Searches for messages in the last 5 minutes return nothing, while the "in/out msgs" at the top right shows messages are indeed coming in.
Should be able to view messages in the last 5 minutes.
Search in the last 5 minutes return nothing.
Updating?
I don't have definite steps to produce the issue but ill provide the issues and my actions that lead to the issue.
1) Graylog tried to rotate the index, to which it failed after elasticsearch status changed to red.
2) I then deleted an unassigned index in elasticsearch, restarted elasticsearch,mongodb, graylog in that order.
3) Restarted the Graylog server again after seeing the log Failed to index [29] messages. Please check the index error log in your web interface for the reason. Error: failure in bulk execution and multiple logs like [13]: index [graylog2_1], type [message], id [b00a3532-8d83-11e6-b532-005056984104], message [ClusterBlockException[blocked by: [FORBIDDEN/8/index write (api)];]]
4) Confirmed that logs are reaching the server, did a search, got nothing.
We are using GitHub issues for tracking bugs in Graylog itself, but this doesn't look like one. Please post this issue to our public mailing list or join the #graylog channel on freenode IRC.
Thank you!
@jalogisch I'm running into this as well, after changing rotation strategy and related settings. I think this (the problem I'm describing; not the same as described above, but seems related) is indeed a bug, and here is the right place to discuss, debug and fix it.
Currently, I'm using 2.3.1.
Workaround: In the webinterface:
System -> Indices -> Default index set -> Maintenance -> Rotate active write index
Should I open a new issue for this?
Most helpful comment
Workaround: In the webinterface:
Should I open a new issue for this?