WebMar 9, 2024 · Sorted by: 1. you can freely delete your indexes (from the indexes panel) in either graylog or elasticsearch, just recalculate your indexes after. you may want to update your retention policy to fit your storage availability. I would rotate them based on space, and then only keep the number of indexes you have room for. WebJan 26, 2024 · You can configure the strategy it uses to determine # when to rotate the currently active write index. # It supports multiple rotation strategies, the default being "count": # - "count" of messages per index, use elasticsearch_max_docs_per_index below to configure # - "size" per index, use elasticsearch_max_size_per_index below to …
Optimizing indices after index rotation blocks master …
WebAug 21, 2024 · I’ve setup graylog about half a year ago. I have an index to collect logs from our FortiGates, I want to store the logs for about half a year. This is why I’ve set the Rotation Period to P1D (1 Day) and Max number of indices to 180. ... To force a rotation you could restart graylog or make a change to the strategies or index to get it going ... WebGraylog nodes constantly keep track of every indexing operation they perform. This helps to make sure they don't unintentionally lose any messages. The web interface can show you a number of write operations that failed and also a list of failed operations. how many days since january 21 2023
Can
WebApr 5, 2024 · 1: Set your indexes to time-based rotation; because the ILM policies trigger on size, index age, or document count. If both Graylog and ILM trigger on an index (size, count), you’re in for a bad time, so you need time based rotation. I personally use P1D. WebDec 9, 2024 · 1. Describe your incident: I would like to try GL5 with Opensearch but the log keeps saying unable to start because connection to ES cannot be established. 2. Describe your environment: OS Information: Ubuntu 20.04.04 Package Version: GL5, OS2.0.1 Service logs, configurations, and environment variables: Vanilla installation, all default … WebDec 1, 2024 · It looks like Graylog is not able to rotate and create new index. It just grows that latests one from default index set. Otherwise it seem to work. This is docker composer environment with Mongodb 3.6.21 Graylog 4.0.1 Elasticsearch 7.10.0 (from 6.8.13) Interesting entries from Graylog’s log: how many days since january 22 2023