Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2020-11-20T16:27:05.258-03:00 INFO [CmdLineTool] Loaded plugin: TelegramNotification 2.3.1 [de.irgendwr.TelegramNotificationPlugin]
- 2020-11-20T16:27:05.261-03:00 INFO [CmdLineTool] Loaded plugin: AWS plugins 4.0.0 [org.graylog.aws.AWSPlugin]
- 2020-11-20T16:27:05.262-03:00 INFO [CmdLineTool] Loaded plugin: Collector 4.0.0 [org.graylog.plugins.collector.CollectorPlugin]
- 2020-11-20T16:27:05.263-03:00 INFO [CmdLineTool] Loaded plugin: Threat Intelligence Plugin 4.0.0 [org.graylog.plugins.threatintel.ThreatIntelPlugin]
- 2020-11-20T16:27:05.263-03:00 INFO [CmdLineTool] Loaded plugin: SnmpPlugin 0.3.0 [org.graylog.snmp.SnmpPlugin]
- 2020-11-20T16:27:05.263-03:00 INFO [CmdLineTool] Loaded plugin: Elasticsearch 6 Support 4.0.0+9376305 [org.graylog.storage.elasticsearch6.Elasticsearch6Plugin]
- 2020-11-20T16:27:05.263-03:00 INFO [CmdLineTool] Loaded plugin: Elasticsearch 7 Support 4.0.0+9376305 [org.graylog.storage.elasticsearch7.Elasticsearch7Plugin]
- 2020-11-20T16:27:05.453-03:00 INFO [CmdLineTool] Running with JVM arguments: -Xms4g -Xmx4g -XX:NewRatio=1 -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow -XX:+UseParNewGC -Dlog4j.configurationFile=file:///etc/graylog/server/log4j2.xml -Djava.library.path=/usr/share/graylog-server/lib/sigar -Dgraylog2.installation_source=deb
- 2020-11-20T16:27:05.644-03:00 INFO [Version] HV000001: Hibernate Validator null
- 2020-11-20T16:27:08.230-03:00 INFO [InputBufferImpl] Message journal is enabled.
- 2020-11-20T16:27:08.248-03:00 INFO [NodeId] Node ID: ddbb0e96-67f6-4d67-b8f7-0d2e074b608b
- 2020-11-20T16:27:08.417-03:00 INFO [LogManager] Loading logs.
- 2020-11-20T16:27:08.475-03:00 INFO [LogManager] Logs loading complete.
- 2020-11-20T16:27:08.479-03:00 INFO [KafkaJournal] Initialized Kafka based journal at /var/lib/graylog-server/journal
- 2020-11-20T16:27:08.521-03:00 INFO [cluster] Cluster created with settings {hosts=[localhost:27017], mode=SINGLE, requiredClusterType=UNKNOWN, serverSelectionTimeout='30000 ms', maxWaitQueueSize=5000}
- 2020-11-20T16:27:08.574-03:00 INFO [cluster] Cluster description not yet available. Waiting for 30000 ms before timing out
- 2020-11-20T16:27:08.601-03:00 INFO [connection] Opened connection [connectionId{localValue:1, serverValue:36}] to localhost:27017
- 2020-11-20T16:27:08.603-03:00 INFO [cluster] Monitor thread successfully connected to server with description ServerDescription{address=localhost:27017, type=STANDALONE, state=CONNECTED, ok=true, version=ServerVersion{versionList=[2, 6, 10]}, minWireVersion=0, maxWireVersion=2, maxDocumentSize=16777216, logicalSessionTimeoutMinutes=null, roundTripTimeNanos=1123342}
- 2020-11-20T16:27:08.616-03:00 INFO [connection] Opened connection [connectionId{localValue:2, serverValue:37}] to localhost:27017
- 2020-11-20T16:27:08.841-03:00 INFO [InputBufferImpl] Initialized InputBufferImpl with ring size <65536> and wait strategy <BlockingWaitStrategy>, running 4 parallel message handlers.
- 2020-11-20T16:27:09.096-03:00 INFO [ElasticsearchVersionProvider] Elasticsearch cluster is running v6.8.8
- 2020-11-20T16:27:09.135-03:00 INFO [AbstractJestClient] Setting server pool to a list of 1 servers: [http://172.16.2.240:9200]
- 2020-11-20T16:27:09.136-03:00 INFO [JestClientFactory] Using multi thread/connection supporting pooling connection manager
- 2020-11-20T16:27:09.200-03:00 INFO [JestClientFactory] Using custom ObjectMapper instance
- 2020-11-20T16:27:09.200-03:00 INFO [JestClientFactory] Node Discovery enabled...
- 2020-11-20T16:27:09.228-03:00 INFO [JestClientFactory] Idle connection reaping disabled...
- 2020-11-20T16:27:09.658-03:00 INFO [ProcessBuffer] Initialized ProcessBuffer with ring size <131072> and wait strategy <BlockingWaitStrategy>.
- 2020-11-20T16:27:09.932-03:00 INFO [OutputBuffer] Initialized OutputBuffer with ring size <131072> and wait strategy <BlockingWaitStrategy>.
- 2020-11-20T16:27:09.960-03:00 INFO [connection] Opened connection [connectionId{localValue:3, serverValue:38}] to localhost:27017
- 2020-11-20T16:27:10.669-03:00 INFO [ServerBootstrap] Graylog server 4.0.0+9376305 starting up
- 2020-11-20T16:27:10.670-03:00 INFO [ServerBootstrap] JRE: Private Build 1.8.0_275 on Linux 4.4.0-194-generic
- 2020-11-20T16:27:10.670-03:00 INFO [ServerBootstrap] Deployment: deb
- 2020-11-20T16:27:10.670-03:00 INFO [ServerBootstrap] OS: Ubuntu 16.04.7 LTS (xenial)
- 2020-11-20T16:27:10.670-03:00 INFO [ServerBootstrap] Arch: amd64
- 2020-11-20T16:27:10.709-03:00 INFO [PeriodicalsService] Starting 30 periodicals ...
- 2020-11-20T16:27:10.709-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ThroughputCalculator] periodical in [0s], polling every [1s].
- 2020-11-20T16:27:10.804-03:00 INFO [Periodicals] Starting [org.graylog.plugins.pipelineprocessor.periodical.LegacyDefaultStreamMigration] periodical, running forever.
- 2020-11-20T16:27:10.813-03:00 INFO [connection] Opened connection [connectionId{localValue:4, serverValue:39}] to localhost:27017
- 2020-11-20T16:27:10.819-03:00 INFO [PeriodicalsService] Not starting [org.graylog2.periodical.AlertScannerThread] periodical. Not configured to run on this node.
- 2020-11-20T16:27:10.820-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.BatchedElasticSearchOutputFlushThread] periodical in [0s], polling every [1s].
- 2020-11-20T16:27:10.846-03:00 INFO [LegacyDefaultStreamMigration] Legacy default stream has no connections, no migration needed.
- 2020-11-20T16:27:10.847-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ClusterHealthCheckThread] periodical in [120s], polling every [20s].
- 2020-11-20T16:27:10.847-03:00 INFO [PeriodicalsService] Not starting [org.graylog2.periodical.ContentPackLoaderPeriodical] periodical. Not configured to run on this node.
- 2020-11-20T16:27:10.848-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.GarbageCollectionWarningThread] periodical, running forever.
- 2020-11-20T16:27:10.848-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexerClusterCheckerThread] periodical in [0s], polling every [30s].
- 2020-11-20T16:27:10.848-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRetentionThread] periodical in [0s], polling every [300s].
- 2020-11-20T16:27:10.855-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRotationThread] periodical in [0s], polling every [10s].
- 2020-11-20T16:27:10.856-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.NodePingThread] periodical in [0s], polling every [1s].
- 2020-11-20T16:27:10.862-03:00 INFO [connection] Opened connection [connectionId{localValue:5, serverValue:40}] to localhost:27017
- 2020-11-20T16:27:10.872-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.VersionCheckThread] periodical in [300s], polling every [1800s].
- 2020-11-20T16:27:10.887-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ThrottleStateUpdaterThread] periodical in [1s], polling every [1s].
- 2020-11-20T16:27:10.900-03:00 INFO [Periodicals] Starting [org.graylog2.events.ClusterEventPeriodical] periodical in [0s], polling every [1s].
- 2020-11-20T16:27:10.901-03:00 INFO [Periodicals] Starting [org.graylog2.events.ClusterEventCleanupPeriodical] periodical in [0s], polling every [86400s].
- 2020-11-20T16:27:10.901-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ClusterIdGeneratorPeriodical] periodical, running forever.
- 2020-11-20T16:27:10.901-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRangesMigrationPeriodical] periodical, running forever.
- 2020-11-20T16:27:10.906-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRangesCleanupPeriodical] periodical in [15s], polling every [3600s].
- 2020-11-20T16:27:10.908-03:00 INFO [connection] Opened connection [connectionId{localValue:6, serverValue:41}] to localhost:27017
- 2020-11-20T16:27:10.919-03:00 INFO [connection] Opened connection [connectionId{localValue:7, serverValue:42}] to localhost:27017
- 2020-11-20T16:27:10.942-03:00 INFO [PeriodicalsService] Not starting [org.graylog2.periodical.UserPermissionMigrationPeriodical] periodical. Not configured to run on this node.
- 2020-11-20T16:27:10.943-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ConfigurationManagementPeriodical] periodical, running forever.
- 2020-11-20T16:27:10.943-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexFailuresPeriodical] periodical, running forever.
- 2020-11-20T16:27:10.943-03:00 ERROR [LookupDataAdapter] Couldn't start data adapter <abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc68/@64135161>
- org.graylog.plugins.threatintel.tools.AdapterDisabledException: Abuse.ch service is disabled, not starting adapter. To enable it please go to System / Configurations.
- at org.graylog.plugins.threatintel.adapters.abusech.AbuseChRansomAdapter.doStart(AbuseChRansomAdapter.java:96) ~[?:?]
- at org.graylog2.plugin.lookup.LookupDataAdapter.startUp(LookupDataAdapter.java:79) [graylog.jar:?]
- at com.google.common.util.concurrent.AbstractIdleService$DelegateService$1.run(AbstractIdleService.java:62) [graylog.jar:?]
- at com.google.common.util.concurrent.Callables$4.run(Callables.java:119) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:27:10.966-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc6d [@2c916636] STARTING
- 2020-11-20T16:27:10.967-03:00 INFO [LookupTableService] Data Adapter aria_json/5ee8de9d326862721e882bd2 [@2f96f1d1] STARTING
- 2020-11-20T16:27:10.967-03:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5a0ddf9baf963c0edc44fc67 [@7f79be22] STARTING
- 2020-11-20T16:27:10.967-03:00 INFO [LookupTableService] Data Adapter tor-exit-node/5a0ddf9baf963c0edc44fc6b [@7c24d038] STARTING
- 2020-11-20T16:27:10.967-03:00 INFO [LookupTableService] Data Adapter otx-ip/5a0ddf9baf963c0edc44fc6c [@766ecdd3] STARTING
- 2020-11-20T16:27:10.975-03:00 INFO [LookupTableService] Data Adapter whois/5a0ddf9baf963c0edc44fc6a [@474e3c9d] STARTING
- 2020-11-20T16:27:10.978-03:00 INFO [LookupTableService] Data Adapter queue-name-adapter/5c8114153bbc820783336b95 [@2f16a1b5] STARTING
- 2020-11-20T16:27:10.982-03:00 ERROR [LookupDataAdapter] Couldn't start data adapter <abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc6d/@2c916636>
- org.graylog.plugins.threatintel.tools.AdapterDisabledException: Abuse.ch service is disabled, not starting adapter. To enable it please go to System / Configurations.
- at org.graylog.plugins.threatintel.adapters.abusech.AbuseChRansomAdapter.doStart(AbuseChRansomAdapter.java:96) ~[?:?]
- at org.graylog2.plugin.lookup.LookupDataAdapter.startUp(LookupDataAdapter.java:79) [graylog.jar:?]
- at com.google.common.util.concurrent.AbstractIdleService$DelegateService$1.run(AbstractIdleService.java:62) [graylog.jar:?]
- at com.google.common.util.concurrent.Callables$4.run(Callables.java:119) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:27:10.982-03:00 ERROR [LookupDataAdapter] Couldn't start data adapter <spamhaus-drop/5a0ddf9baf963c0edc44fc67/@7f79be22>
- org.graylog.plugins.threatintel.tools.AdapterDisabledException: Spamhaus service is disabled, not starting (E)DROP adapter. To enable it please go to System / Configurations.
- at org.graylog.plugins.threatintel.adapters.spamhaus.SpamhausEDROPDataAdapter.doStart(SpamhausEDROPDataAdapter.java:85) ~[?:?]
- at org.graylog2.plugin.lookup.LookupDataAdapter.startUp(LookupDataAdapter.java:79) [graylog.jar:?]
- at com.google.common.util.concurrent.AbstractIdleService$DelegateService$1.run(AbstractIdleService.java:62) [graylog.jar:?]
- at com.google.common.util.concurrent.Callables$4.run(Callables.java:119) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:27:10.983-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc68 [@64135161] STARTING
- 2020-11-20T16:27:10.983-03:00 ERROR [LookupDataAdapter] Couldn't start data adapter <tor-exit-node/5a0ddf9baf963c0edc44fc6b/@7c24d038>
- org.graylog.plugins.threatintel.tools.AdapterDisabledException: TOR service is disabled, not starting TOR exit addresses adapter. To enable it please go to System / Configurations.
- at org.graylog.plugins.threatintel.adapters.tor.TorExitNodeDataAdapter.doStart(TorExitNodeDataAdapter.java:89) ~[?:?]
- at org.graylog2.plugin.lookup.LookupDataAdapter.startUp(LookupDataAdapter.java:79) [graylog.jar:?]
- at com.google.common.util.concurrent.AbstractIdleService$DelegateService$1.run(AbstractIdleService.java:62) [graylog.jar:?]
- at com.google.common.util.concurrent.Callables$4.run(Callables.java:119) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:27:10.984-03:00 INFO [LookupTableService] Data Adapter queue-name-adapter/5c8114153bbc820783336b95 [@2f16a1b5] RUNNING
- 2020-11-20T16:27:10.990-03:00 INFO [LookupTableService] Data Adapter whois/5a0ddf9baf963c0edc44fc6a [@474e3c9d] RUNNING
- 2020-11-20T16:27:10.991-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.TrafficCounterCalculator] periodical in [0s], polling every [1s].
- 2020-11-20T16:27:10.991-03:00 INFO [Periodicals] Starting [org.graylog2.indexer.fieldtypes.IndexFieldTypePollerPeriodical] periodical in [0s], polling every [3600s].
- 2020-11-20T16:27:10.991-03:00 INFO [Periodicals] Starting [org.graylog.scheduler.periodicals.ScheduleTriggerCleanUp] periodical in [120s], polling every [86400s].
- 2020-11-20T16:27:10.991-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ESVersionCheckPeriodical] periodical in [0s], polling every [30s].
- 2020-11-20T16:27:10.991-03:00 INFO [Periodicals] Starting [org.graylog.plugins.sidecar.periodical.PurgeExpiredSidecarsThread] periodical in [0s], polling every [600s].
- 2020-11-20T16:27:10.992-03:00 INFO [Periodicals] Starting [org.graylog.plugins.sidecar.periodical.PurgeExpiredConfigurationUploads] periodical in [0s], polling every [600s].
- 2020-11-20T16:27:10.992-03:00 INFO [Periodicals] Starting [org.graylog.plugins.views.search.db.SearchesCleanUpJob] periodical in [3600s], polling every [28800s].
- 2020-11-20T16:27:10.997-03:00 INFO [Periodicals] Starting [org.graylog.events.periodicals.EventNotificationStatusCleanUp] periodical in [120s], polling every [86400s].
- 2020-11-20T16:27:10.983-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc68 [@64135161] RUNNING
- 2020-11-20T16:27:10.983-03:00 INFO [LookupTableService] Data Adapter asn-adapter/5c6aac273bbc820e9060a043 [@1c7ba9cd] STARTING
- 2020-11-20T16:27:10.998-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc6d [@2c916636] RUNNING
- 2020-11-20T16:27:10.998-03:00 INFO [LookupTableService] Data Adapter asn-adapter/5c6aac273bbc820e9060a043 [@1c7ba9cd] RUNNING
- 2020-11-20T16:27:11.002-03:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5a0ddf9baf963c0edc44fc67 [@7f79be22] RUNNING
- 2020-11-20T16:27:11.002-03:00 INFO [LookupTableService] Data Adapter otx-ip/5a0ddf9baf963c0edc44fc6c [@766ecdd3] RUNNING
- 2020-11-20T16:27:11.003-03:00 INFO [LookupTableService] Data Adapter aria_json/5ee8de9d326862721e882bd2 [@2f96f1d1] RUNNING
- 2020-11-20T16:27:10.998-03:00 INFO [LookupTableService] Data Adapter tor-exit-node/5a0ddf9baf963c0edc44fc6b [@7c24d038] RUNNING
- 2020-11-20T16:27:11.004-03:00 INFO [Periodicals] Starting [org.graylog.plugins.collector.periodical.PurgeExpiredCollectorsThread] periodical in [0s], polling every [3600s].
- 2020-11-20T16:27:11.078-03:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@1866aad7] STARTING
- 2020-11-20T16:27:11.079-03:00 INFO [LookupTableService] Cache whois-cache/5a0ddf9baf963c0edc44fc62 [@110f4c6d] STARTING
- 2020-11-20T16:27:11.079-03:00 INFO [LookupTableService] Cache asn-cache-2/5d0255153bbc82032d37f487 [@7a86a672] STARTING
- 2020-11-20T16:27:11.079-03:00 INFO [LookupTableService] Cache queues2/5ee8fa9a326862721e884a34 [@49ed17c4] STARTING
- 2020-11-20T16:27:11.090-03:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5a0ddf9baf963c0edc44fc63 [@316385ae] STARTING
- 2020-11-20T16:27:11.095-03:00 INFO [LookupTableService] Cache whois-cache/5a0ddf9baf963c0edc44fc62 [@110f4c6d] RUNNING
- 2020-11-20T16:27:11.095-03:00 INFO [LookupTableService] Cache queues2/5ee8fa9a326862721e884a34 [@49ed17c4] RUNNING
- 2020-11-20T16:27:11.099-03:00 INFO [LookupTableService] Cache asn-cache-2/5d0255153bbc82032d37f487 [@7a86a672] RUNNING
- 2020-11-20T16:27:11.099-03:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@1866aad7] RUNNING
- 2020-11-20T16:27:11.100-03:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5a0ddf9baf963c0edc44fc63 [@316385ae] RUNNING
- 2020-11-20T16:27:11.113-03:00 INFO [LookupTableService] Starting lookup table spamhaus-drop/5a0ddf9baf963c0edc44fc6f [@4cae4a84] using cache spamhaus-e-drop-cache/5a0ddf9baf963c0edc44fc63 [@316385ae], data adapter spamhaus-drop/5a0ddf9baf963c0edc44fc67 [@7f79be22]
- 2020-11-20T16:27:11.113-03:00 INFO [LookupTableService] Starting lookup table whois/5a0ddf9baf963c0edc44fc70 [@5c2d4886] using cache whois-cache/5a0ddf9baf963c0edc44fc62 [@110f4c6d], data adapter whois/5a0ddf9baf963c0edc44fc6a [@474e3c9d]
- 2020-11-20T16:27:11.113-03:00 INFO [LookupTableService] Starting lookup table tor-exit-node-list/5a0ddf9baf963c0edc44fc71 [@28f55f1d] using cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@1866aad7], data adapter tor-exit-node/5a0ddf9baf963c0edc44fc6b [@7c24d038]
- 2020-11-20T16:27:11.113-03:00 INFO [LookupTableService] Starting lookup table abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc73 [@593961ff] using cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@1866aad7], data adapter abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc6d [@2c916636]
- 2020-11-20T16:27:11.113-03:00 INFO [LookupTableService] Starting lookup table abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc74 [@677dea36] using cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@1866aad7], data adapter abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc68 [@64135161]
- 2020-11-20T16:27:11.114-03:00 INFO [LookupTableService] Starting lookup table asn-lkt/5c6aac733bbc820e9060a098 [@51a2f727] using cache asn-cache-2/5d0255153bbc82032d37f487 [@7a86a672], data adapter asn-adapter/5c6aac273bbc820e9060a043 [@1c7ba9cd]
- 2020-11-20T16:27:11.114-03:00 INFO [LookupTableService] Starting lookup table q-lkp/5c81178c3bbc820783337630 [@532d57b9] using cache queues2/5ee8fa9a326862721e884a34 [@49ed17c4], data adapter aria_json/5ee8de9d326862721e882bd2 [@2f96f1d1]
- 2020-11-20T16:27:11.519-03:00 ERROR [ConfigurationManagementPeriodical] Error while running migration <V20190705071400_AddEventIndexSetsMigration{2019-07-05T07:14:00Z}>
- java.lang.IllegalStateException: Index prefix conflict: a non-events index-set with prefix <gl-events> already exists. Configure a different <default_events_index_prefix> value in the server config file.
- at org.graylog2.migrations.V20190705071400_AddEventIndexSetsMigration.checkIndexPrefixConflicts(V20190705071400_AddEventIndexSetsMigration.java:130) ~[graylog.jar:?]
- at org.graylog2.migrations.V20190705071400_AddEventIndexSetsMigration.ensureEventsStreamAndIndexSet(V20190705071400_AddEventIndexSetsMigration.java:111) ~[graylog.jar:?]
- at org.graylog2.migrations.V20190705071400_AddEventIndexSetsMigration.upgrade(V20190705071400_AddEventIndexSetsMigration.java:84) ~[graylog.jar:?]
- at org.graylog2.periodical.ConfigurationManagementPeriodical.doRun(ConfigurationManagementPeriodical.java:42) [graylog.jar:?]
- at org.graylog2.plugin.periodical.Periodical.run(Periodical.java:77) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:27:11.691-03:00 ERROR [ConfigurationManagementPeriodical] Error while running migration <V20200409083200_RemoveRootQueriesFromMigratedDashboards{2020-04-09T08:32:00Z}>
- com.mongodb.MongoWriteException: cannot use the part (queries of queries.$[elem].query.query_string) to traverse the element ({queries: [ { id: "00000170-0c48-aa03-8788-00505694f28c", timerange: { type: "relative", range: 300 }, query: { type: "elasticsearch", query_string: "" }, search_types: [ { id: "00000170-0c48-a9ff-8788-00505694f28c", timerange: { type: "keyword", keyword: "last 6 hours" }, query: { type: "elasticsearch", query_string: "source:tickets" }, streams: [], name: "chart", series: [ { type: "count", id: "count()", field: null } ], sort: [ { type: "series", field: "ticket_cause", direction: "Descending" } ], rollup: true, type: "pivot", row_groups: [ { field: "ticket_cause", limit: 5, type: "values" } ], column_groups: [] }, { id: "00000170-0c48-aa01-8788-00505694f28c", timerange: { type: "relative", range: 21600 }, query: { type: "elasticsearch", query_string: "source:tickets" }, streams: [], name: "chart", series: [ { type: "count", id: "count()", field: null } ], sort: [ { type: "series", field: "ticket_nodo", direction: "Descending" } ], rollup: true, type: "pivot", row_groups: [ { field: "ticket_nodo", limit: 5, type: "values" } ], column_groups: [] }, { id: "00000170-0c48-aa00-8788-00505694f28c", timerange: { type: "keyword", keyword: "last 6 hours" }, query: { type: "elasticsearch", query_string: "source:tickets" }, streams: [], name: "chart", series: [ { type: "count", id: "count()", field: null } ], sort: [ { type: "series", field: "ticket_cause", direction: "Descending" } ], rollup: true, type: "pivot", row_groups: [ { field: "ticket_cause", limit: 50, type: "values" } ], column_groups: [] }, { id: "00000170-0c48-aa02-8788-00505694f28c", timerange: { type: "relative", range: 21600 }, query: { type: "elasticsearch", query_string: "source:tickets" }, streams: [], name: "chart", series: [ { type: "count", id: "count()", field: null } ], sort: [ { type: "series", field: "ticket_nodo", direction: "Descending" } ], rollup: true, type: "pivot", row_groups: [ { field: "ticket_nodo", limit: 50, type: "values" } ], column_groups: [] } ] } ]})
- at com.mongodb.client.internal.MongoCollectionImpl.executeSingleWriteRequest(MongoCollectionImpl.java:1060) ~[graylog.jar:?]
- at com.mongodb.client.internal.MongoCollectionImpl.executeUpdate(MongoCollectionImpl.java:1037) ~[graylog.jar:?]
- at com.mongodb.client.internal.MongoCollectionImpl.updateMany(MongoCollectionImpl.java:668) ~[graylog.jar:?]
- at org.graylog.plugins.views.migrations.V20200409083200_RemoveRootQueriesFromMigratedDashboards.upgrade(V20200409083200_RemoveRootQueriesFromMigratedDashboards.java:96) ~[graylog.jar:?]
- at org.graylog2.periodical.ConfigurationManagementPeriodical.doRun(ConfigurationManagementPeriodical.java:42) [graylog.jar:?]
- at org.graylog2.plugin.periodical.Periodical.run(Periodical.java:77) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:27:30.141-03:00 INFO [NetworkListener] Started listener bound to [172.16.2.131:9000]
- 2020-11-20T16:27:30.143-03:00 INFO [HttpServer] [HttpServer] Started.
- 2020-11-20T16:27:30.143-03:00 INFO [JerseyService] Started REST API at <172.16.2.131:9000>
- 2020-11-20T16:27:30.144-03:00 INFO [ServerBootstrap] Services started, startup times in ms: {InputSetupService [RUNNING]=29, EtagService [RUNNING]=116, OutputSetupService [RUNNING]=117, UrlWhitelistService [RUNNING]=118, JobSchedulerService [RUNNING]=126, BufferSynchronizerService [RUNNING]=126, JournalReader [RUNNING]=127, GracefulShutdownService [RUNNING]=128, ConfigurationEtagService [RUNNING]=132, KafkaJournal [RUNNING]=133, MongoDBProcessingStatusRecorderService [RUNNING]=205, StreamCacheService [RUNNING]=222, PeriodicalsService [RUNNING]=316, LookupTableService [RUNNING]=409, JerseyService [RUNNING]=19448}
- 2020-11-20T16:27:30.146-03:00 INFO [ServiceManagerListener] Services are healthy
- 2020-11-20T16:27:30.147-03:00 INFO [InputSetupService] Triggering launching persisted inputs, node transitioned from Uninitialized [LB:DEAD] to Running [LB:ALIVE]
- 2020-11-20T16:27:30.147-03:00 INFO [ServerBootstrap] Graylog server up and running.
- 2020-11-20T16:27:30.186-03:00 INFO [InputStateListener] Input [Syslog UDP/59b1a628af963c249eaced4b] is now STARTING
- 2020-11-20T16:27:30.200-03:00 INFO [InputStateListener] Input [Syslog UDP/59c90186af963c0396e166e4] is now STARTING
- 2020-11-20T16:27:30.200-03:00 INFO [InputStateListener] Input [Syslog UDP/5de115193bbc825575f5cd6e] is now STARTING
- 2020-11-20T16:27:30.201-03:00 INFO [InputStateListener] Input [Syslog UDP/5ba13aae3bbc820310494f89] is now STARTING
- 2020-11-20T16:27:30.203-03:00 INFO [InputStateListener] Input [Syslog UDP/5bc0dc763bbc8203106b9925] is now STARTING
- 2020-11-20T16:27:30.204-03:00 INFO [InputStateListener] Input [Syslog UDP/5ec690e43bbc8233761d539c] is now STARTING
- 2020-11-20T16:27:30.205-03:00 INFO [InputStateListener] Input [Syslog UDP/5eb337343bbc821e37698f1e] is now STARTING
- 2020-11-20T16:27:30.210-03:00 INFO [InputStateListener] Input [Syslog UDP/5a09dc89af963c03b73c3647] is now STARTING
- 2020-11-20T16:27:30.228-03:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/59db6a6caf963c03af1db25e] is now STARTING
- 2020-11-20T16:27:30.334-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Unifi controller, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x6503879c, L:/0:0:0:0:0:0:0:0%0:5521]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.334-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=DNS, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x9411a1f6, L:/0:0:0:0:0:0:0:0%0:5530]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.334-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Bind non queries log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xf88409ad, L:/0:0:0:0:0:0:0:0%0:5522]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.335-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Fastnetmon, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=null} (channel [id: 0x76f12094, L:/0:0:0:0:0:0:0:0%0:5515]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.335-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Routers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x610aed54, L:/0:0:0:0:0:0:0:0%0:5516]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.335-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog UDP 5514, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xee89cad2, L:/0:0:0:0:0:0:0:0%0:5514]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.335-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Firewall, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xe9d63fc8, L:/0:0:0:0:0:0:0:0%0:5519]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.335-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Linux servers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x9046a9bb, L:/0:0:0:0:0:0:0:0%0:5517]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.335-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Tickets, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x5b178336, L:/0:0:0:0:0:0:0:0%0:5529]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.355-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Firewall, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x11b76b4f, L:/0:0:0:0:0:0:0:0%0:5519]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.355-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog UDP 5514, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x549e0254, L:/0:0:0:0:0:0:0:0%0:5514]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.356-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Routers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x4876ae93, L:/0:0:0:0:0:0:0:0%0:5516]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.359-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Unifi controller, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x351ad915, L:/0:0:0:0:0:0:0:0%0:5521]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.362-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Linux servers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x6f9ffba9, L:/0:0:0:0:0:0:0:0%0:5517]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.378-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Tickets, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x688b3260, L:/0:0:0:0:0:0:0:0%0:5529]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.378-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Fastnetmon, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=null} (channel [id: 0x2b18ddea, L:/0:0:0:0:0:0:0:0%0:5515]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.389-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog UDP 5514, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xd215e039, L:/0:0:0:0:0:0:0:0%0:5514]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.389-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Routers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x53ddc83a, L:/0:0:0:0:0:0:0:0%0:5516]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.390-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Linux servers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x3e36d53a, L:/0:0:0:0:0:0:0:0%0:5517]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.392-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Firewall, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x0e1259fa, L:/0:0:0:0:0:0:0:0%0:5519]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.398-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=DNS, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x6f1c5287, L:/0:0:0:0:0:0:0:0%0:5530]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.399-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Bind non queries log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xecad6a18, L:/0:0:0:0:0:0:0:0%0:5522]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.487-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Unifi controller, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x6ad8ebf8, L:/0:0:0:0:0:0:0:0%0:5521]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.487-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Tickets, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x259aab61, L:/0:0:0:0:0:0:0:0%0:5529]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.514-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Linux servers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xbd2ff88f, L:/0:0:0:0:0:0:0:0%0:5517]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.514-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog UDP 5514, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xe414bed3, L:/0:0:0:0:0:0:0:0%0:5514]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.529-03:00 INFO [InputStateListener] Input [Syslog UDP/5a09dc89af963c03b73c3647] is now RUNNING
- 2020-11-20T16:27:30.531-03:00 INFO [InputStateListener] Input [Syslog UDP/5de115193bbc825575f5cd6e] is now RUNNING
- 2020-11-20T16:27:30.542-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Fastnetmon, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=null} (channel [id: 0xfeafda5a, L:/0:0:0:0:0:0:0:0%0:5515]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.575-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=DNS, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xdd1d93a2, L:/0:0:0:0:0:0:0:0%0:5530]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.577-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Firewall, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xa4960328, L:/0:0:0:0:0:0:0:0%0:5519]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.577-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Routers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xe5e2d35a, L:/0:0:0:0:0:0:0:0%0:5516]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.579-03:00 INFO [InputStateListener] Input [Syslog UDP/59c90186af963c0396e166e4] is now RUNNING
- 2020-11-20T16:27:30.580-03:00 INFO [InputStateListener] Input [Syslog UDP/5bc0dc763bbc8203106b9925] is now RUNNING
- 2020-11-20T16:27:30.711-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Bind non queries log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xd6d55d8d, L:/0:0:0:0:0:0:0:0%0:5522]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.711-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Unifi controller, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x0db67685, L:/0:0:0:0:0:0:0:0%0:5521]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.711-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Fastnetmon, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=null} (channel [id: 0x563eec02, L:/0:0:0:0:0:0:0:0%0:5515]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.712-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Tickets, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xacc01608, L:/0:0:0:0:0:0:0:0%0:5529]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.717-03:00 INFO [InputStateListener] Input [Syslog UDP/5ba13aae3bbc820310494f89] is now RUNNING
- 2020-11-20T16:27:30.718-03:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/59db6a6caf963c03af1db25e] is now RUNNING
- 2020-11-20T16:27:30.719-03:00 INFO [InputStateListener] Input [Syslog UDP/59b1a628af963c249eaced4b] is now RUNNING
- 2020-11-20T16:27:30.741-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=DNS, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x3574a0a4, L:/0:0:0:0:0:0:0:0%0:5530]) should be 262144 but is 425984.
- 2020-11-20T16:27:30.743-03:00 INFO [InputStateListener] Input [Syslog UDP/5eb337343bbc821e37698f1e] is now RUNNING
- 2020-11-20T16:27:30.748-03:00 INFO [InputStateListener] Input [Syslog UDP/5ec690e43bbc8233761d539c] is now RUNNING
- 2020-11-20T16:27:30.749-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Bind non queries log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x0a6585cd, L:/0:0:0:0:0:0:0:0%0:5522]) should be 262144 but is 425984.
- 2020-11-20T16:28:47.044-03:00 INFO [Server] SIGNAL received. Shutting down.
- 2020-11-20T16:28:47.045-03:00 INFO [GracefulShutdown] Graceful shutdown initiated.
- 2020-11-20T16:28:47.046-03:00 INFO [GracefulShutdown] Node status: [Halting [LB:DEAD]]. Waiting <3sec> for possible load balancers to recognize state change.
- 2020-11-20T16:28:51.048-03:00 INFO [InputSetupService] Attempting to close input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5ec690e43bbc8233761d539c> [Syslog UDP].
- 2020-11-20T16:28:51.055-03:00 INFO [InputSetupService] Input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5ec690e43bbc8233761d539c> closed. Took [6ms]
- 2020-11-20T16:28:51.055-03:00 INFO [InputSetupService] Attempting to close input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5a09dc89af963c03b73c3647> [Syslog UDP].
- 2020-11-20T16:28:51.060-03:00 INFO [InputSetupService] Input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5a09dc89af963c03b73c3647> closed. Took [4ms]
- 2020-11-20T16:28:51.060-03:00 INFO [InputSetupService] Attempting to close input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5ba13aae3bbc820310494f89> [Syslog UDP].
- 2020-11-20T16:28:51.065-03:00 INFO [InputSetupService] Input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5ba13aae3bbc820310494f89> closed. Took [5ms]
- 2020-11-20T16:28:51.065-03:00 INFO [InputSetupService] Attempting to close input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.59b1a628af963c249eaced4b> [Syslog UDP].
- 2020-11-20T16:28:51.068-03:00 INFO [InputSetupService] Input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.59b1a628af963c249eaced4b> closed. Took [2ms]
- 2020-11-20T16:28:51.068-03:00 INFO [InputSetupService] Attempting to close input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.59c90186af963c0396e166e4> [Syslog UDP].
- 2020-11-20T16:28:51.073-03:00 INFO [InputSetupService] Input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.59c90186af963c0396e166e4> closed. Took [4ms]
- 2020-11-20T16:28:51.073-03:00 INFO [InputSetupService] Attempting to close input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5bc0dc763bbc8203106b9925> [Syslog UDP].
- 2020-11-20T16:28:51.074-03:00 INFO [InputSetupService] Input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5bc0dc763bbc8203106b9925> closed. Took [1ms]
- 2020-11-20T16:28:51.074-03:00 INFO [InputSetupService] Attempting to close input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5eb337343bbc821e37698f1e> [Syslog UDP].
- 2020-11-20T16:28:51.077-03:00 INFO [InputSetupService] Input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5eb337343bbc821e37698f1e> closed. Took [3ms]
- 2020-11-20T16:28:51.077-03:00 INFO [InputSetupService] Attempting to close input <org.graylog2.inputs.raw.udp.RawUDPInput.59db6a6caf963c03af1db25e> [Raw/Plaintext UDP].
- 2020-11-20T16:28:51.081-03:00 INFO [InputSetupService] Input <org.graylog2.inputs.raw.udp.RawUDPInput.59db6a6caf963c03af1db25e> closed. Took [3ms]
- 2020-11-20T16:28:51.081-03:00 INFO [InputSetupService] Attempting to close input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5de115193bbc825575f5cd6e> [Syslog UDP].
- 2020-11-20T16:28:51.082-03:00 INFO [InputSetupService] Input <org.graylog2.inputs.syslog.udp.SyslogUDPInput.5de115193bbc825575f5cd6e> closed. Took [1ms]
- 2020-11-20T16:28:51.098-03:00 INFO [Buffers] Waiting until all buffers are empty.
- 2020-11-20T16:28:51.099-03:00 INFO [Buffers] All buffers are empty. Continuing.
- 2020-11-20T16:28:51.100-03:00 INFO [OutputSetupService] Stopping output org.graylog2.outputs.BlockingBatchedESOutput
- 2020-11-20T16:28:51.103-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.BatchedElasticSearchOutputFlushThread].
- 2020-11-20T16:28:51.103-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.BatchedElasticSearchOutputFlushThread] complete, took <0ms>.
- 2020-11-20T16:28:51.103-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.ClusterHealthCheckThread].
- 2020-11-20T16:28:51.103-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.ClusterHealthCheckThread] complete, took <0ms>.
- 2020-11-20T16:28:51.103-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.IndexerClusterCheckerThread].
- 2020-11-20T16:28:51.103-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.IndexerClusterCheckerThread] complete, took <0ms>.
- 2020-11-20T16:28:51.103-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.IndexRetentionThread].
- 2020-11-20T16:28:51.103-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.IndexRetentionThread] complete, took <0ms>.
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.IndexRotationThread].
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.IndexRotationThread] complete, took <0ms>.
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.VersionCheckThread].
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.VersionCheckThread] complete, took <0ms>.
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.ThrottleStateUpdaterThread].
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.ThrottleStateUpdaterThread] complete, took <0ms>.
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.events.ClusterEventPeriodical].
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.events.ClusterEventPeriodical] complete, took <0ms>.
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.events.ClusterEventCleanupPeriodical].
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.events.ClusterEventCleanupPeriodical] complete, took <0ms>.
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.IndexRangesCleanupPeriodical].
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.IndexRangesCleanupPeriodical] complete, took <0ms>.
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.TrafficCounterCalculator].
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.TrafficCounterCalculator] complete, took <0ms>.
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.indexer.fieldtypes.IndexFieldTypePollerPeriodical].
- 2020-11-20T16:28:51.104-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.indexer.fieldtypes.IndexFieldTypePollerPeriodical] complete, took <0ms>.
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog.scheduler.periodicals.ScheduleTriggerCleanUp].
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog.scheduler.periodicals.ScheduleTriggerCleanUp] complete, took <0ms>.
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog2.periodical.ESVersionCheckPeriodical].
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog2.periodical.ESVersionCheckPeriodical] complete, took <0ms>.
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog.plugins.sidecar.periodical.PurgeExpiredSidecarsThread].
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog.plugins.sidecar.periodical.PurgeExpiredSidecarsThread] complete, took <0ms>.
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog.plugins.sidecar.periodical.PurgeExpiredConfigurationUploads].
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog.plugins.sidecar.periodical.PurgeExpiredConfigurationUploads] complete, took <0ms>.
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog.plugins.views.search.db.SearchesCleanUpJob].
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog.plugins.views.search.db.SearchesCleanUpJob] complete, took <0ms>.
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog.events.periodicals.EventNotificationStatusCleanUp].
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog.events.periodicals.EventNotificationStatusCleanUp] complete, took <0ms>.
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutting down periodical [org.graylog.plugins.collector.periodical.PurgeExpiredCollectorsThread].
- 2020-11-20T16:28:51.105-03:00 INFO [PeriodicalsService] Shutdown of periodical [org.graylog.plugins.collector.periodical.PurgeExpiredCollectorsThread] complete, took <0ms>.
- 2020-11-20T16:28:51.107-03:00 INFO [GracefulShutdownService] Running graceful shutdown for <2> shutdown hooks
- 2020-11-20T16:28:51.108-03:00 INFO [GracefulShutdownService] Initiate shutdown for <JobWorkerPool>
- 2020-11-20T16:28:51.108-03:00 INFO [GracefulShutdownService] Finished shutdown for <JobWorkerPool>, took 0 ms
- 2020-11-20T16:28:51.108-03:00 INFO [GracefulShutdownService] Initiate shutdown for <RestHighLevelClientProvider$$Lambda$331/1036227602>
- 2020-11-20T16:28:51.109-03:00 INFO [GracefulShutdownService] Finished shutdown for <RestHighLevelClientProvider$$Lambda$331/1036227602>, took 0 ms
- 2020-11-20T16:28:51.110-03:00 INFO [GracefulShutdown] Goodbye.
- 2020-11-20T16:28:51.110-03:00 INFO [JerseyService] Shutting down HTTP listener at <172.16.2.131:9000>
- 2020-11-20T16:28:51.114-03:00 INFO [LogManager] Shutting down.
- 2020-11-20T16:28:51.119-03:00 INFO [LookupTableService] Cache asn-cache-2/5d0255153bbc82032d37f487 [@7a86a672] STOPPING, was RUNNING
- 2020-11-20T16:28:51.123-03:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@1866aad7] STOPPING, was RUNNING
- 2020-11-20T16:28:51.131-03:00 INFO [LookupTableService] Cache queues2/5ee8fa9a326862721e884a34 [@49ed17c4] STOPPING, was RUNNING
- 2020-11-20T16:28:51.131-03:00 INFO [LookupTableService] Cache whois-cache/5a0ddf9baf963c0edc44fc62 [@110f4c6d] STOPPING, was RUNNING
- 2020-11-20T16:28:51.134-03:00 INFO [LookupTableService] Cache whois-cache/5a0ddf9baf963c0edc44fc62 [@110f4c6d] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.131-03:00 INFO [LookupTableService] Cache asn-cache-2/5d0255153bbc82032d37f487 [@7a86a672] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.135-03:00 INFO [LookupTableService] Cache queues2/5ee8fa9a326862721e884a34 [@49ed17c4] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.135-03:00 INFO [LookupTableService] Data Adapter asn-adapter/5c6aac273bbc820e9060a043 [@1c7ba9cd] STOPPING, was RUNNING
- 2020-11-20T16:28:51.131-03:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5a0ddf9baf963c0edc44fc63 [@316385ae] STOPPING, was RUNNING
- 2020-11-20T16:28:51.135-03:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5a0ddf9baf963c0edc44fc63 [@316385ae] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@1866aad7] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5a0ddf9baf963c0edc44fc67 [@7f79be22] STOPPING, was RUNNING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc68 [@64135161] STOPPING, was RUNNING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter otx-ip/5a0ddf9baf963c0edc44fc6c [@766ecdd3] STOPPING, was RUNNING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5a0ddf9baf963c0edc44fc67 [@7f79be22] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc68 [@64135161] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter whois/5a0ddf9baf963c0edc44fc6a [@474e3c9d] STOPPING, was RUNNING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter tor-exit-node/5a0ddf9baf963c0edc44fc6b [@7c24d038] STOPPING, was RUNNING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter tor-exit-node/5a0ddf9baf963c0edc44fc6b [@7c24d038] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter aria_json/5ee8de9d326862721e882bd2 [@2f96f1d1] STOPPING, was RUNNING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter queue-name-adapter/5c8114153bbc820783336b95 [@2f16a1b5] STOPPING, was RUNNING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter aria_json/5ee8de9d326862721e882bd2 [@2f96f1d1] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.143-03:00 INFO [LookupTableService] Data Adapter queue-name-adapter/5c8114153bbc820783336b95 [@2f16a1b5] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.142-03:00 INFO [LookupTableService] Data Adapter otx-ip/5a0ddf9baf963c0edc44fc6c [@766ecdd3] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.143-03:00 INFO [LookupTableService] Data Adapter asn-adapter/5c6aac273bbc820e9060a043 [@1c7ba9cd] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.147-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc6d [@2c916636] STOPPING, was RUNNING
- 2020-11-20T16:28:51.147-03:00 INFO [LookupDataAdapterRefreshService] Stopping 0 jobs
- 2020-11-20T16:28:51.147-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc6d [@2c916636] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.147-03:00 INFO [LookupTableService] Data Adapter whois/5a0ddf9baf963c0edc44fc6a [@474e3c9d] TERMINATED, was STOPPING
- 2020-11-20T16:28:51.153-03:00 INFO [JournalReader] Stopping.
- 2020-11-20T16:28:51.168-03:00 INFO [NetworkListener] Stopped listener bound to [172.16.2.131:9000]
- 2020-11-20T16:28:51.197-03:00 INFO [LogManager] Shutdown complete.
- 2020-11-20T16:28:51.241-03:00 INFO [ServiceManagerListener] Services are now stopped.
- 2020-11-20T16:28:52.721-03:00 INFO [CmdLineTool] Loaded plugin: AWS plugins 4.0.0 [org.graylog.aws.AWSPlugin]
- 2020-11-20T16:28:52.724-03:00 INFO [CmdLineTool] Loaded plugin: Collector 4.0.0 [org.graylog.plugins.collector.CollectorPlugin]
- 2020-11-20T16:28:52.725-03:00 INFO [CmdLineTool] Loaded plugin: Threat Intelligence Plugin 4.0.0 [org.graylog.plugins.threatintel.ThreatIntelPlugin]
- 2020-11-20T16:28:52.725-03:00 INFO [CmdLineTool] Loaded plugin: SnmpPlugin 0.3.0 [org.graylog.snmp.SnmpPlugin]
- 2020-11-20T16:28:52.725-03:00 INFO [CmdLineTool] Loaded plugin: Elasticsearch 6 Support 4.0.0+9376305 [org.graylog.storage.elasticsearch6.Elasticsearch6Plugin]
- 2020-11-20T16:28:52.725-03:00 INFO [CmdLineTool] Loaded plugin: Elasticsearch 7 Support 4.0.0+9376305 [org.graylog.storage.elasticsearch7.Elasticsearch7Plugin]
- 2020-11-20T16:28:52.914-03:00 INFO [CmdLineTool] Running with JVM arguments: -Xms4g -Xmx4g -XX:NewRatio=1 -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow -XX:+UseParNewGC -Dlog4j.configurationFile=file:///etc/graylog/server/log4j2.xml -Djava.library.path=/usr/share/graylog-server/lib/sigar -Dgraylog2.installation_source=deb
- 2020-11-20T16:28:53.104-03:00 INFO [Version] HV000001: Hibernate Validator null
- 2020-11-20T16:28:55.640-03:00 INFO [InputBufferImpl] Message journal is enabled.
- 2020-11-20T16:28:55.658-03:00 INFO [NodeId] Node ID: ddbb0e96-67f6-4d67-b8f7-0d2e074b608b
- 2020-11-20T16:28:55.830-03:00 INFO [LogManager] Loading logs.
- 2020-11-20T16:28:55.889-03:00 INFO [LogManager] Logs loading complete.
- 2020-11-20T16:28:55.892-03:00 INFO [KafkaJournal] Initialized Kafka based journal at /var/lib/graylog-server/journal
- 2020-11-20T16:28:55.915-03:00 INFO [cluster] Cluster created with settings {hosts=[localhost:27017], mode=SINGLE, requiredClusterType=UNKNOWN, serverSelectionTimeout='30000 ms', maxWaitQueueSize=5000}
- 2020-11-20T16:28:55.967-03:00 INFO [cluster] Cluster description not yet available. Waiting for 30000 ms before timing out
- 2020-11-20T16:28:55.979-03:00 INFO [connection] Opened connection [connectionId{localValue:1, serverValue:43}] to localhost:27017
- 2020-11-20T16:28:55.982-03:00 INFO [cluster] Monitor thread successfully connected to server with description ServerDescription{address=localhost:27017, type=STANDALONE, state=CONNECTED, ok=true, version=ServerVersion{versionList=[2, 6, 10]}, minWireVersion=0, maxWireVersion=2, maxDocumentSize=16777216, logicalSessionTimeoutMinutes=null, roundTripTimeNanos=1226468}
- 2020-11-20T16:28:55.994-03:00 INFO [connection] Opened connection [connectionId{localValue:2, serverValue:44}] to localhost:27017
- 2020-11-20T16:28:56.195-03:00 INFO [InputBufferImpl] Initialized InputBufferImpl with ring size <65536> and wait strategy <BlockingWaitStrategy>, running 4 parallel message handlers.
- 2020-11-20T16:28:56.465-03:00 INFO [ElasticsearchVersionProvider] Elasticsearch cluster is running v6.8.8
- 2020-11-20T16:28:56.505-03:00 INFO [AbstractJestClient] Setting server pool to a list of 1 servers: [http://172.16.2.240:9200]
- 2020-11-20T16:28:56.506-03:00 INFO [JestClientFactory] Using multi thread/connection supporting pooling connection manager
- 2020-11-20T16:28:56.564-03:00 INFO [JestClientFactory] Using custom ObjectMapper instance
- 2020-11-20T16:28:56.565-03:00 INFO [JestClientFactory] Node Discovery enabled...
- 2020-11-20T16:28:56.577-03:00 INFO [JestClientFactory] Idle connection reaping disabled...
- 2020-11-20T16:28:57.011-03:00 INFO [ProcessBuffer] Initialized ProcessBuffer with ring size <131072> and wait strategy <BlockingWaitStrategy>.
- 2020-11-20T16:28:57.269-03:00 INFO [OutputBuffer] Initialized OutputBuffer with ring size <131072> and wait strategy <BlockingWaitStrategy>.
- 2020-11-20T16:28:57.301-03:00 INFO [connection] Opened connection [connectionId{localValue:3, serverValue:45}] to localhost:27017
- 2020-11-20T16:28:57.997-03:00 INFO [ServerBootstrap] Graylog server 4.0.0+9376305 starting up
- 2020-11-20T16:28:57.997-03:00 INFO [ServerBootstrap] JRE: Private Build 1.8.0_275 on Linux 4.4.0-194-generic
- 2020-11-20T16:28:57.998-03:00 INFO [ServerBootstrap] Deployment: deb
- 2020-11-20T16:28:57.998-03:00 INFO [ServerBootstrap] OS: Ubuntu 16.04.7 LTS (xenial)
- 2020-11-20T16:28:57.998-03:00 INFO [ServerBootstrap] Arch: amd64
- 2020-11-20T16:28:58.028-03:00 INFO [PeriodicalsService] Starting 30 periodicals ...
- 2020-11-20T16:28:58.028-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ThroughputCalculator] periodical in [0s], polling every [1s].
- 2020-11-20T16:28:58.034-03:00 INFO [Periodicals] Starting [org.graylog.plugins.pipelineprocessor.periodical.LegacyDefaultStreamMigration] periodical, running forever.
- 2020-11-20T16:28:58.035-03:00 INFO [PeriodicalsService] Not starting [org.graylog2.periodical.AlertScannerThread] periodical. Not configured to run on this node.
- 2020-11-20T16:28:58.035-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.BatchedElasticSearchOutputFlushThread] periodical in [0s], polling every [1s].
- 2020-11-20T16:28:58.152-03:00 INFO [LegacyDefaultStreamMigration] Legacy default stream has no connections, no migration needed.
- 2020-11-20T16:28:58.155-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ClusterHealthCheckThread] periodical in [120s], polling every [20s].
- 2020-11-20T16:28:58.169-03:00 INFO [PeriodicalsService] Not starting [org.graylog2.periodical.ContentPackLoaderPeriodical] periodical. Not configured to run on this node.
- 2020-11-20T16:28:58.169-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.GarbageCollectionWarningThread] periodical, running forever.
- 2020-11-20T16:28:58.170-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexerClusterCheckerThread] periodical in [0s], polling every [30s].
- 2020-11-20T16:28:58.170-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRetentionThread] periodical in [0s], polling every [300s].
- 2020-11-20T16:28:58.170-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRotationThread] periodical in [0s], polling every [10s].
- 2020-11-20T16:28:58.171-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.NodePingThread] periodical in [0s], polling every [1s].
- 2020-11-20T16:28:58.171-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.VersionCheckThread] periodical in [300s], polling every [1800s].
- 2020-11-20T16:28:58.171-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ThrottleStateUpdaterThread] periodical in [1s], polling every [1s].
- 2020-11-20T16:28:58.171-03:00 INFO [Periodicals] Starting [org.graylog2.events.ClusterEventPeriodical] periodical in [0s], polling every [1s].
- 2020-11-20T16:28:58.172-03:00 INFO [Periodicals] Starting [org.graylog2.events.ClusterEventCleanupPeriodical] periodical in [0s], polling every [86400s].
- 2020-11-20T16:28:58.172-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ClusterIdGeneratorPeriodical] periodical, running forever.
- 2020-11-20T16:28:58.173-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRangesMigrationPeriodical] periodical, running forever.
- 2020-11-20T16:28:58.173-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexRangesCleanupPeriodical] periodical in [15s], polling every [3600s].
- 2020-11-20T16:28:58.181-03:00 INFO [connection] Opened connection [connectionId{localValue:4, serverValue:46}] to localhost:27017
- 2020-11-20T16:28:58.197-03:00 INFO [connection] Opened connection [connectionId{localValue:5, serverValue:47}] to localhost:27017
- 2020-11-20T16:28:58.214-03:00 INFO [connection] Opened connection [connectionId{localValue:6, serverValue:48}] to localhost:27017
- 2020-11-20T16:28:58.214-03:00 INFO [PeriodicalsService] Not starting [org.graylog2.periodical.UserPermissionMigrationPeriodical] periodical. Not configured to run on this node.
- 2020-11-20T16:28:58.228-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ConfigurationManagementPeriodical] periodical, running forever.
- 2020-11-20T16:28:58.238-03:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5a0ddf9baf963c0edc44fc67 [@7fe3c5e9] STARTING
- 2020-11-20T16:28:58.239-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc6d [@2fcee274] STARTING
- 2020-11-20T16:28:58.239-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc68 [@118b4aeb] STARTING
- 2020-11-20T16:28:58.239-03:00 INFO [LookupTableService] Data Adapter tor-exit-node/5a0ddf9baf963c0edc44fc6b [@3ad3f478] STARTING
- 2020-11-20T16:28:58.239-03:00 INFO [LookupTableService] Data Adapter asn-adapter/5c6aac273bbc820e9060a043 [@2a99d733] STARTING
- 2020-11-20T16:28:58.242-03:00 INFO [LookupTableService] Data Adapter otx-ip/5a0ddf9baf963c0edc44fc6c [@a9bb76b] STARTING
- 2020-11-20T16:28:58.243-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.IndexFailuresPeriodical] periodical, running forever.
- 2020-11-20T16:28:58.243-03:00 INFO [LookupTableService] Data Adapter whois/5a0ddf9baf963c0edc44fc6a [@4a2d2b1e] STARTING
- 2020-11-20T16:28:58.217-03:00 ERROR [LookupDataAdapter] Couldn't start data adapter <abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc68/@118b4aeb>
- org.graylog.plugins.threatintel.tools.AdapterDisabledException: Abuse.ch service is disabled, not starting adapter. To enable it please go to System / Configurations.
- at org.graylog.plugins.threatintel.adapters.abusech.AbuseChRansomAdapter.doStart(AbuseChRansomAdapter.java:96) ~[?:?]
- at org.graylog2.plugin.lookup.LookupDataAdapter.startUp(LookupDataAdapter.java:79) [graylog.jar:?]
- at com.google.common.util.concurrent.AbstractIdleService$DelegateService$1.run(AbstractIdleService.java:62) [graylog.jar:?]
- at com.google.common.util.concurrent.Callables$4.run(Callables.java:119) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:28:58.247-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.TrafficCounterCalculator] periodical in [0s], polling every [1s].
- 2020-11-20T16:28:58.248-03:00 INFO [Periodicals] Starting [org.graylog2.indexer.fieldtypes.IndexFieldTypePollerPeriodical] periodical in [0s], polling every [3600s].
- 2020-11-20T16:28:58.248-03:00 INFO [Periodicals] Starting [org.graylog.scheduler.periodicals.ScheduleTriggerCleanUp] periodical in [120s], polling every [86400s].
- 2020-11-20T16:28:58.248-03:00 INFO [Periodicals] Starting [org.graylog2.periodical.ESVersionCheckPeriodical] periodical in [0s], polling every [30s].
- 2020-11-20T16:28:58.248-03:00 INFO [Periodicals] Starting [org.graylog.plugins.sidecar.periodical.PurgeExpiredSidecarsThread] periodical in [0s], polling every [600s].
- 2020-11-20T16:28:58.248-03:00 INFO [Periodicals] Starting [org.graylog.plugins.sidecar.periodical.PurgeExpiredConfigurationUploads] periodical in [0s], polling every [600s].
- 2020-11-20T16:28:58.248-03:00 INFO [Periodicals] Starting [org.graylog.plugins.views.search.db.SearchesCleanUpJob] periodical in [3600s], polling every [28800s].
- 2020-11-20T16:28:58.249-03:00 INFO [Periodicals] Starting [org.graylog.events.periodicals.EventNotificationStatusCleanUp] periodical in [120s], polling every [86400s].
- 2020-11-20T16:28:58.249-03:00 INFO [Periodicals] Starting [org.graylog.plugins.collector.periodical.PurgeExpiredCollectorsThread] periodical in [0s], polling every [3600s].
- 2020-11-20T16:28:58.252-03:00 ERROR [LookupDataAdapter] Couldn't start data adapter <spamhaus-drop/5a0ddf9baf963c0edc44fc67/@7fe3c5e9>
- org.graylog.plugins.threatintel.tools.AdapterDisabledException: Spamhaus service is disabled, not starting (E)DROP adapter. To enable it please go to System / Configurations.
- at org.graylog.plugins.threatintel.adapters.spamhaus.SpamhausEDROPDataAdapter.doStart(SpamhausEDROPDataAdapter.java:85) ~[?:?]
- at org.graylog2.plugin.lookup.LookupDataAdapter.startUp(LookupDataAdapter.java:79) [graylog.jar:?]
- at com.google.common.util.concurrent.AbstractIdleService$DelegateService$1.run(AbstractIdleService.java:62) [graylog.jar:?]
- at com.google.common.util.concurrent.Callables$4.run(Callables.java:119) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:28:58.252-03:00 ERROR [LookupDataAdapter] Couldn't start data adapter <abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc6d/@2fcee274>
- org.graylog.plugins.threatintel.tools.AdapterDisabledException: Abuse.ch service is disabled, not starting adapter. To enable it please go to System / Configurations.
- at org.graylog.plugins.threatintel.adapters.abusech.AbuseChRansomAdapter.doStart(AbuseChRansomAdapter.java:96) ~[?:?]
- at org.graylog2.plugin.lookup.LookupDataAdapter.startUp(LookupDataAdapter.java:79) [graylog.jar:?]
- at com.google.common.util.concurrent.AbstractIdleService$DelegateService$1.run(AbstractIdleService.java:62) [graylog.jar:?]
- at com.google.common.util.concurrent.Callables$4.run(Callables.java:119) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:28:58.255-03:00 ERROR [LookupDataAdapter] Couldn't start data adapter <tor-exit-node/5a0ddf9baf963c0edc44fc6b/@3ad3f478>
- org.graylog.plugins.threatintel.tools.AdapterDisabledException: TOR service is disabled, not starting TOR exit addresses adapter. To enable it please go to System / Configurations.
- at org.graylog.plugins.threatintel.adapters.tor.TorExitNodeDataAdapter.doStart(TorExitNodeDataAdapter.java:89) ~[?:?]
- at org.graylog2.plugin.lookup.LookupDataAdapter.startUp(LookupDataAdapter.java:79) [graylog.jar:?]
- at com.google.common.util.concurrent.AbstractIdleService$DelegateService$1.run(AbstractIdleService.java:62) [graylog.jar:?]
- at com.google.common.util.concurrent.Callables$4.run(Callables.java:119) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:28:58.256-03:00 INFO [LookupTableService] Data Adapter queue-name-adapter/5c8114153bbc820783336b95 [@61757a01] STARTING
- 2020-11-20T16:28:58.256-03:00 INFO [LookupTableService] Data Adapter aria_json/5ee8de9d326862721e882bd2 [@3602a9ab] STARTING
- 2020-11-20T16:28:58.256-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc68 [@118b4aeb] RUNNING
- 2020-11-20T16:28:58.257-03:00 INFO [LookupTableService] Data Adapter whois/5a0ddf9baf963c0edc44fc6a [@4a2d2b1e] RUNNING
- 2020-11-20T16:28:58.257-03:00 INFO [LookupTableService] Data Adapter spamhaus-drop/5a0ddf9baf963c0edc44fc67 [@7fe3c5e9] RUNNING
- 2020-11-20T16:28:58.258-03:00 INFO [LookupTableService] Data Adapter abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc6d [@2fcee274] RUNNING
- 2020-11-20T16:28:58.275-03:00 INFO [LookupTableService] Data Adapter tor-exit-node/5a0ddf9baf963c0edc44fc6b [@3ad3f478] RUNNING
- 2020-11-20T16:28:58.278-03:00 INFO [LookupTableService] Data Adapter asn-adapter/5c6aac273bbc820e9060a043 [@2a99d733] RUNNING
- 2020-11-20T16:28:58.278-03:00 INFO [LookupTableService] Data Adapter aria_json/5ee8de9d326862721e882bd2 [@3602a9ab] RUNNING
- 2020-11-20T16:28:58.279-03:00 INFO [LookupTableService] Data Adapter queue-name-adapter/5c8114153bbc820783336b95 [@61757a01] RUNNING
- 2020-11-20T16:28:58.278-03:00 INFO [LookupTableService] Data Adapter otx-ip/5a0ddf9baf963c0edc44fc6c [@a9bb76b] RUNNING
- 2020-11-20T16:28:58.345-03:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5a0ddf9baf963c0edc44fc63 [@5a901eb0] STARTING
- 2020-11-20T16:28:58.352-03:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@19fa40d8] STARTING
- 2020-11-20T16:28:58.352-03:00 INFO [LookupTableService] Cache whois-cache/5a0ddf9baf963c0edc44fc62 [@413c9dfa] STARTING
- 2020-11-20T16:28:58.352-03:00 INFO [LookupTableService] Cache asn-cache-2/5d0255153bbc82032d37f487 [@2487811c] STARTING
- 2020-11-20T16:28:58.360-03:00 INFO [LookupTableService] Cache queues2/5ee8fa9a326862721e884a34 [@8cf4100] STARTING
- 2020-11-20T16:28:58.382-03:00 INFO [LookupTableService] Cache spamhaus-e-drop-cache/5a0ddf9baf963c0edc44fc63 [@5a901eb0] RUNNING
- 2020-11-20T16:28:58.382-03:00 INFO [LookupTableService] Cache whois-cache/5a0ddf9baf963c0edc44fc62 [@413c9dfa] RUNNING
- 2020-11-20T16:28:58.382-03:00 INFO [LookupTableService] Cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@19fa40d8] RUNNING
- 2020-11-20T16:28:58.382-03:00 INFO [LookupTableService] Cache queues2/5ee8fa9a326862721e884a34 [@8cf4100] RUNNING
- 2020-11-20T16:28:58.382-03:00 INFO [LookupTableService] Cache asn-cache-2/5d0255153bbc82032d37f487 [@2487811c] RUNNING
- 2020-11-20T16:28:58.389-03:00 INFO [LookupTableService] Starting lookup table spamhaus-drop/5a0ddf9baf963c0edc44fc6f [@34f8bf02] using cache spamhaus-e-drop-cache/5a0ddf9baf963c0edc44fc63 [@5a901eb0], data adapter spamhaus-drop/5a0ddf9baf963c0edc44fc67 [@7fe3c5e9]
- 2020-11-20T16:28:58.389-03:00 INFO [LookupTableService] Starting lookup table whois/5a0ddf9baf963c0edc44fc70 [@405a48e6] using cache whois-cache/5a0ddf9baf963c0edc44fc62 [@413c9dfa], data adapter whois/5a0ddf9baf963c0edc44fc6a [@4a2d2b1e]
- 2020-11-20T16:28:58.390-03:00 INFO [LookupTableService] Starting lookup table tor-exit-node-list/5a0ddf9baf963c0edc44fc71 [@36e0029] using cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@19fa40d8], data adapter tor-exit-node/5a0ddf9baf963c0edc44fc6b [@3ad3f478]
- 2020-11-20T16:28:58.390-03:00 INFO [LookupTableService] Starting lookup table abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc73 [@289d5667] using cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@19fa40d8], data adapter abuse-ch-ransomware-domains/5a0ddf9baf963c0edc44fc6d [@2fcee274]
- 2020-11-20T16:28:58.390-03:00 INFO [LookupTableService] Starting lookup table abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc74 [@59ececd9] using cache threat-intel-uncached-adapters/5a0ddf9baf963c0edc44fc64 [@19fa40d8], data adapter abuse-ch-ransomware-ip/5a0ddf9baf963c0edc44fc68 [@118b4aeb]
- 2020-11-20T16:28:58.390-03:00 INFO [LookupTableService] Starting lookup table asn-lkt/5c6aac733bbc820e9060a098 [@4be3927a] using cache asn-cache-2/5d0255153bbc82032d37f487 [@2487811c], data adapter asn-adapter/5c6aac273bbc820e9060a043 [@2a99d733]
- 2020-11-20T16:28:58.390-03:00 INFO [LookupTableService] Starting lookup table q-lkp/5c81178c3bbc820783337630 [@38ffac67] using cache queues2/5ee8fa9a326862721e884a34 [@8cf4100], data adapter aria_json/5ee8de9d326862721e882bd2 [@3602a9ab]
- 2020-11-20T16:28:58.851-03:00 ERROR [ConfigurationManagementPeriodical] Error while running migration <V20190705071400_AddEventIndexSetsMigration{2019-07-05T07:14:00Z}>
- java.lang.IllegalStateException: Index prefix conflict: a non-events index-set with prefix <gl-events> already exists. Configure a different <default_events_index_prefix> value in the server config file.
- at org.graylog2.migrations.V20190705071400_AddEventIndexSetsMigration.checkIndexPrefixConflicts(V20190705071400_AddEventIndexSetsMigration.java:130) ~[graylog.jar:?]
- at org.graylog2.migrations.V20190705071400_AddEventIndexSetsMigration.ensureEventsStreamAndIndexSet(V20190705071400_AddEventIndexSetsMigration.java:111) ~[graylog.jar:?]
- at org.graylog2.migrations.V20190705071400_AddEventIndexSetsMigration.upgrade(V20190705071400_AddEventIndexSetsMigration.java:84) ~[graylog.jar:?]
- at org.graylog2.periodical.ConfigurationManagementPeriodical.doRun(ConfigurationManagementPeriodical.java:42) [graylog.jar:?]
- at org.graylog2.plugin.periodical.Periodical.run(Periodical.java:77) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:28:59.021-03:00 ERROR [ConfigurationManagementPeriodical] Error while running migration <V20200409083200_RemoveRootQueriesFromMigratedDashboards{2020-04-09T08:32:00Z}>
- com.mongodb.MongoWriteException: cannot use the part (queries of queries.$[elem].query.query_string) to traverse the element ({queries: [ { id: "00000170-0c48-aa03-8788-00505694f28c", timerange: { type: "relative", range: 300 }, query: { type: "elasticsearch", query_string: "" }, search_types: [ { id: "00000170-0c48-a9ff-8788-00505694f28c", timerange: { type: "keyword", keyword: "last 6 hours" }, query: { type: "elasticsearch", query_string: "source:tickets" }, streams: [], name: "chart", series: [ { type: "count", id: "count()", field: null } ], sort: [ { type: "series", field: "ticket_cause", direction: "Descending" } ], rollup: true, type: "pivot", row_groups: [ { field: "ticket_cause", limit: 5, type: "values" } ], column_groups: [] }, { id: "00000170-0c48-aa01-8788-00505694f28c", timerange: { type: "relative", range: 21600 }, query: { type: "elasticsearch", query_string: "source:tickets" }, streams: [], name: "chart", series: [ { type: "count", id: "count()", field: null } ], sort: [ { type: "series", field: "ticket_nodo", direction: "Descending" } ], rollup: true, type: "pivot", row_groups: [ { field: "ticket_nodo", limit: 5, type: "values" } ], column_groups: [] }, { id: "00000170-0c48-aa00-8788-00505694f28c", timerange: { type: "keyword", keyword: "last 6 hours" }, query: { type: "elasticsearch", query_string: "source:tickets" }, streams: [], name: "chart", series: [ { type: "count", id: "count()", field: null } ], sort: [ { type: "series", field: "ticket_cause", direction: "Descending" } ], rollup: true, type: "pivot", row_groups: [ { field: "ticket_cause", limit: 50, type: "values" } ], column_groups: [] }, { id: "00000170-0c48-aa02-8788-00505694f28c", timerange: { type: "relative", range: 21600 }, query: { type: "elasticsearch", query_string: "source:tickets" }, streams: [], name: "chart", series: [ { type: "count", id: "count()", field: null } ], sort: [ { type: "series", field: "ticket_nodo", direction: "Descending" } ], rollup: true, type: "pivot", row_groups: [ { field: "ticket_nodo", limit: 50, type: "values" } ], column_groups: [] } ] } ]})
- at com.mongodb.client.internal.MongoCollectionImpl.executeSingleWriteRequest(MongoCollectionImpl.java:1060) ~[graylog.jar:?]
- at com.mongodb.client.internal.MongoCollectionImpl.executeUpdate(MongoCollectionImpl.java:1037) ~[graylog.jar:?]
- at com.mongodb.client.internal.MongoCollectionImpl.updateMany(MongoCollectionImpl.java:668) ~[graylog.jar:?]
- at org.graylog.plugins.views.migrations.V20200409083200_RemoveRootQueriesFromMigratedDashboards.upgrade(V20200409083200_RemoveRootQueriesFromMigratedDashboards.java:96) ~[graylog.jar:?]
- at org.graylog2.periodical.ConfigurationManagementPeriodical.doRun(ConfigurationManagementPeriodical.java:42) [graylog.jar:?]
- at org.graylog2.plugin.periodical.Periodical.run(Periodical.java:77) [graylog.jar:?]
- at java.lang.Thread.run(Thread.java:748) [?:1.8.0_275]
- 2020-11-20T16:29:17.315-03:00 INFO [NetworkListener] Started listener bound to [172.16.2.131:9000]
- 2020-11-20T16:29:17.316-03:00 INFO [HttpServer] [HttpServer] Started.
- 2020-11-20T16:29:17.316-03:00 INFO [JerseyService] Started REST API at <172.16.2.131:9000>
- 2020-11-20T16:29:17.317-03:00 INFO [ServiceManagerListener] Services are healthy
- 2020-11-20T16:29:17.317-03:00 INFO [InputSetupService] Triggering launching persisted inputs, node transitioned from Uninitialized [LB:DEAD] to Running [LB:ALIVE]
- 2020-11-20T16:29:17.317-03:00 INFO [ServerBootstrap] Services started, startup times in ms: {BufferSynchronizerService [RUNNING]=112, ConfigurationEtagService [RUNNING]=112, InputSetupService [RUNNING]=113, JournalReader [RUNNING]=113, UrlWhitelistService [RUNNING]=113, GracefulShutdownService [RUNNING]=114, JobSchedulerService [RUNNING]=119, OutputSetupService [RUNNING]=119, EtagService [RUNNING]=119, KafkaJournal [RUNNING]=120, MongoDBProcessingStatusRecorderService [RUNNING]=133, StreamCacheService [RUNNING]=157, PeriodicalsService [RUNNING]=237, LookupTableService [RUNNING]=376, JerseyService [RUNNING]=19303}
- 2020-11-20T16:29:17.326-03:00 INFO [ServerBootstrap] Graylog server up and running.
- 2020-11-20T16:29:17.365-03:00 INFO [InputStateListener] Input [Syslog UDP/59c90186af963c0396e166e4] is now STARTING
- 2020-11-20T16:29:17.366-03:00 INFO [InputStateListener] Input [Syslog UDP/5ba13aae3bbc820310494f89] is now STARTING
- 2020-11-20T16:29:17.367-03:00 INFO [InputStateListener] Input [Syslog UDP/5bc0dc763bbc8203106b9925] is now STARTING
- 2020-11-20T16:29:17.368-03:00 INFO [InputStateListener] Input [Syslog UDP/5de115193bbc825575f5cd6e] is now STARTING
- 2020-11-20T16:29:17.368-03:00 INFO [InputStateListener] Input [Syslog UDP/5ec690e43bbc8233761d539c] is now STARTING
- 2020-11-20T16:29:17.370-03:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/59db6a6caf963c03af1db25e] is now STARTING
- 2020-11-20T16:29:17.370-03:00 INFO [InputStateListener] Input [Syslog UDP/59b1a628af963c249eaced4b] is now STARTING
- 2020-11-20T16:29:17.371-03:00 INFO [InputStateListener] Input [Syslog UDP/5a09dc89af963c03b73c3647] is now STARTING
- 2020-11-20T16:29:17.379-03:00 INFO [InputStateListener] Input [Syslog UDP/5eb337343bbc821e37698f1e] is now STARTING
- 2020-11-20T16:29:17.491-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Fastnetmon, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=null} (channel [id: 0xfb08ff2a, L:/0:0:0:0:0:0:0:0%0:5515]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.491-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Bind non queries log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xa787ecda, L:/0:0:0:0:0:0:0:0%0:5522]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.491-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=DNS, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x62de39a6, L:/0:0:0:0:0:0:0:0%0:5530]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.491-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Routers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xdca252ad, L:/0:0:0:0:0:0:0:0%0:5516]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.491-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Linux servers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x3fa2f790, L:/0:0:0:0:0:0:0:0%0:5517]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.491-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Firewall, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x500c4f8d, L:/0:0:0:0:0:0:0:0%0:5519]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.491-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog UDP 5514, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x5f2b929a, L:/0:0:0:0:0:0:0:0%0:5514]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.491-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Tickets, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x7ab7a83a, L:/0:0:0:0:0:0:0:0%0:5529]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.492-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Unifi controller, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x10b05986, L:/0:0:0:0:0:0:0:0%0:5521]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.495-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=DNS, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x2b6faf19, L:/0:0:0:0:0:0:0:0%0:5530]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.496-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog UDP 5514, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xabdcdeef, L:/0:0:0:0:0:0:0:0%0:5514]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.496-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Linux servers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x7bd35077, L:/0:0:0:0:0:0:0:0%0:5517]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.505-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Tickets, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xa75f7605, L:/0:0:0:0:0:0:0:0%0:5529]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.505-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Bind non queries log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x688b4679, L:/0:0:0:0:0:0:0:0%0:5522]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.505-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Fastnetmon, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=null} (channel [id: 0x5ca2c299, L:/0:0:0:0:0:0:0:0%0:5515]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.505-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Routers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x2e19866c, L:/0:0:0:0:0:0:0:0%0:5516]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.515-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog UDP 5514, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x3d5f5529, L:/0:0:0:0:0:0:0:0%0:5514]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.515-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Tickets, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x9112af2f, L:/0:0:0:0:0:0:0:0%0:5529]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.516-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Firewall, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xff32123e, L:/0:0:0:0:0:0:0:0%0:5519]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.516-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=DNS, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x53820d2b, L:/0:0:0:0:0:0:0:0%0:5530]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.516-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Bind non queries log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xa732b853, L:/0:0:0:0:0:0:0:0%0:5522]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.521-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Fastnetmon, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=null} (channel [id: 0xc1285130, L:/0:0:0:0:0:0:0:0%0:5515]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.522-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Linux servers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x19799d47, L:/0:0:0:0:0:0:0:0%0:5517]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.522-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Routers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x92250817, L:/0:0:0:0:0:0:0:0%0:5516]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.530-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Unifi controller, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xe7bcdd1e, L:/0:0:0:0:0:0:0:0%0:5521]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.546-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=DNS, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x084b0556, L:/0:0:0:0:0:0:0:0%0:5530]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.550-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input RawUDPInput{title=Fastnetmon, type=org.graylog2.inputs.raw.udp.RawUDPInput, nodeId=null} (channel [id: 0x20d39f15, L:/0:0:0:0:0:0:0:0%0:5515]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.551-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Firewall, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xac26de48, L:/0:0:0:0:0:0:0:0%0:5519]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.550-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Syslog UDP 5514, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xb9adf113, L:/0:0:0:0:0:0:0:0%0:5514]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.556-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Bind non queries log, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xc3c3749b, L:/0:0:0:0:0:0:0:0%0:5522]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.559-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Unifi controller, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x7281e350, L:/0:0:0:0:0:0:0:0%0:5521]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.626-03:00 INFO [InputStateListener] Input [Syslog UDP/5eb337343bbc821e37698f1e] is now RUNNING
- 2020-11-20T16:29:17.636-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Linux servers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x84e01edf, L:/0:0:0:0:0:0:0:0%0:5517]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.636-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Tickets, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xfe5c49be, L:/0:0:0:0:0:0:0:0%0:5529]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.638-03:00 INFO [InputStateListener] Input [Syslog UDP/5a09dc89af963c03b73c3647] is now RUNNING
- 2020-11-20T16:29:17.636-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Routers, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xcdf92a71, L:/0:0:0:0:0:0:0:0%0:5516]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.650-03:00 INFO [InputStateListener] Input [Syslog UDP/5ec690e43bbc8233761d539c] is now RUNNING
- 2020-11-20T16:29:17.651-03:00 INFO [InputStateListener] Input [Syslog UDP/5ba13aae3bbc820310494f89] is now RUNNING
- 2020-11-20T16:29:17.652-03:00 INFO [InputStateListener] Input [Raw/Plaintext UDP/59db6a6caf963c03af1db25e] is now RUNNING
- 2020-11-20T16:29:17.653-03:00 INFO [InputStateListener] Input [Syslog UDP/59c90186af963c0396e166e4] is now RUNNING
- 2020-11-20T16:29:17.656-03:00 INFO [InputStateListener] Input [Syslog UDP/5de115193bbc825575f5cd6e] is now RUNNING
- 2020-11-20T16:29:17.687-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Firewall, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0x9920d752, L:/0:0:0:0:0:0:0:0%0:5519]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.688-03:00 INFO [InputStateListener] Input [Syslog UDP/5bc0dc763bbc8203106b9925] is now RUNNING
- 2020-11-20T16:29:17.699-03:00 WARN [UdpTransport] receiveBufferSize (SO_RCVBUF) for input SyslogUDPInput{title=Unifi controller, type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, nodeId=null} (channel [id: 0xc3bbdc02, L:/0:0:0:0:0:0:0:0%0:5521]) should be 262144 but is 425984.
- 2020-11-20T16:29:17.701-03:00 INFO [InputStateListener] Input [Syslog UDP/59b1a628af963c249eaced4b] is now RUNNING
- 2020-11-20T16:38:35.392-03:00 INFO [connection] Opened connection [connectionId{localValue:7, serverValue:49}] to localhost:27017
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement