Advertisement
Guest User

Untitled

a guest
Sep 4th, 2019
155
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 30.23 KB | None | 0 0
  1. 2019-09-04T08:17:28.639-04:00 INFO [CmdLineTool] Loaded plugin: AWS plugins 3.0.2 [org.graylog.aws.AWSPlugin]
  2. 2019-09-04T08:17:28.642-04:00 INFO [CmdLineTool] Loaded plugin: Collector 3.0.2 [org.graylog.plugins.collector.CollectorPlugin]
  3. 2019-09-04T08:17:28.643-04:00 INFO [CmdLineTool] Loaded plugin: Threat Intelligence Plugin 3.0.2 [org.graylog.plugins.threatintel.ThreatIntelPlugin]
  4. 2019-09-04T08:17:29.063-04:00 INFO [CmdLineTool] Running with JVM arguments: -Xms1g -Xmx1g -XX:NewRatio=1 -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow -Dlog4j.configurationFile=file:///etc/graylog/server/log4j2.xml -Djava.library.path=/usr/share/graylog-server/lib/sigar -Dgraylog2.installation_source=rpm
  5. 2019-09-04T08:17:29.279-04:00 INFO [Version] HV000001: Hibernate Validator 5.1.3.Final
  6. 2019-09-04T08:17:31.046-04:00 INFO [InputBufferImpl] Message journal is enabled.
  7. 2019-09-04T08:17:31.069-04:00 INFO [NodeId] Node ID: 8a9e58ed-7d5b-4366-9ea5-9ebd7339e0cc
  8. 2019-09-04T08:17:31.262-04:00 INFO [LogManager] Loading logs.
  9. 2019-09-04T08:17:31.319-04:00 INFO [LogManager] Logs loading complete.
  10. 2019-09-04T08:17:31.323-04:00 INFO [KafkaJournal] Initialized Kafka based journal at /mnt/store1/graylog-server/journal
  11. 2019-09-04T08:17:31.337-04:00 INFO [InputBufferImpl] Initialized InputBufferImpl with ring size <65536> and wait strategy <BlockingWaitStrategy>, running 2 parallel message handlers.
  12. 2019-09-04T08:17:31.360-04:00 INFO [cluster] Cluster created with settings {hosts=[127.0.0.1:27017], mode=SINGLE, requiredClusterType=UNKNOWN, serverSelectionTimeout='30000 ms', maxWaitQueueSize=5000}
  13. 2019-09-04T08:17:31.401-04:00 INFO [cluster] Cluster description not yet available. Waiting for 30000 ms before timing out
  14. 2019-09-04T08:17:31.425-04:00 INFO [connection] Opened connection [connectionId{localValue:1, serverValue:189}] to 127.0.0.1:27017
  15. 2019-09-04T08:17:31.427-04:00 INFO [cluster] Monitor thread successfully connected to server with description ServerDescription{address=127.0.0.1:27017, type=STANDALONE, state=CONNECTED, ok=true, version=ServerVersion{versionList=[2, 6, 11]}, minWireVersion=0, maxWireVersion=2, maxDocumentSize=16777216, logicalSessionTimeoutMinutes=null, roundTripTimeNanos=892599}
  16. 2019-09-04T08:17:31.438-04:00 INFO [connection] Opened connection [connectionId{localValue:2, serverValue:190}] to 127.0.0.1:27017
  17. 2019-09-04T08:17:31.753-04:00 INFO [AbstractJestClient] Setting server pool to a list of 1 servers: [http://192.168.48.158:9200]
  18. 2019-09-04T08:17:31.754-04:00 INFO [JestClientFactory] Using multi thread/connection supporting pooling connection manager
  19. 2019-09-04T08:17:31.828-04:00 INFO [JestClientFactory] Using custom ObjectMapper instance
  20. 2019-09-04T08:17:31.828-04:00 INFO [JestClientFactory] Node Discovery disabled...
  21. 2019-09-04T08:17:31.828-04:00 INFO [JestClientFactory] Idle connection reaping disabled...
  22. 2019-09-04T08:17:31.945-04:00 INFO [ProcessBuffer] Initialized ProcessBuffer with ring size <65536> and wait strategy <BlockingWaitStrategy>.
  23. 2019-09-04T08:17:32.358-04:00 INFO [connection] Opened connection [connectionId{localValue:3, serverValue:191}] to 127.0.0.1:27017
  24. 2019-09-04T08:17:32.367-04:00 INFO [OutputBuffer] Initialized OutputBuffer with ring size <65536> and wait strategy <BlockingWaitStrategy>.
  25. 2019-09-04T08:17:33.034-04:00 INFO [ServerBootstrap] Graylog server 3.0.2+1686930 starting up
  26. 2019-09-04T08:17:33.034-04:00 INFO [ServerBootstrap] JRE: Oracle Corporation 1.8.0_91 on Linux 3.10.0-229.20.1.el7.x86_64
  27. 2019-09-04T08:17:33.034-04:00 INFO [ServerBootstrap] Deployment: rpm
  28. 2019-09-04T08:17:33.034-04:00 INFO [ServerBootstrap] OS: CentOS Linux 7 (Core) (centos)
  29. 2019-09-04T08:17:33.035-04:00 INFO [ServerBootstrap] Arch: amd64
  30. 2019-09-04T08:17:33.064-04:00 INFO [PeriodicalsService] Starting 27 periodicals ...
  31. 2019-09-04T08:17:33.065-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.ThroughputCalculator] periodical in [0s], polling every [1s].
  32. 2019-09-04T08:17:33.087-04:00 INFO [Periodicals] Starting [org.graylog.plugins.pipelineprocessor.periodical.LegacyDefaultStreamMigration] periodical, running forever.
  33. 2019-09-04T08:17:33.088-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.AlertScannerThread] periodical in [10s], polling every [45s].
  34. 2019-09-04T08:17:33.089-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.BatchedElasticSearchOutputFlushThread] periodical in [0s], polling every [1s].
  35. 2019-09-04T08:17:33.089-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.ClusterHealthCheckThread] periodical in [120s], polling every [20s].
  36. 2019-09-04T08:17:33.090-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.GarbageCollectionWarningThread] periodical, running forever.
  37. 2019-09-04T08:17:33.092-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexerClusterCheckerThread] periodical in [0s], polling every [30s].
  38. 2019-09-04T08:17:33.094-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRetentionThread] periodical in [0s], polling every [300s].
  39. 2019-09-04T08:17:33.096-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRotationThread] periodical in [0s], polling every [10s].
  40. 2019-09-04T08:17:33.096-04:00 INFO [connection] Opened connection [connectionId{localValue:4, serverValue:192}] to 127.0.0.1:27017
  41. 2019-09-04T08:17:33.100-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.NodePingThread] periodical in [0s], polling every [1s].
  42. 2019-09-04T08:17:33.101-04:00 INFO [LegacyDefaultStreamMigration] Legacy default stream has no connections, no migration needed.
  43. 2019-09-04T08:17:33.101-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.VersionCheckThread] periodical in [300s], polling every [1800s].
  44. 2019-09-04T08:17:33.121-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.ThrottleStateUpdaterThread] periodical in [1s], polling every [1s].
  45. 2019-09-04T08:17:33.122-04:00 INFO [Periodicals] Starting [org.graylog2.events.ClusterEventPeriodical] periodical in [0s], polling every [1s].
  46. 2019-09-04T08:17:33.123-04:00 INFO [Periodicals] Starting [org.graylog2.events.ClusterEventCleanupPeriodical] periodical in [0s], polling every [86400s].
  47. 2019-09-04T08:17:33.123-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.ClusterIdGeneratorPeriodical] periodical, running forever.
  48. 2019-09-04T08:17:33.124-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRangesMigrationPeriodical] periodical, running forever.
  49. 2019-09-04T08:17:33.126-04:00 INFO [connection] Opened connection [connectionId{localValue:5, serverValue:193}] to 127.0.0.1:27017
  50. 2019-09-04T08:17:33.127-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRangesCleanupPeriodical] periodical in [15s], polling every [3600s].
  51. 2019-09-04T08:17:33.130-04:00 INFO [connection] Opened connection [connectionId{localValue:6, serverValue:194}] to 127.0.0.1:27017
  52. 2019-09-04T08:17:33.136-04:00 INFO [connection] Opened connection [connectionId{localValue:8, serverValue:196}] to 127.0.0.1:27017
  53. 2019-09-04T08:17:33.136-04:00 INFO [connection] Opened connection [connectionId{localValue:7, serverValue:195}] to 127.0.0.1:27017
  54. 2019-09-04T08:17:33.137-04:00 INFO [LookupTableService] Data Adapter otx-api-domain/5ade22e42bf9e61bf8226f87 [@250b9b5a] STARTING
  55. 2019-09-04T08:17:33.145-04:00 INFO [PeriodicalsService] Not starting [org.graylog2.periodical.UserPermissionMigrationPeriodical] periodical. Not configured to run on this node.
  56. 2019-09-04T08:17:33.146-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.AlarmCallbacksMigrationPeriodical] periodical, running forever.
  57. 2019-09-04T08:17:33.150-04:00 INFO [LookupTableService] Data Adapter whois/5ade22e42bf9e61bf8226f88 [@706e2b35] STARTING
  58. 2019-09-04T08:17:33.150-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.ConfigurationManagementPeriodical] periodical, running forever.
  59. 2019-09-04T08:17:33.150-04:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5ade22e42bf9e61bf8226f83 [@7ff585e2] STARTING
  60. 2019-09-04T08:17:33.150-04:00 INFO [LookupTableService] Data Adapter tor-exit-node/5ade22e42bf9e61bf8226f85 [@6136b53f] STARTING
  61. 2019-09-04T08:17:33.151-04:00 WARN [OTXDataAdapter] OTX API key is missing. Make sure to add the key to allow higher request limits.
  62. 2019-09-04T08:17:33.147-04:00 INFO [LookupTableService] Data Adapter otx-api-ip/5ade22e42bf9e61bf8226f89 [@35ee6d1f] STARTING
  63. 2019-09-04T08:17:33.150-04:00 ERROR [LookupDataAdapter] Couldn't start data adapter <spamhaus-drop/5ade22e42bf9e61bf8226f83/@7ff585e2>
  64. org.graylog.plugins.threatintel.tools.AdapterDisabledException: Spamhaus service is disabled, not starting (E)DROP adapter. To enable it please go to System / Configurations.
  65. at org.graylog.plugins.threatintel.adapters.spamhaus.SpamhausEDROPDataAdapter.doStart(SpamhausEDROPDataAdapter.java:85) ~[?:?]
  66. at org.graylog2.plugin.lookup.LookupDataAdapter.startUp(LookupDataAdapter.java:59) [graylog.jar:?]
  67. at com.google.common.util.concurrent.AbstractIdleService$DelegateService$1.run(AbstractIdleService.java:62) [graylog.jar:?]
  68. at com.google.common.util.concurrent.Callables$4.run(Callables.java:119) [graylog.jar:?]
  69. at java.lang.Thread.run(Thread.java:745) [?:1.8.0_91]
  70. 2019-09-04T08:17:33.156-04:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5ade22e42bf9e61bf8226f84 [@2b245df9] STARTING
  71. 2019-09-04T08:17:33.158-04:00 INFO [LookupTableService] Data Adapter whois/5ade22e42bf9e61bf8226f88 [@706e2b35] RUNNING
  72. 2019-09-04T08:17:33.158-04:00 INFO [PeriodicalsService] Not starting [org.graylog2.periodical.LdapGroupMappingMigration] periodical. Not configured to run on this node.
  73. 2019-09-04T08:17:33.160-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexFailuresPeriodical] periodical, running forever.
  74. 2019-09-04T08:17:33.150-04:00 ERROR [LookupDataAdapter] Couldn't start data adapter <tor-exit-node/5ade22e42bf9e61bf8226f85/@6136b53f>
  75. org.graylog.plugins.threatintel.tools.AdapterDisabledException: TOR service is disabled, not starting TOR exit addresses adapter. To enable it please go to System / Configurations.
  76. at org.graylog.plugins.threatintel.adapters.tor.TorExitNodeDataAdapter.doStart(TorExitNodeDataAdapter.java:89) ~[?:?]
  77. at org.graylog2.plugin.lookup.LookupDataAdapter.startUp(LookupDataAdapter.java:59) [graylog.jar:?]
  78. at com.google.common.util.concurrent.AbstractIdleService$DelegateService$1.run(AbstractIdleService.java:62) [graylog.jar:?]
  79. at com.google.common.util.concurrent.Callables$4.run(Callables.java:119) [graylog.jar:?]
  80. at java.lang.Thread.run(Thread.java:745) [?:1.8.0_91]
  81. 2019-09-04T08:17:33.160-04:00 INFO [Periodicals] Starting [org.graylog2.periodical.TrafficCounterCalculator] periodical in [0s], polling every [1s].
  82. 2019-09-04T08:17:33.160-04:00 INFO [Periodicals] Starting [org.graylog2.indexer.fieldtypes.IndexFieldTypePollerPeriodical] periodical in [0s], polling every [3600s].
  83. 2019-09-04T08:17:33.160-04:00 INFO [Periodicals] Starting [org.graylog.plugins.sidecar.periodical.PurgeExpiredSidecarsThread] periodical in [0s], polling every [600s].
  84. 2019-09-04T08:17:33.160-04:00 INFO [Periodicals] Starting [org.graylog.plugins.sidecar.periodical.PurgeExpiredConfigurationUploads] periodical in [0s], polling every [600s].
  85. 2019-09-04T08:17:33.158-04:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5ade22e42bf9e61bf8226f83 [@7ff585e2] RUNNING
  86. 2019-09-04T08:17:33.162-04:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5ade22e42bf9e61bf8226f86 [@2b8cdb50] STARTING
  87. 2019-09-04T08:17:33.161-04:00 INFO [Periodicals] Starting [org.graylog.plugins.collector.periodical.PurgeExpiredCollectorsThread] periodical in [0s], polling every [3600s].
  88. 2019-09-04T08:17:33.156-04:00 WARN [OTXDataAdapter] OTX API key is missing. Make sure to add the key to allow higher request limits.
  89. 2019-09-04T08:17:33.171-04:00 INFO [LookupTableService] Data Adapter otx-api-domain/5ade22e42bf9e61bf8226f87 [@250b9b5a] RUNNING
  90. 2019-09-04T08:17:33.171-04:00 INFO [LookupTableService] Data Adapter tor-exit-node/5ade22e42bf9e61bf8226f85 [@6136b53f] RUNNING
  91. 2019-09-04T08:17:33.179-04:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5ade22e42bf9e61bf8226f81 [@39fce7ea] STARTING
  92. 2019-09-04T08:17:33.180-04:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5ade22e42bf9e61bf8226f82 [@71c00bb1] STARTING
  93. 2019-09-04T08:17:33.180-04:00 INFO [LookupTableService] Cache otx-api-domain-cache/5ade22e42bf9e61bf8226f7f [@6b6c1fce] STARTING
  94. 2019-09-04T08:17:33.180-04:00 INFO [LookupTableService] Data Adapter otx-api-ip/5ade22e42bf9e61bf8226f89 [@35ee6d1f] RUNNING
  95. 2019-09-04T08:17:33.179-04:00 INFO [LookupTableService] Cache otx-api-ip-cache/5ade22e42bf9e61bf8226f7e [@5a5554ed] STARTING
  96. 2019-09-04T08:17:33.179-04:00 INFO [LookupTableService] Cache whois-cache/5ade22e42bf9e61bf8226f80 [@79259f9c] STARTING
  97. 2019-09-04T08:17:33.181-04:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5ade22e42bf9e61bf8226f81 [@39fce7ea] RUNNING
  98. 2019-09-04T08:17:33.181-04:00 INFO [LookupTableService] Cache otx-api-ip-cache/5ade22e42bf9e61bf8226f7e [@5a5554ed] RUNNING
  99. 2019-09-04T08:17:33.185-04:00 INFO [LookupTableService] Cache whois-cache/5ade22e42bf9e61bf8226f80 [@79259f9c] RUNNING
  100. 2019-09-04T08:17:33.185-04:00 INFO [LookupTableService] Cache otx-api-domain-cache/5ade22e42bf9e61bf8226f7f [@6b6c1fce] RUNNING
  101. 2019-09-04T08:17:33.185-04:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5ade22e42bf9e61bf8226f82 [@71c00bb1] RUNNING
  102. 2019-09-04T08:17:33.547-04:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5ade22e42bf9e61bf8226f86 [@2b8cdb50] RUNNING
  103. 2019-09-04T08:17:33.547-04:00 INFO [LookupDataAdapterRefreshService] Adding job for <abuse-ch-ransomware-ip/5ade22e42bf9e61bf8226f86/@2b8cdb50> [interval=150000ms]
  104. 2019-09-04T08:17:33.570-04:00 INFO [LookupDataAdapterRefreshService] Adding job for <abuse-ch-ransomware-domains/5ade22e42bf9e61bf8226f84/@2b245df9> [interval=150000ms]
  105. 2019-09-04T08:17:33.570-04:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5ade22e42bf9e61bf8226f84 [@2b245df9] RUNNING
  106. 2019-09-04T08:17:33.581-04:00 INFO [LookupTableService] Starting lookup table spamhaus-drop/5ade22e42bf9e61bf8226f8a [@584786b4] using cache spamhaus-e-drop-cache/5ade22e42bf9e61bf8226f81 [@39fce7ea], data adapter spamhaus-drop/5ade22e42bf9e61bf8226f83 [@7ff585e2]
  107. 2019-09-04T08:17:33.581-04:00 INFO [LookupTableService] Starting lookup table abuse-ch-ransomware-ip/5ade22e42bf9e61bf8226f8b [@6590b458] using cache threat-intel-uncached-adapters/5ade22e42bf9e61bf8226f82 [@71c00bb1], data adapter abuse-ch-ransomware-ip/5ade22e42bf9e61bf8226f86 [@2b8cdb50]
  108. 2019-09-04T08:17:33.581-04:00 INFO [LookupTableService] Starting lookup table otx-api-domain/5ade22e42bf9e61bf8226f8d [@b6d1e5c] using cache otx-api-domain-cache/5ade22e42bf9e61bf8226f7f [@6b6c1fce], data adapter otx-api-domain/5ade22e42bf9e61bf8226f87 [@250b9b5a]
  109. 2019-09-04T08:17:33.581-04:00 INFO [LookupTableService] Starting lookup table whois/5ade22e42bf9e61bf8226f8e [@5e1a6ca7] using cache whois-cache/5ade22e42bf9e61bf8226f80 [@79259f9c], data adapter whois/5ade22e42bf9e61bf8226f88 [@706e2b35]
  110. 2019-09-04T08:17:33.582-04:00 INFO [LookupTableService] Starting lookup table abuse-ch-ransomware-domains/5ade22e42bf9e61bf8226f8f [@3a0c23f6] using cache threat-intel-uncached-adapters/5ade22e42bf9e61bf8226f82 [@71c00bb1], data adapter abuse-ch-ransomware-domains/5ade22e42bf9e61bf8226f84 [@2b245df9]
  111. 2019-09-04T08:17:33.582-04:00 INFO [LookupTableService] Starting lookup table tor-exit-node-list/5ade22e42bf9e61bf8226f90 [@5a5e729b] using cache threat-intel-uncached-adapters/5ade22e42bf9e61bf8226f82 [@71c00bb1], data adapter tor-exit-node/5ade22e42bf9e61bf8226f85 [@6136b53f]
  112. 2019-09-04T08:17:33.582-04:00 INFO [LookupTableService] Starting lookup table otx-api-ip/5ade22e42bf9e61bf8226f91 [@39220872] using cache otx-api-ip-cache/5ade22e42bf9e61bf8226f7e [@5a5554ed], data adapter otx-api-ip/5ade22e42bf9e61bf8226f89 [@35ee6d1f]
  113. 2019-09-04T08:17:33.611-04:00 INFO [JerseyService] Enabling CORS for HTTP endpoint
  114. 2019-09-04T08:17:57.079-04:00 INFO [NetworkListener] Started listener bound to [0.0.0.0:9000]
  115. 2019-09-04T08:17:57.081-04:00 INFO [HttpServer] [HttpServer] Started.
  116. 2019-09-04T08:17:57.081-04:00 INFO [JerseyService] Started REST API at <0.0.0.0:9000>
  117. 2019-09-04T08:17:57.081-04:00 INFO [ServiceManagerListener] Services are healthy
  118. 2019-09-04T08:17:57.082-04:00 INFO [InputSetupService] Triggering launching persisted inputs, node transitioned from Uninitialized [LB:DEAD] to Running [LB:ALIVE]
  119. 2019-09-04T08:17:57.082-04:00 INFO [ServerBootstrap] Services started, startup times in ms: {GracefulShutdownService [RUNNING]=1, InputSetupService [RUNNING]=7, OutputSetupService [RUNNING]=9, EtagService [RUNNING]=11, BufferSynchronizerService [RUNNING]=13, JournalReader [RUNNING]=19, KafkaJournal [RUNNING]=20, ConfigurationEtagService [RUNNING]=63, PeriodicalsService [RUNNING]=105, StreamCacheService [RUNNING]=107, LookupTableService [RUNNING]=512, JerseyService [RUNNING]=24016}
  120. 2019-09-04T08:17:57.085-04:00 INFO [ServerBootstrap] Graylog server up and running.
  121. 2019-09-04T08:17:57.097-04:00 INFO [InputStateListener] Input [Syslog UDP/5661e0fc9008db9ea643b87f] is now STARTING
  122. 2019-09-04T08:17:57.205-04:00 INFO [InputStateListener] Input [Syslog UDP/5661e0fc9008db9ea643b87f] is now RUNNING
  123. 2019-09-04T08:17:57.219-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog-UDP, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=8a9e58ed-7d5b-4366-9ea5-9ebd7339e0cc} (channel [id: 0x37effb4a, L:/192.168.48.158:1514]) should be 262144 but is 425984.
  124. 2019-09-04T08:17:57.218-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog-UDP, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=8a9e58ed-7d5b-4366-9ea5-9ebd7339e0cc} (channel [id: 0x4c3475cd, L:/192.168.48.158:1514]) should be 262144 but is 425984.
  125. 2019-09-04T08:17:57.219-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog-UDP, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=8a9e58ed-7d5b-4366-9ea5-9ebd7339e0cc} (channel [id: 0x8bfbc485, L:/192.168.48.158:1514]) should be 262144 but is 425984.
  126. 2019-09-04T08:17:57.219-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog-UDP, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=8a9e58ed-7d5b-4366-9ea5-9ebd7339e0cc} (channel [id: 0x17a37ea0, L:/192.168.48.158:1514]) should be 262144 but is 425984.
  127. 2019-09-04T08:17:57.219-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog-UDP, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=8a9e58ed-7d5b-4366-9ea5-9ebd7339e0cc} (channel [id: 0xf1b9fb4d, L:/192.168.48.158:1514]) should be 262144 but is 425984.
  128. 2019-09-04T08:17:57.219-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog-UDP, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=8a9e58ed-7d5b-4366-9ea5-9ebd7339e0cc} (channel [id: 0xc167a62b, L:/192.168.48.158:1514]) should be 262144 but is 425984.
  129. 2019-09-04T08:17:57.219-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog-UDP, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=8a9e58ed-7d5b-4366-9ea5-9ebd7339e0cc} (channel [id: 0x49819e67, L:/192.168.48.158:1514]) should be 262144 but is 425984.
  130. 2019-09-04T08:17:57.219-04:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog-UDP, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=8a9e58ed-7d5b-4366-9ea5-9ebd7339e0cc} (channel [id: 0xde00c785, L:/192.168.48.158:1514]) should be 262144 but is 425984.
  131. 2019-09-04T08:23:23.141-04:00 INFO [Server] SIGNAL received. Shutting down.
  132. 2019-09-04T08:23:23.145-04:00 INFO [GracefulShutdown] Graceful shutdown initiated.
  133. 2019-09-04T08:23:23.145-04:00 INFO [GracefulShutdown] Node status: [Halting [LB:DEAD]]. Waiting <3sec> for possible load balancers to recognize state change.
  134. 2019-09-04T08:23:27.148-04:00 INFO [InputSetupService] Attempting to close input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5661e0fc9008db9ea643b87f> [Syslog UDP].
  135. 2019-09-04T08:23:27.156-04:00 INFO [InputSetupService] Input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5661e0fc9008db9ea643b87f> closed. Took [7ms]
  136. 2019-09-04T08:23:27.166-04:00 INFO [Buffers] Waiting until all buffers are empty.
  137. 2019-09-04T08:23:27.168-04:00 INFO [Buffers] All buffers are empty. Continuing.
  138. 2019-09-04T08:23:27.169-04:00 INFO [OutputSetupService] Stopping output org.graylog2.outputs.BlockingBatchedESOutput
  139. 2019-09-04T08:23:27.170-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.AlertScannerThread].
  140. 2019-09-04T08:23:27.170-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.AlertScannerThread] complete, took <0ms>.
  141. 2019-09-04T08:23:27.170-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.BatchedElasticSearchOutputFlushThread].
  142. 2019-09-04T08:23:27.171-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.BatchedElasticSearchOutputFlushThread] complete, took <0ms>.
  143. 2019-09-04T08:23:27.171-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.ClusterHealthCheckThread].
  144. 2019-09-04T08:23:27.171-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.ClusterHealthCheckThread] complete, took <0ms>.
  145. 2019-09-04T08:23:27.171-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.IndexerClusterCheckerThread].
  146. 2019-09-04T08:23:27.171-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.IndexerClusterCheckerThread] complete, took <0ms>.
  147. 2019-09-04T08:23:27.171-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.IndexRetentionThread].
  148. 2019-09-04T08:23:27.171-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.IndexRetentionThread] complete, took <0ms>.
  149. 2019-09-04T08:23:27.171-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.IndexRotationThread].
  150. 2019-09-04T08:23:27.171-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.IndexRotationThread] complete, took <0ms>.
  151. 2019-09-04T08:23:27.172-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.VersionCheckThread].
  152. 2019-09-04T08:23:27.172-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.VersionCheckThread] complete, took <0ms>.
  153. 2019-09-04T08:23:27.172-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.ThrottleStateUpdaterThread].
  154. 2019-09-04T08:23:27.172-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.ThrottleStateUpdaterThread] complete, took <0ms>.
  155. 2019-09-04T08:23:27.172-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.events.ClusterEventPeriodical].
  156. 2019-09-04T08:23:27.172-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.events.ClusterEventPeriodical] complete, took <0ms>.
  157. 2019-09-04T08:23:27.172-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.events.ClusterEventCleanupPeriodical].
  158. 2019-09-04T08:23:27.172-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.events.ClusterEventCleanupPeriodical] complete, took <0ms>.
  159. 2019-09-04T08:23:27.172-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.IndexRangesCleanupPeriodical].
  160. 2019-09-04T08:23:27.173-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.IndexRangesCleanupPeriodical] complete, took <0ms>.
  161. 2019-09-04T08:23:27.173-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.TrafficCounterCalculator].
  162. 2019-09-04T08:23:27.173-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.TrafficCounterCalculator] complete, took <0ms>.
  163. 2019-09-04T08:23:27.173-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.indexer.fieldtypes.IndexFieldTypePollerPeriodical].
  164. 2019-09-04T08:23:27.173-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.indexer.fieldtypes.IndexFieldTypePollerPeriodical] complete, took <0ms>.
  165. 2019-09-04T08:23:27.173-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog.plugins.sidecar.periodical.PurgeExpiredSidecarsThread].
  166. 2019-09-04T08:23:27.173-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog.plugins.sidecar.periodical.PurgeExpiredSidecarsThread] complete, took <0ms>.
  167. 2019-09-04T08:23:27.173-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog.plugins.sidecar.periodical.PurgeExpiredConfigurationUploads].
  168. 2019-09-04T08:23:27.173-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog.plugins.sidecar.periodical.PurgeExpiredConfigurationUploads] complete, took <0ms>.
  169. 2019-09-04T08:23:27.173-04:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog.plugins.collector.periodical.PurgeExpiredCollectorsThread].
  170. 2019-09-04T08:23:27.174-04:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog.plugins.collector.periodical.PurgeExpiredCollectorsThread] complete, took <0ms>.
  171. 2019-09-04T08:23:27.174-04:00 INFO [GracefulShutdown] Goodbye.
  172. 2019-09-04T08:23:27.175-04:00 INFO [JerseyService] Shutting down HTTP listener at <0.0.0.0:9000>
  173. 2019-09-04T08:23:27.181-04:00 INFO [LogManager] Shutting down.
  174. 2019-09-04T08:23:27.189-04:00 INFO [LookupTableService] Cache otx-api-domain-cache/5ade22e42bf9e61bf8226f7f [@6b6c1fce] STOPPING, was RUNNING
  175. 2019-09-04T08:23:27.189-04:00 INFO [LookupTableService] Cache otx-api-ip-cache/5ade22e42bf9e61bf8226f7e [@5a5554ed] STOPPING, was RUNNING
  176. 2019-09-04T08:23:27.190-04:00 INFO [LookupTableService] Cache otx-api-domain-cache/5ade22e42bf9e61bf8226f7f [@6b6c1fce] TERMINATED, was STOPPING
  177. 2019-09-04T08:23:27.190-04:00 INFO [LookupTableService] Cache otx-api-ip-cache/5ade22e42bf9e61bf8226f7e [@5a5554ed] TERMINATED, was STOPPING
  178. 2019-09-04T08:23:27.198-04:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5ade22e42bf9e61bf8226f82 [@71c00bb1] STOPPING, was RUNNING
  179. 2019-09-04T08:23:27.199-04:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5ade22e42bf9e61bf8226f82 [@71c00bb1] TERMINATED, was STOPPING
  180. 2019-09-04T08:23:27.199-04:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5ade22e42bf9e61bf8226f81 [@39fce7ea] STOPPING, was RUNNING
  181. 2019-09-04T08:23:27.200-04:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5ade22e42bf9e61bf8226f81 [@39fce7ea] TERMINATED, was STOPPING
  182. 2019-09-04T08:23:27.204-04:00 INFO [LookupTableService] Cache whois-cache/5ade22e42bf9e61bf8226f80 [@79259f9c] STOPPING, was RUNNING
  183. 2019-09-04T08:23:27.209-04:00 INFO [LookupTableService] Cache whois-cache/5ade22e42bf9e61bf8226f80 [@79259f9c] TERMINATED, was STOPPING
  184. 2019-09-04T08:23:27.211-04:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5ade22e42bf9e61bf8226f86 [@2b8cdb50] STOPPING, was RUNNING
  185. 2019-09-04T08:23:27.211-04:00 INFO [LookupDataAdapterRefreshService] Removing job for <abuse-ch-ransomware-ip/5ade22e42bf9e61bf8226f86/@2b8cdb50>
  186. 2019-09-04T08:23:27.212-04:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5ade22e42bf9e61bf8226f83 [@7ff585e2] STOPPING, was RUNNING
  187. 2019-09-04T08:23:27.212-04:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5ade22e42bf9e61bf8226f86 [@2b8cdb50] TERMINATED, was STOPPING
  188. 2019-09-04T08:23:27.212-04:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5ade22e42bf9e61bf8226f83 [@7ff585e2] TERMINATED, was STOPPING
  189. 2019-09-04T08:23:27.212-04:00 INFO [LookupTableService] Data Adapter otx-api-ip/5ade22e42bf9e61bf8226f89 [@35ee6d1f] STOPPING, was RUNNING
  190. 2019-09-04T08:23:27.213-04:00 INFO [LookupTableService] Data Adapter otx-api-ip/5ade22e42bf9e61bf8226f89 [@35ee6d1f] TERMINATED, was STOPPING
  191. 2019-09-04T08:23:27.213-04:00 INFO [LookupTableService] Data Adapter whois/5ade22e42bf9e61bf8226f88 [@706e2b35] STOPPING, was RUNNING
  192. 2019-09-04T08:23:27.214-04:00 INFO [LookupTableService] Data Adapter tor-exit-node/5ade22e42bf9e61bf8226f85 [@6136b53f] STOPPING, was RUNNING
  193. 2019-09-04T08:23:27.214-04:00 INFO [LookupTableService] Data Adapter whois/5ade22e42bf9e61bf8226f88 [@706e2b35] TERMINATED, was STOPPING
  194. 2019-09-04T08:23:27.217-04:00 INFO [LookupDataAdapterRefreshService] Stopping 1 jobs
  195. 2019-09-04T08:23:27.217-04:00 INFO [LookupTableService] Data Adapter otx-api-domain/5ade22e42bf9e61bf8226f87 [@250b9b5a] STOPPING, was RUNNING
  196. 2019-09-04T08:23:27.217-04:00 INFO [LookupTableService] Data Adapter tor-exit-node/5ade22e42bf9e61bf8226f85 [@6136b53f] TERMINATED, was STOPPING
  197. 2019-09-04T08:23:27.217-04:00 INFO [LookupTableService] Data Adapter otx-api-domain/5ade22e42bf9e61bf8226f87 [@250b9b5a] TERMINATED, was STOPPING
  198. 2019-09-04T08:23:27.217-04:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5ade22e42bf9e61bf8226f84 [@2b245df9] STOPPING, was RUNNING
  199. 2019-09-04T08:23:27.218-04:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5ade22e42bf9e61bf8226f84 [@2b245df9] TERMINATED, was STOPPING
  200. 2019-09-04T08:23:27.220-04:00 INFO [LogManager] Shutdown complete.
  201. 2019-09-04T08:23:27.230-04:00 INFO [NetworkListener] Stopped listener bound to [0.0.0.0:9000]
  202. 2019-09-04T08:23:27.250-04:00 INFO [JournalReader] Stopping.
  203. 2019-09-04T08:23:27.250-04:00 INFO [ServiceManagerListener] Services are now stopped.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement