Graylog Server version 4.1
Graylog Sidecar Version (windows): 1.1.0
Hello Graylog Forum,
I’ve successfully installed sidecar on my graylog server and configured it to talk to sidecar’s setup on my Windows and Linux Servers. I’ve also successfully installed the Windows Sidecar on a Windows 10 and Windows 2019 server and following the instructions on this page: Graylog Sidecar - Graylog Sidecar
I issued these commands in an elevated command prompt admin window to install the service:
“C:\Program Files\graylog\sidecar\graylog-sidecar.exe” - service install
The service does install and I set it to start automatically and the service is running. But in my Graylog > sidecar console I don’t see the server. The server status is Unknown and the error is that I’ve “Received no ping signal from sidecar”.
So looking at the documentation I see that I can start the service from the elevated command prompt so I issued this command:
“C:\Program Files\graylog\sidecar\graylog-sidecar.exe” - service start
In my Graylog console the server now shows up as running and logs are collected. BUT…the elevated command prompt does not close on my windows computer. The service was started. If I close the command prompt the service stops and my Graylog console again shows the windows computer as Unknown. So I went to my Services in the windows computer and started the service. The service shows as running but again my Graylog console shows the windows computer as Uknown.
So it appears the only way I can get my Windows sidecar services to connect to my Graylog server is to start the service with elevated rights. It seems I have a permissions or rights issue with how my windows sidecar service is run. I installed the windows sidecar with an account that is in the Administrator’s group. My windows service uses the local system account.
Any ideas from this community on where I need to make a change on my windows computers to get my service running properly and stay connected to my Graylog server?
Thank you in advance for any help you can provide me.