at java.util.concurrent.FutureTask.run(FutureTask.java:266) [?:1.8.0\_151]  
> at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) [?:1.8.0\_151]  
> at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) [?:1.8.0\_151]  
> at java.lang.Thread.run(Thread.java:748) [?:1.8.0\_151]  
> Caused by: java.net.SocketException: Socket closed  
> at java.net.SocketInputStream.read(SocketInputStream.java:204) ~[?:1.8.0\_151]  
> at java.net.SocketInputStream.read(SocketInputStream.java:141) ~[?:1.8.0\_151]  
> at okio.Okio$2.read(Okio.java:139) ~[graylog.jar:?]  
> at okio.AsyncTimeout$2.read(AsyncTimeout.java:237) ~[graylog.jar:?]  
> … 28 more

Here is my graylog server conf

> is\_master = true  
> node\_id\_file = /etc/graylog/server/node-id  
> password\_secret = mypass  
> root\_username = myname  
> root\_password\_sha2 = mysha2pass  
> root\_email = mymail  
> root\_timezone = Europe/Paris  
> plugin\_dir = /usr/share/graylog-server/plugin  
> rest\_listen\_uri = [http://0.0.0.0:9000/api](http://0.0.0.0:9000/api)  
> rest\_enable\_cors = true  
> web\_listen\_uri = [http://0.0.0.0:9000/](http://0.0.0.0:9000/)  
> elasticsearch\_hosts = [http://IPelaticsearch:9200](http://IPelaticsearch:9200), [http://IPels:9200](http://IPels:9200), [http://IPels:9200](http://IPels:9200)  
> rotation\_strategy = count  
> elasticsearch\_max\_docs\_per\_index = 20000000  
> elasticsearch\_max\_number\_of\_indices = 20  
> retention\_strategy = delete  
> elasticsearch\_shards = 4  
> elasticsearch\_replicas = 1  
> elasticsearch\_index\_prefix = graylog  
> allow\_leading\_wildcard\_searches = true  
> allow\_highlighting = false  
> elasticsearch\_analyzer = standard  
> output\_batch\_size = 500  
> output\_flush\_interval = 1  
> output\_fault\_count\_threshold = 5  
> output\_fault\_penalty\_seconds = 30  
> processbuffer\_processors = 8  
> outputbuffer\_processors = 5  
> processor\_wait\_strategy = blocking  
> ring\_size = 65536  
> inputbuffer\_ring\_size = 65536  
> inputbuffer\_processors = 2  
> inputbuffer\_wait\_strategy = blocking  
> message\_journal\_enabled = true  
> message\_journal\_dir = /var/lib/graylog-server/journal  
> lb\_recognition\_period\_seconds = 3  
> mongodb\_uri = mongodb://localhost/graylog  
> mongodb\_max\_connections = 1000  
> mongodb\_threads\_allowed\_to\_block\_multiplier = 5  
> content\_packs\_dir = /usr/share/graylog-server/contentpacks  
> content\_packs\_auto\_load = grok-patterns.json  
> proxied\_requests\_thread\_pool\_size = 32

the other params are commented by “#”

Graylog 2.3.2 is running on CentOS7 with mongodb on the same virtual machine (vsphere)  
There is 2 Master node Elasticsearch 5.5.2 and 1 slave.

Tell me if you need more informations,

I’ll be grateful if anyone can help

Regards

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [December 15, 2017, 10:46am UTC](https://community.graylog.org/t/warn-proxiedressource/3509/2 "2017-12-15T10:46:17Z")

</div>

Is `http://GraylogIP:9000/api/system` reachable for the Graylog node itself?  
What’s the output of the following command on the machine running Graylog?

```nohighlight
# curl -i http://GraylogIP:9000/api/system

```

---

<div class="post-metadata">

**Author:** ![Manuu](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@Manuu](https://community.graylog.org/u/Manuu)\
**Post date:** [December 15, 2017, 10:58am UTC](https://community.graylog.org/t/warn-proxiedressource/3509/3 "2017-12-15T10:58:48Z")

</div>

On the browser; [http://GraylogIP:9000/api/system](http://GraylogIP:9000/api/system) is reachable but I have to login with my graylog web ID and Password each time I try to connect

On graylog server the command return :  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/808f086287b265443ea75bfb98e366f86fab6d28.png)

Thanks a lot

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [December 15, 2017, 11:31am UTC](https://community.graylog.org/t/warn-proxiedressource/3509/4 "2017-12-15T11:31:13Z")

</div>

Is there only this one error message in the logs of your Graylog node or is this reproducible?

---

<div class="post-metadata">

**Author:** ![Manuu](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@Manuu](https://community.graylog.org/u/Manuu)\
**Post date:** [December 15, 2017, 11:41am UTC](https://community.graylog.org/t/warn-proxiedressource/3509/5 "2017-12-15T11:41:51Z")

</div>

I don’t know if it’s reproductible but yes it’s the only error message I have, it happens just after the gelf input started in the log

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [December 15, 2017, 11:59am UTC](https://community.graylog.org/t/warn-proxiedressource/3509/6 "2017-12-15T11:59:37Z")

</div>

In that case it’s possible that only this single request timed out and it’s nothing to worry about.

Keep an eye on the logs of your Graylog nodes and open a new topic if you have more questions.

---

<div class="post-metadata">

**Author:** ![Manuu](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@Manuu](https://community.graylog.org/u/Manuu)\
**Post date:** [December 15, 2017, 12:12pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/7 "2017-12-15T12:12:41Z")

</div>

After serverals reboot of all my servers, log are still the same,

The point is, I can’t see the Graylog Info  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/7/71b618b7ee6e43a395ffb362eb338ec3ac277626.png)

And when I click on the blue text, it shows this

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/e/e5cd6b7c6abd1a0b2de1b495f594de5c4c547a80.jpg)

Any ideas?

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [December 15, 2017, 12:34pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/8 "2017-12-15T12:34:30Z")

</div>

you might carefully read [http://docs.graylog.org/en/2.3/pages/configuration/server.conf.html#general](http://docs.graylog.org/en/2.3/pages/configuration/server.conf.html#general) and special the comment for `rest_transport_uri`:

> REST API transport address. Defaults to the value of rest\_listen\_uri. Exception: If rest\_listen\_uri is set to a wildcard IP address (0.0.0.0) the first non-loopback IPv4 system address is used.

---

<div class="post-metadata">

**Author:** ![Manuu](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@Manuu](https://community.graylog.org/u/Manuu)\
**Post date:** [December 15, 2017, 2:40pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/9 "2017-12-15T14:40:37Z")

</div>

Thanks jan

but, before I try several change on my configuration, no one of my server.conf IP addresses was on 0.0.0.0

I changed rest\_transport\_uri to [http://GraylogIP:9000/api](http://GraylogIP:9000/api) and the problem is still the same.

On the wait to read you,

Regards

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [December 18, 2017, 7:18am UTC](https://community.graylog.org/t/warn-proxiedressource/3509/10 "2017-12-18T07:18:06Z")

</div>

the configuration you provided to us included wildcards

```auto
rest_listen_uri = http://0.0.0.0:9000/api
web_listen_uri = http://0.0.0.0:9000/

```

Sorry if you modify the provided information in a way that it does not represent the environment, nobody can help you.

---

<div class="post-metadata">

**Author:** ![Manuu](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@Manuu](https://community.graylog.org/u/Manuu)\
**Post date:** [December 18, 2017, 1:40pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/11 "2017-12-18T13:40:08Z")

</div>

My apologies, that’s a mistake I should saw,

I correct that, so my last conf is :

web\_listen\_uri = [http://GraylogIP:9000/](http://GraylogIP:9000/)  
rest\_listen\_uri = [http://GraylogIP:9000/api](http://GraylogIP:9000/api)  
#rest\_transport\_uri = not set

The information are still unavailable

---

<div class="post-metadata">

**Author:** ![Manuu](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@Manuu](https://community.graylog.org/u/Manuu)\
**Post date:** [December 18, 2017, 3:48pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/12 "2017-12-18T15:48:45Z")

</div>

With API

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/f/fb602dccfcdf39b0db480be43dc43c194e32c529.png)

Is it possible that a bug happened when I converted graylog from virtual box to vmware?

Graylog seems like it can’t connect to itself

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [December 18, 2017, 3:58pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/13 "2017-12-18T15:58:44Z")

</div>

@Manuu

you name the problem yourself:

> Graylog seems like it can’t connect to itself

now you need to find the reason for that. Did you checked if SELinux or any kind of firewall is the reason?

---

<div class="post-metadata">

**Author:** ![Manuu](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@Manuu](https://community.graylog.org/u/Manuu)\
**Post date:** [December 18, 2017, 4:00pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/14 "2017-12-18T16:00:34Z")

</div>

SElinux is removed, and the firewall-cmd disabled

---

<div class="post-metadata">

**Author:** ![Manuu](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@Manuu](https://community.graylog.org/u/Manuu)\
**Post date:** [December 19, 2017, 1:35pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/15 "2017-12-19T13:35:53Z")

</div>

I’m trying to solve this issue since 2 weeks, I’m lost now, I don’t know what kind of test I can do or what params I can add…

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [December 19, 2017, 3:11pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/16 "2017-12-19T15:11:18Z")

</div>

> [@WARN ProxiedRessource](https://community.graylog.org/t/warn-proxiedressource/3509/13):
>
> @Manuu you name the problem yourself: Graylog seems like it can’t connect to itself now you need to find the reason for that. Did you checked if SELinux or any kind of firewall is the reason?

I did not like to play ping pong with you about all possible reasons why Graylog is not able to connect to itself. You need to find that yourself as we all can only guess the reason, but you are able to check.

---

<div class="post-metadata">

**Author:** ![Manuu](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@Manuu](https://community.graylog.org/u/Manuu)\
**Post date:** [December 19, 2017, 3:43pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/17 "2017-12-19T15:43:40Z")

</div>

Yes of course I understand that,

But I was just asking if maybe there is an hidden authentication in the graylog protocol to connect to itself or something else which required attention

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [January 2, 2018, 3:43pm UTC](https://community.graylog.org/t/warn-proxiedressource/3509/18 "2018-01-02T15:43:40Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
