Welcome to the Graylog documentation¶
NOTE: There are multiple options for reading this documentation. See link to the lower left.
Graylog
- Architectural considerations
- Getting Started
- Installing Graylog
- Upgrading Graylog
- Upgrading to Graylog 2.0.x
- Upgrading to Graylog 2.1.x
- Upgrading to Graylog 2.2.x
- Upgrading to Graylog 2.3.x
- Upgrading to Graylog 2.4.x
- Upgrading to Graylog 2.5.x
- Upgrading to Graylog 3.0.x
- Elasticsearch Version Requirements
- Simplified HTTP interface configuration
- Plugins merged into the Graylog server
- New “bin_dir” and “data_dir” configuration parameters
- Removed support for Drools-based filters
- Changed metrics name for stream rules
- Email alarm callback default settings
- Collector Sidecar is deprecated
- Legacy Content Packs
- Elasticsearch 6 changes
- Upgrading to Graylog 3.1.x
- Upgrading to Graylog 3.2.x
- Upgrading to Graylog 3.3.x
- Upgrading to Graylog 4.0.x
- Upgrading Graylog Originally Installed from Image
- Upgrading Graylog Originally Installed from Package
- Upgrading Elasticsearch
- Configuring Graylog
- server.conf
- Web interface
- Load balancer integration
- Using HTTPS
- Things to consider
- Certificate/Key file format
- Creating a self-signed private key/certificate
- Converting a PKCS #12 (PFX) file to private key and certificate pair
- Converting an existing Java Keystore to private key/certificate pair
- Sample files
- Adding a self-signed certificate to the JVM trust store
- Multi-node Setup
- Elasticsearch
- Index model
- Backup
- Default file locations
- Graylog REST API
- Securing Graylog
- Sending in log data
- Graylog Sidecar
- Searching
- Streams
- Alerts
- Dashboards
- Extractors
- Processing Pipelines
- Lookup Tables
- Geolocation
- Setup
- Visualize geolocations in a map
- FAQs
- Will Graylog extract IPs from all fields?
- What geo-information is extracted from IPs?
- Where is the extracted geo-information stored?
- Which geo-points format does Graylog use to store coordinates?
- I have a field in my messages with coordinates information already, can I use it in Graylog?
- Not all fields containing IP addresses are resolved. Why does this happen?
- Indexer failures
- Permission Management
- Plugins
- Content Packs
- Graylog Marketplace
- Frequently asked questions
- General
- Architecture
- What is MongoDB used for?
- Can you guide me on how to replicate MongoDB for High Availability?
- I have datacenters across the world and do not want logs forwarding from everywhere to a central location due to bandwidth, etc. How do I handle this?
- Which load balancers do you recommend we use with Graylog?
- Isn’t Java slow? Does it need a lot of memory?
- Does Graylog encrypt log data?
- Where are the log files Graylog produces?
- Installation / Setup
- Functionality
- Can Graylog automatically clean old data?
- Does Graylog support LDAP / Active Directory and its groups?
- Do we have a user audit log for compliance?
- Does Graylog have reporting functionality?
- Can I filter inbound messages before they are processed by the Graylog server?
- Dedicated Partition for the Journal
- Raise the Java Heap
- How can I start an input on a port below 1024?
- Graylog & Integrations
- What is the best way to integrate my applications to Graylog?
- I have a log source that creates dynamic syslog messages based on events and subtypes and grok patterns are difficult to use - what is the best way to handle this?
- I want to archive my log data. Can I write to another database, for example HDFS / Hadoop, from Graylog?
- I don’t want to use Elasticsearch as my backend storage system – can I use another database, like MySQL, Oracle, etc?
- How can I create a restricted user to check internal Graylog metrics in my monitoring system?
- Troubleshooting
- I’m sending in messages, and I can see they are being accepted by Graylog, but I can’t see them in the search. What is going wrong?
- I have configured an SMTP server or an output with TLS connection and receive handshake errors. What should I do?
- Suddenly parts of Graylog did not work as expected
- I cannot go past page 66 in search results
- My field names contain dots and stream alerts do not match anymore
- What does “Uncommited messages deleted from journal” mean?
- What does “Journal utilization is too high” mean?
- How do I fix the “Deflector exists as an index and is not an alias” error message?
- How do I enable debug logging for a specific plugin or area of Graylog?
- Have another troubleshooting question?
- Support
- The thinking behind the Graylog architecture and why it matters to you
- Changelog
- Graylog 4.0.5
- Graylog 4.0.4
- Graylog 4.0.3
- Graylog 4.0.2
- Graylog 4.0.1
- Graylog 4.0.0
- Graylog 3.3.11
- Graylog 3.3.10
- Graylog 3.3.9
- Graylog 3.3.8
- Graylog 3.3.7
- Graylog 3.3.6
- Graylog 3.3.5
- Graylog 3.3.4
- Graylog 3.3.3
- Graylog 3.3.2
- Graylog 3.3.1
- Graylog 3.3.0
- Graylog 3.2.6
- Graylog 3.2.5
- Graylog 3.2.4
- Graylog 3.2.3
- Graylog 3.2.2
- Graylog 3.2.1
- Graylog 3.2.0
- Graylog 3.1.4
- Graylog 3.1.3
- Graylog 3.1.2
- Graylog 3.1.1
- Graylog 3.1.0
- Graylog 3.0.2
- Graylog 3.0.1
- Graylog 3.0.0
- Graylog 2.5.2
- Graylog 2.5.1
- Graylog 2.5.0
- Graylog 2.4.7
- Graylog 2.4.6
- Graylog 2.4.5
- Graylog 2.4.4
- Graylog 2.4.3
- Graylog 2.4.2
- Graylog 2.4.1
- Graylog 2.4.0
- Graylog 2.4.0-rc.2
- Graylog 2.4.0-rc.1
- Graylog 2.4.0-beta.4
- Graylog 2.4.0-beta.3
- Graylog 2.4.0-beta.2
- Graylog 2.4.0-beta.1
- Graylog 2.3.2
- Graylog 2.3.1
- Graylog 2.3.0
- Graylog 2.2.3
- Graylog 2.2.2
- Graylog 2.2.1
- Graylog 2.2.0
- Graylog 2.1.3
- Graylog 2.1.2
- Graylog 2.1.1
- Graylog 2.1.0
- Graylog 2.0.3
- Graylog 2.0.2
- Graylog 2.0.1
- Graylog 2.0.0
- Graylog 1.3.4
- Graylog 1.3.3
- Graylog 1.3.2
- Graylog 1.3.1
- Graylog 1.3.0
- Graylog 1.2.2
- Graylog 1.2.1
- Graylog 1.2.0
- Graylog 1.2.0-rc.4
- Graylog 1.2.0-rc.2
- Graylog 1.1.6
- Graylog 1.1.5
- Graylog 1.1.4
- Graylog 1.1.3
- Graylog 1.1.2
- Graylog 1.1.1
- Graylog 1.1.0
- Graylog 1.1.0-rc.3
- Graylog 1.1.0-rc.1
- Graylog 1.1.0-beta.3
- Graylog 1.1.0-beta.2
- Graylog 1.0.2
- Graylog 1.0.1
- Graylog 1.0.0
- Graylog 1.0.0-rc.4
- Graylog 1.0.0-rc.3
- Graylog 1.0.0-rc.2
- Graylog 1.0.0-rc.1
- Graylog 1.0.0-beta.2
- Graylog 1.0.0-beta.2
- Graylog2 0.92.4
- Graylog 1.0.0-beta.1
- Graylog2 0.92.3
- Graylog2 0.92.1
- Graylog2 0.92.0
- Graylog2 0.92.0-rc.1
- Graylog2 0.91.3
- Graylog2 0.91.3
- Graylog2 0.92.0-beta.1
- Graylog2 0.91.1
- Graylog2 0.90.1
- Graylog2 0.91.0-rc.1
- Graylog2 0.90.0
- Graylog2 0.20.3
- Graylog2 0.20.2
Graylog Enterprise
- Introduction
- Setup
- Archiving
- Audit Log
- Reporting
- License
- Changelog
- Graylog Enterprise 4.0.5
- Graylog Enterprise 4.0.4
- Graylog Enterprise 4.0.3
- Graylog Enterprise 4.0.2
- Graylog Enterprise 4.0.1
- Graylog Enterprise 4.0.0
- Graylog Enterprise 3.3.11
- Graylog Enterprise 3.3.10
- Graylog Enterprise 3.3.9
- Graylog Enterprise 3.3.8
- Graylog Enterprise 3.3.7
- Graylog Enterprise 3.3.6
- Graylog Enterprise 3.3.5
- Graylog Enterprise 3.3.4
- Graylog Enterprise 3.3.3
- Graylog Enterprise 3.3.2
- Graylog Enterprise 3.3.1
- Graylog Enterprise 3.3.0
- Graylog Enterprise 3.2.6
- Graylog Enterprise 3.2.5
- Graylog Enterprise 3.2.4
- Graylog Enterprise 3.2.3
- Graylog Enterprise 3.2.2
- Graylog Enterprise 3.2.1
- Graylog Enterprise 3.2.0
- Graylog Enterprise 3.1.4
- Graylog Enterprise 3.1.3
- Graylog Enterprise 3.1.2
- Graylog Enterprise 3.1.1
- Graylog Enterprise 3.1.0
- Graylog Enterprise 3.0.2
- Graylog Enterprise 3.0.1
- Graylog Enterprise 3.0.0
- Graylog Enterprise 2.5.2
- Graylog Enterprise 2.5.1
- Graylog Enterprise 2.5.0
- Graylog Enterprise 2.4.7
- Graylog Enterprise 2.4.6
- Graylog Enterprise 2.4.5
- Graylog Enterprise 2.4.4
- Graylog Enterprise 2.4.3
- Graylog Enterprise 2.4.2
- Graylog Enterprise 2.4.1
- Graylog Enterprise 2.4.0
- Graylog Enterprise 2.4.0-rc.2
- Graylog Enterprise 2.4.0-rc.1
- Graylog Enterprise 2.4.0-beta.4
- Graylog Enterprise 2.4.0-beta.3
- Graylog Enterprise 2.4.0-beta.2
- Graylog Enterprise 2.4.0-beta.1
- Graylog Enterprise 2.3.2
- Graylog Enterprise 2.3.1
- Graylog Enterprise 2.3.0
- Graylog Enterprise 2.2.3
- Graylog Enterprise 2.2.2
- Graylog Enterprise 2.2.1
- Graylog Enterprise 2.2.0
- Graylog Enterprise 1.2.1
- Graylog Enterprise 1.2.0
- Graylog Enterprise 1.1
- Graylog Enterprise 1.0.1
- Graylog Enterprise 1.0.0
Graylog Content