# \#elastic

**URL:** https://community.graylog.org/tag/elastic/76.md

[Latest](https://community.graylog.org/latest.md) · [Categories](https://community.graylog.org/categories.md) · [Tags](https://community.graylog.org/tags.md)

---

## [Graylog can't connect to Wazuh Indexer](https://community.graylog.org/t/graylog-cant-connect-to-wazuh-indexer/37027)

<div class="topic-metadata">

**Author:** [@Sam\_Gunn](https://community.graylog.org/u/Sam_Gunn)\
**Replies:** 12\
**Last updated:** [March 5, 2026, 10:23am UTC](https://community.graylog.org/t/graylog-cant-connect-to-wazuh-indexer/37027 "2026-03-05T10:23:20Z")

</div>

1. Describe your incident: In trying to set up Graylog to connect to Wazuh Indexer, I am unable to get it to connect and create new indexes. I receive this error during preflight when launching the docker container for …

---

## [Error mapper\_parsing\_exception on gl2\_original\_timestamp after upgrading to 6.3.3](https://community.graylog.org/t/error-mapper-parsing-exception-on-gl2-original-timestamp-after-upgrading-to-6-3-3/36419)

<div class="topic-metadata">

**Author:** [@cklg](https://community.graylog.org/u/cklg)\
**Replies:** 4\
**Last updated:** [October 7, 2025, 11:41am UTC](https://community.graylog.org/t/error-mapper-parsing-exception-on-gl2-original-timestamp-after-upgrading-to-6-3-3/36419 "2025-10-07T11:41:33Z")

</div>

Hello Graylog community, I recently upgraded my Graylog instance from 6.1.8 (OpenSearch 2.15.0) to 6.3.3 (OpenSearch 2.19.3) and have a weird indexing error that I’m unable to solve, which seems to be linked to a date f…

---

## [Exporting graylog 6.0.7 configuration of linux](https://community.graylog.org/t/exporting-graylog-6-0-7-configuration-of-linux/34842)

<div class="topic-metadata">

**Author:** [@mohammad\_ramadan](https://community.graylog.org/u/mohammad_ramadan)\
**Replies:** 2\
**Last updated:** [August 17, 2025, 5:55am UTC](https://community.graylog.org/t/exporting-graylog-6-0-7-configuration-of-linux/34842 "2025-08-17T05:55:24Z")

</div>

I have deployed graylog 6 on ubuntu Linux 22, and working fine but due to storage issues i need to export all graylog configurations only such as dashboard, inputsand other rela5ed settings’" including required third p…

---

## [Delete a specific filed or log received](https://community.graylog.org/t/delete-a-specific-filed-or-log-received/35555)

<div class="topic-metadata">

**Author:** [@mohammad\_ramadan](https://community.graylog.org/u/mohammad_ramadan)\
**Replies:** 1\
**Last updated:** [May 8, 2025, 2:10am UTC](https://community.graylog.org/t/delete-a-specific-filed-or-log-received/35555 "2025-05-08T02:10:58Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Simultaneous support of Data Node (Opensearch) and elasticsearch\_hosts (Elasticsearch)](https://community.graylog.org/t/simultaneous-support-of-data-node-opensearch-and-elasticsearch-hosts-elasticsearch/35432)

<div class="topic-metadata">

**Author:** [@hyyrdbzm](https://community.graylog.org/u/hyyrdbzm)\
**Replies:** 1\
**Last updated:** [April 11, 2025, 1:41am UTC](https://community.graylog.org/t/simultaneous-support-of-data-node-opensearch-and-elasticsearch-hosts-elasticsearch/35432 "2025-04-11T01:41:24Z")

</div>

Hello. Question is about last Graylog - 6.1. Self-managed Elasticsearch 7.10.2 connected to it (elasticsearch\_hosts). I’m going to leave Elasticsearch “as is” for read-only logs and add Opensearch 2.12 as Data Node for w…

---

## [Issue's with Log Enrichment](https://community.graylog.org/t/issues-with-log-enrichment/35174)

<div class="topic-metadata">

**Author:** [@FlashComputingSec](https://community.graylog.org/u/FlashComputingSec)\
**Replies:** 1\
**Last updated:** [March 17, 2025, 10:23am UTC](https://community.graylog.org/t/issues-with-log-enrichment/35174 "2025-03-17T10:23:54Z")

</div>

To the Graylog community at large, I’ve been having issues with log enrichment. Specifically, I’ve been having issues with getting geolocation data to properly be enriched with my logs. And the goal and need for this dat…

---

## [We are trying to figure out a way to input defender logs to graylog](https://community.graylog.org/t/we-are-trying-to-figure-out-a-way-to-input-defender-logs-to-graylog/34847)

<div class="topic-metadata">

**Author:** [@CraftyBit88](https://community.graylog.org/u/CraftyBit88)\
**Replies:** 3\
**Last updated:** [February 4, 2025, 11:20pm UTC](https://community.graylog.org/t/we-are-trying-to-figure-out-a-way-to-input-defender-logs-to-graylog/34847 "2025-02-04T23:20:07Z")

</div>

We want to input defender logs to Graylog, but all I am seeing is information for using the enterprise edition of Graylog, which we do not have. Is there really no other way to get defender logs into Graylog? I have bee…

---

## [Issue with REST API](https://community.graylog.org/t/issue-with-rest-api/34629)

<div class="topic-metadata">

**Author:** [@nfonz23](https://community.graylog.org/u/nfonz23)\
**Replies:** 1\
**Last updated:** [January 9, 2025, 9:34am UTC](https://community.graylog.org/t/issue-with-rest-api/34629 "2025-01-09T09:34:05Z")

</div>

Hi, I am having an issue with the REST API. My query is: https://1.1.1.1:9000/api/search/universal/absolute?query=streams%3A621f6cd112205f090575c4a7&from=2025-01-08%2001%3A00%3A00&to=2025-01-08%2015%3A00%3A00&decorate=…

---

## [Node not working after enablind HTTPS](https://community.graylog.org/t/node-not-working-after-enablind-https/34551)

<div class="topic-metadata">

**Author:** [@renoturks](https://community.graylog.org/u/renoturks)\
**Replies:** 1\
**Last updated:** [December 30, 2024, 7:06am UTC](https://community.graylog.org/t/node-not-working-after-enablind-https/34551 "2024-12-30T07:06:31Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [I don't have Elasticsearch installed but I'm getting a watermark error](https://community.graylog.org/t/i-dont-have-elasticsearch-installed-but-im-getting-a-watermark-error/34513)

<div class="topic-metadata">

**Author:** [@Treshkin](https://community.graylog.org/u/Treshkin)\
**Replies:** 4\
**Last updated:** [December 27, 2024, 11:12am UTC](https://community.graylog.org/t/i-dont-have-elasticsearch-installed-but-im-getting-a-watermark-error/34513 "2024-12-27T11:12:06Z")

</div>

I have received this warning, but I am not even using or installing elasticsearch. “Elasticsearch nodes disk usage above low watermark (triggered 19 minutes ago) There are Elasticsearch nodes in the cluster running ou…

---

## [Need to compress logs older than month to save space](https://community.graylog.org/t/need-to-compress-logs-older-than-month-to-save-space/34527)

<div class="topic-metadata">

**Author:** [@mohammad\_ramadan](https://community.graylog.org/u/mohammad_ramadan)\
**Replies:** 2\
**Last updated:** [December 27, 2024, 6:34am UTC](https://community.graylog.org/t/need-to-compress-logs-older-than-month-to-save-space/34527 "2024-12-27T06:34:08Z")

</div>

1. Describe your the incident: I have too many logs that are eating the storage space, I need a way to compress indecied to save storage OS Information: Ubuntu Linux v 22 (64-bit) Package Version: graylog 6.0.7

---

## [Single graylog cluster with multiple nodes](https://community.graylog.org/t/single-graylog-cluster-with-multiple-nodes/34371)

<div class="topic-metadata">

**Author:** [@eurynome](https://community.graylog.org/u/eurynome)\
**Replies:** 1\
**Last updated:** [December 6, 2024, 12:27am UTC](https://community.graylog.org/t/single-graylog-cluster-with-multiple-nodes/34371 "2024-12-06T00:27:16Z")

</div>

Hey Guys! I am pretty new to Graylog, but trying really hard to understand it. I have a running graylog with the following setup: OS: Ubuntu 24 server x64 Graylog: Graylog 6.1.2 Elasticsearch: 7.17.24 MongoDB: 6.0.…

---

## [Process buffer and output buffer are full. Journal over the allowed size. No messages written to elastic](https://community.graylog.org/t/process-buffer-and-output-buffer-are-full-journal-over-the-allowed-size-no-messages-written-to-elastic/33737)

<div class="topic-metadata">

**Author:** [@chimi](https://community.graylog.org/u/chimi)\
**Replies:** 2\
**Last updated:** [October 4, 2024, 12:29pm UTC](https://community.graylog.org/t/process-buffer-and-output-buffer-are-full-journal-over-the-allowed-size-no-messages-written-to-elastic/33737 "2024-10-04T12:29:46Z")

</div>

Describe your incident: I’m running 4 instances of Graylog nodes 5.0.5 managed by load balancer and 5 instances of ElasticSearch. Those four nodes are not sending messages to elasticsearch and there are a lot of messag…

---

## [Messages are lost when sending via udp/tcp gelf](https://community.graylog.org/t/messages-are-lost-when-sending-via-udp-tcp-gelf/33549)

<div class="topic-metadata">

**Author:** [@Aleksandr](https://community.graylog.org/u/Aleksandr)\
**Replies:** 5\
**Last updated:** [September 29, 2024, 2:34pm UTC](https://community.graylog.org/t/messages-are-lost-when-sending-via-udp-tcp-gelf/33549 "2024-09-29T14:34:06Z")

</div>

1. Describe your incident: I’m load testing Graylog. I use local deployment of components on my computer. Docker-compose is used to run Graylog locally version: "3.8" services: mongodb: image: "mongo:4.4.6" …

---

## [Error activation INPUT](https://community.graylog.org/t/error-activation-input/33650)

<div class="topic-metadata">

**Author:** [@arielmc](https://community.graylog.org/u/arielmc)\
**Replies:** 1\
**Last updated:** [September 26, 2024, 7:03am UTC](https://community.graylog.org/t/error-activation-input/33650 "2024-09-26T07:03:43Z")

</div>

Well Good morning, good afternoon and good night for everybody. I’m actually trying to launch a small laboratory, to test de log data collection capabillities of graylog. 1. Describe your incident: When i try to launc…

---

## [Configuring HTTPS on graylog vervsion 6 on ubuntu server 22.04.5 LTS](https://community.graylog.org/t/configuring-https-on-graylog-vervsion-6-on-ubuntu-server-22-04-5-lts/33604)

<div class="topic-metadata">

**Author:** [@Philippe1](https://community.graylog.org/u/Philippe1)\
**Replies:** 0\
**Last updated:** [September 20, 2024, 1:15pm UTC](https://community.graylog.org/t/configuring-https-on-graylog-vervsion-6-on-ubuntu-server-22-04-5-lts/33604 "2024-09-20T13:15:41Z")

</div>

Hello all, ihave started using graylog for some months now and i wish to get more knowledge about this tool. Then i am actually having a local lab. I installed graylog version 6 with all its pre-requisites on ubuntu 2…

---

## [try to conect Wazuh indexer 4.8 SSL error graylog 6.0 ](https://community.graylog.org/t/try-to-conect-wazuh-indexer-4-8-ssl-error-graylog-6-0/33486)

<div class="topic-metadata">

**Author:** [@kmykcdark](https://community.graylog.org/u/kmykcdark)\
**Replies:** 0\
**Last updated:** [September 10, 2024, 2:00pm UTC](https://community.graylog.org/t/try-to-conect-wazuh-indexer-4-8-ssl-error-graylog-6-0/33486 "2024-09-10T14:00:12Z")

</div>

Hi Community i try to conect wazuh indexer version 4.8 to graylog for HTTPS, BUT have a big error. context in my graylog server conf have this configuration : instances as leader. The leader will perform some periodic…

---

## [Elasticsearch:8.4.0 and graylog:5.1.1](https://community.graylog.org/t/elasticsearch-8-4-0-and-graylog-5-1-1/33151)

<div class="topic-metadata">

**Author:** [@balarimpy](https://community.graylog.org/u/balarimpy)\
**Replies:** 5\
**Last updated:** [July 31, 2024, 4:42am UTC](https://community.graylog.org/t/elasticsearch-8-4-0-and-graylog-5-1-1/33151 "2024-07-31T04:42:59Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [AWS Opensearch analyzing old data](https://community.graylog.org/t/aws-opensearch-analyzing-old-data/33085)

<div class="topic-metadata">

**Author:** [@broerman](https://community.graylog.org/u/broerman)\
**Replies:** 0\
**Last updated:** [July 25, 2024, 11:49am UTC](https://community.graylog.org/t/aws-opensearch-analyzing-old-data/33085 "2024-07-25T11:49:51Z")

</div>

Hello we run a Graylogcluster in AWS with 3 ec2 Graylognodes , 3 ec2 Mongodb Nodes and a managed AWS OpenSearch Service \[OSS\]. OSS has 3 Data nodes for HOT and 3 Ultrawarm Data nodes for WARM and COLD indices. With …

---

## [Deflector exists as an index and is not an alias Error](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-error/32872)

<div class="topic-metadata">

**Author:** [@Primax98](https://community.graylog.org/u/Primax98)\
**Replies:** 2\
**Last updated:** [July 1, 2024, 12:06pm UTC](https://community.graylog.org/t/deflector-exists-as-an-index-and-is-not-an-alias-error/32872 "2024-07-01T12:06:19Z")

</div>

Hi all, i would consider myself still much of a novice with GL and had a few issues over the last week where my GL cluster was not working well. MEssages received but not processes and the GL cluster was permanently Red.…

---

## [Graylog 6.0.3 index.refresh\_interval](https://community.graylog.org/t/graylog-6-0-3-index-refresh-interval/32775)

<div class="topic-metadata">

**Author:** [@gowen](https://community.graylog.org/u/gowen)\
**Replies:** 1\
**Last updated:** [June 20, 2024, 3:02pm UTC](https://community.graylog.org/t/graylog-6-0-3-index-refresh-interval/32775 "2024-06-20T15:02:51Z")

</div>

Hi, I just did a fresh install of Graylog 6.0.3, installing everything on a single server. Now that we are moving forward, I have been requested to use AWS Opensearch instead of the opensearch install I had on EC2. Th…

---

## [Upgraded server to 5.2.8.1 now it will not launch](https://community.graylog.org/t/upgraded-server-to-5-2-8-1-now-it-will-not-launch/32755)

<div class="topic-metadata">

**Author:** [@the\_tree](https://community.graylog.org/u/the_tree)\
**Replies:** 10\
**Last updated:** [June 19, 2024, 3:19am UTC](https://community.graylog.org/t/upgraded-server-to-5-2-8-1-now-it-will-not-launch/32755 "2024-06-19T03:19:08Z")

</div>

I upgraded our server to 5.2.8.1 and it will not launch The server log shows 2024-06-18T16:36:00.934-07:00 ERROR \[Messages\] Caught exception during bulk indexing: ElasticsearchException{message=ElasticsearchException\[A…

---

## [Failed to migrate from Graylog Enterprise 5.2.4 to 6.0](https://community.graylog.org/t/failed-to-migrate-from-graylog-enterprise-5-2-4-to-6-0/32478)

<div class="topic-metadata">

**Author:** [@Tecknoth](https://community.graylog.org/u/Tecknoth)\
**Replies:** 2\
**Last updated:** [May 23, 2024, 6:22am UTC](https://community.graylog.org/t/failed-to-migrate-from-graylog-enterprise-5-2-4-to-6-0/32478 "2024-05-23T06:22:49Z")

</div>

Hello, Graylog doesnt start after having upgraded its version from 5.2.4 to 6.0.1, with the error hereafter visible in the logs. We are using Graylog Enterprise, running it on Ubuntu 20.04 focal with ElasticSearch 7.10…

---

## [Elasticsearch support for Graylog 6.0](https://community.graylog.org/t/elasticsearch-support-for-graylog-6-0/32322)

<div class="topic-metadata">

**Author:** [@bettels-uhi](https://community.graylog.org/u/bettels-uhi)\
**Replies:** 2\
**Last updated:** [May 7, 2024, 1:34pm UTC](https://community.graylog.org/t/elasticsearch-support-for-graylog-6-0/32322 "2024-05-07T13:34:52Z")

</div>

Hi, since I couldn’t find a reference for elasticsearch on the installation documentation for Graylog 6.0, has the support for Elasticsearch been dropped? Will elasticsearch 7.10.2 still work or do we need to migrate al…

---

## [Error: \[VersionProbe\] Unable to retrieve version from Elasticsearch in a GL running Opensearch instead](https://community.graylog.org/t/error-versionprobe-unable-to-retrieve-version-from-elasticsearch-in-a-gl-running-opensearch-instead/32302)

<div class="topic-metadata">

**Author:** [@SaukInfraNOC](https://community.graylog.org/u/SaukInfraNOC)\
**Replies:** 2\
**Last updated:** [May 7, 2024, 1:29am UTC](https://community.graylog.org/t/error-versionprobe-unable-to-retrieve-version-from-elasticsearch-in-a-gl-running-opensearch-instead/32302 "2024-05-07T01:29:19Z")

</div>

1. Describe your incident: Basically, i had created my environment by Ansible, and when i tried bringing up the graylog in the target server, he shows me the error saying that is impossible to find the Elasticsearch ins…

---

## [Search issue with double colons](https://community.graylog.org/t/search-issue-with-double-colons/32159)

<div class="topic-metadata">

**Author:** [@intpdm](https://community.graylog.org/u/intpdm)\
**Replies:** 3\
**Last updated:** [April 19, 2024, 12:13pm UTC](https://community.graylog.org/t/search-issue-with-double-colons/32159 "2024-04-19T12:13:32Z")

</div>

Hi. Are there any restrictions on searching in graylog? Because i tried to find message with text having double colons ( :: ) and not get any results, but if i look by timestamp i can see it. There is no errors in gra…

---

## [Graylog send log forwarder to logstash](https://community.graylog.org/t/graylog-send-log-forwarder-to-logstash/31981)

<div class="topic-metadata">

**Author:** [@thanarat](https://community.graylog.org/u/thanarat)\
**Replies:** 1\
**Last updated:** [April 4, 2024, 2:55am UTC](https://community.graylog.org/t/graylog-send-log-forwarder-to-logstash/31981 "2024-04-04T02:55:32Z")

</div>

Hi I would like to use Graylog forwarder log to Logstash. Has anyone ever done this? Now I’m encountering this error. The output cannot be connected to Logstash. Graylog version Graylog 5.1.5+993cd0f

---

## [Reindexing automatically for migration from Elastic 6.8 (indices) to OpenSearch](https://community.graylog.org/t/reindexing-automatically-for-migration-from-elastic-6-8-indices-to-opensearch/31990)

<div class="topic-metadata">

**Author:** [@TechSys](https://community.graylog.org/u/TechSys)\
**Replies:** 1\
**Last updated:** [April 4, 2024, 2:50am UTC](https://community.graylog.org/t/reindexing-automatically-for-migration-from-elastic-6-8-indices-to-opensearch/31990 "2024-04-04T02:50:53Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [This site can’t be reached took too long to respond](https://community.graylog.org/t/this-site-can-t-be-reached-took-too-long-to-respond/31964)

<div class="topic-metadata">

**Author:** [@Malcolm](https://community.graylog.org/u/Malcolm)\
**Replies:** 5\
**Last updated:** [April 3, 2024, 9:42pm UTC](https://community.graylog.org/t/this-site-can-t-be-reached-took-too-long-to-respond/31964 "2024-04-03T21:42:02Z")

</div>

Hello, I installed graylog 5 in june 2023. Running with mongo v6.0.6 and elasticsearch 7.10.2 on Rocky Linux 9 It was working perfectly. Using NXLOG and I configured input with TLS. Now, the web interface does not re…

---

## [Help with clusters; multi-elastisearch (opensearch) vs multi-graylog clusters](https://community.graylog.org/t/help-with-clusters-multi-elastisearch-opensearch-vs-multi-graylog-clusters/32014)

<div class="topic-metadata">

**Author:** [@Errand0596](https://community.graylog.org/u/Errand0596)\
**Replies:** 7\
**Last updated:** [April 3, 2024, 3:44pm UTC](https://community.graylog.org/t/help-with-clusters-multi-elastisearch-opensearch-vs-multi-graylog-clusters/32014 "2024-04-03T15:44:50Z")

</div>

1. Describe your incident: I am looking for general guidance on clusters and am confused. I’m referencing this doc: https://graylog.org/post/back-to-basics-from-single-server-to-graylog-cluster/ But almost every link …

[Next page](https://community.graylog.org/tag/elastic/76.md?match_all_tags=true&page=1&tags%5B%5D=elastic)
