Tuesday, March 1, 2016

Graylog series, part 1

Graylog Primer

This post applies to Graylog version 1.3.3.

Initial Server Install

This is straightforward: download the virtual appliance, import and start. That's it!

Graylog Collector

This post applies to version 0.4.2.

  • Download graylog-collector-0.4.2.zip archieve and explode it in target directory
  • Rename collector.conf.example to collector.conf; Modify it according to your needs (there are plenty of samples in Graylog documentation)
  • Install/start the service running bin\graylog-collector-service.bat install GraylogCollector and bin\graylog-collector-service.bat start GraylogCollector

Now we have a server side problem: by default there are two pre-installed inputs :appliance-gelf-udp and appliance-syslog-udp while the client Collector supports (for GELF at least) only TCP. So we have to create another input according to our configuration (port mainly).

If everything worked according to the plan we should see now in the Search section our events and every second a nginx sourced event (very annoying).

Server insights

Startup scripts

/opt/graylog/service contains symbolic links to all stratup directories. In /etc/init/graylog-runsvdir.conf there is executed exec /opt/graylog/embedded/bin/runsvdir-start which in turn runs exec env - PATH=$PATH runsvdir -P /opt/graylog/service 'log:.

Every directory pointed by the symbolic links mentioned before contains a run script. For instance in /opt/graylog/sv/graylog-server/ we have

#!/bin/sh
exec 2>&1

umask 077

if [ -f "/opt/graylog/embedded/share/graylog/installation-source.sh" ]; then
    . "/opt/graylog/embedded/share/graylog/installation-source.sh"
fi

export JAVA_HOME=/opt/graylog/embedded/jre
export GRAYLOG_SERVER_JAVA_OPTS="-Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"

# check if mongodb is up
timeout 600 bash -c "until curl -s http://127.0.0.1:27017; do sleep 1; done"
exec chpst -P -U graylog -u graylog /opt/graylog/embedded/bin/authbind $JAVA_HOME/bin/java $GRAYLOG_SERVER_JAVA_OPTS -jar -Dlog4j.configuration=file:///opt/graylog/conf/log4j.xml -Djava.library.path=/opt/graylog/server/lib/sigar/ -Dgraylog2.installation_source=${GRAYLOG_INSTALLATION_SOURCE:=unknown} /opt/graylog/server/graylog.jar server -f /opt/graylog/conf/graylog.conf

Logging

Logging is started through log\run. See svloggelfd documentation on github as well as linux svlogd manual. Notice that UDP is used by svloggelfd.

Actual logs are saved in /var/log/graylog/... according to svlogd rules while svloggelfd sends all data to Graylog UDP input.

Sample log\run content:

#!/bin/sh
exec /opt/graylog/embedded/bin/svloggelfd -H 127.0.0.1:12201 -s graylog-server -e | svlogd -tt /var/log/graylog/server

Disabling nginx Loging forward to Graylog

Just cahnge /opt/graylog/sv/nginx/log/run to:

#!/bin/sh
#exec /opt/graylog/embedded/bin/svloggelfd -H 127.0.0.1:12201 -s nginx -e | svlogd -tt /var/log/graylog/nginx
exec svlogd -tt /var/log/graylog/nginx

and restart Graylog (see below)

Controllig Graylog from command line

graylog-ctl status
graylog-ctl stop
graylog-ctl start

Timezone

Use sudo date to change the default settings for date/time (UTC+0).

Changing timezone :

  • Edit /etc/timezone and change to the desired timezone (like Europe/Bucharest)
  • Run sudo dpkg-reconfigure --frontend noninteractive tzdata

This is not enough; Graylog web interface will still disply events with time in Etc/UTC timezone.

So:

  • Check the startup script for graylog-web (semething like exec chpst -P -U graylog -u graylog /opt/graylog/web/bin/graylog-web-interface -Dconfig.file=/opt/graylog/conf/graylog-web-interface.conf -Dhttp.port=9000 -Dhttp.address=0.0.0.0 -Dpidfile.path=/var/opt/graylog/web.pid -Dlogger.file=/opt/graylog/conf/web-logger.xml
  • Now edit the configuration file (/opt/graylog/conf/graylog-web-interface.conf) and change the timezone property according to your needs
  • This might not be enough: admin user has a fixed UTC timezone configuration so you will have to create a new user and assign the desired timezone or none (so the default just configured before will be used)

Debugging

This is not about bugs but just inspecting the implementation code to clarify things not captured in official documentation

Server

  • Change startup script (/opt/graylog/sv/graylog-server/run) to
#!/bin/sh
exec 2>&1

umask 077

if [ -f "/opt/graylog/embedded/share/graylog/installation-source.sh" ]; then
    . "/opt/graylog/embedded/share/graylog/installation-source.sh"
fi

export JAVA_HOME=/opt/graylog/embedded/jre
# export GRAYLOG_SERVER_JAVA_OPTS="-Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"
export GRAYLOG_SERVER_JAVA_OPTS="-Xdebug -Xnoagent -Xrunjdwp:transport=dt_socket,server=y,suspend=n,address=4242 -Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"

# check if mongodb is up
timeout 600 bash -c "until curl -s http://127.0.0.1:27017; do sleep 1; done"
exec chpst -P -U graylog -u graylog /opt/graylog/embedded/bin/authbind $JAVA_HOME/bin/java $GRAYLOG_SERVER_JAVA_OPTS -jar -Dlog4j.configuration=file:///opt/graylog/conf/log4j.xml -Djava.library.path=/opt/graylog/server/lib/sigar/ -Dgraylog2.installation_source=${GRAYLOG_INSTALLATION_SOURCE:=unknown} /opt/graylog/server/graylog.jar server -f /opt/graylog/conf/graylog.conf
  • Download tag 1.3.3 of graylog-server from github
  • Open pom.xml in your favorite Java IDE
  • Attach to <graylog-server-fqdn>, port 4242
  • Happy inspecting!

Web interface

Debugging web interface is a little bit tricky since it is written in Scala-Play without a maven based project, so:

  • Change the startup script (/opt/graylog/sv/graylog-web/run) to:
#!/bin/sh
exec 2>&1

umask 077
export JAVA_HOME=/opt/graylog/embedded/jre

rm -f /var/opt/graylog/web.pid
exec chpst -P -U graylog -u graylog /opt/graylog/web/bin/graylog-web-interface -jvm-debug 4243 -Dconfig.file=/opt/graylog/conf/graylog-web-interface.conf -Dhttp.port=9000 -Dhttp.address=0.0.0.0 -Dpidfile.path=/var/opt/graylog/web.pid -Dlogger.file=/opt/graylog/conf/web-logger.xml
  • Notice the -jvm-debug 4243 extra parameter
  • Configure your favourite Java IDE to use the source path also from graylog2-web-interface-1.3.3\app (download tag 1.3.3 of deprecated web interface sources)
  • Some functionality refers to classes in graylog2-rest-client module of graylog server project (like org.graylog2.restclient.lib.DateTools containing method getUserTimeZone).
  • Search is performed in renderSearch method of controllers.SearchController class.
  • Render template is graylog2-web-interface-1.3.3\app\views\search\index.scala.html
  • Java script dealing with rendering dates according to the user's timezone is done in app\assets\javascripts\moment-helper.js while gl2UserTimeZone is defined in app\views\partials\navbar.scala.html
# Graylog Primer
This post applies to Graylog version 1.3.3.

## Initial Server Install

This is straightforward: download the virtual appliance, import and start. That's it!

## Graylog Collector

This post applies to version 0.4.2.

* Download graylog-collector-0.4.2.zip archieve and explode it in target directory
* Rename `collector.conf.example` to `collector.conf`; Modify it according to your needs (there are plenty of samples in Graylog documentation)
* Install/start the service running `bin\graylog-collector-service.bat install GraylogCollector` and `bin\graylog-collector-service.bat start GraylogCollector`

Now we have a server side problem: by default there are two pre-installed inputs :`appliance-gelf-udp` and `appliance-syslog-udp` while the client Collector supports (for GELF at least) only TCP. So we have to create another input according to our configuration (`port` mainly).

If everything worked according to the plan we should see now in the Search section our events and every second a `nginx` sourced event (very annoying).

## Server insights

### Startup scripts

`/opt/graylog/service` contains symbolic links to all stratup directories. In `/etc/init/graylog-runsvdir.conf` there is executed `exec /opt/graylog/embedded/bin/runsvdir-start` which in turn runs `exec env - PATH=$PATH runsvdir -P /opt/graylog/service 'log:`.

Every directory pointed by the symbolic links mentioned before contains a `run` script. For instance in `/opt/graylog/sv/graylog-server/` we have

```bash
#!/bin/sh
exec 2>&1

umask 077

if [ -f "/opt/graylog/embedded/share/graylog/installation-source.sh" ]; then
    . "/opt/graylog/embedded/share/graylog/installation-source.sh"
fi

export JAVA_HOME=/opt/graylog/embedded/jre
export GRAYLOG_SERVER_JAVA_OPTS="-Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"

# check if mongodb is up
timeout 600 bash -c "until curl -s http://127.0.0.1:27017; do sleep 1; done"
exec chpst -P -U graylog -u graylog /opt/graylog/embedded/bin/authbind $JAVA_HOME/bin/java $GRAYLOG_SERVER_JAVA_OPTS -jar -Dlog4j.configuration=file:///opt/graylog/conf/log4j.xml -Djava.library.path=/opt/graylog/server/lib/sigar/ -Dgraylog2.installation_source=${GRAYLOG_INSTALLATION_SOURCE:=unknown} /opt/graylog/server/graylog.jar server -f /opt/graylog/conf/graylog.conf
```

### Logging

Logging is started through `log\run`. See `svloggelfd` documentation on github as well as linux `svlogd` manual. Notice that UDP is used by `svloggelfd`.

Actual logs are saved in `/var/log/graylog/...` according to `svlogd` rules while `svloggelfd` sends all data to Graylog UDP input.

Sample `log\run` content:
```bash
#!/bin/sh
exec /opt/graylog/embedded/bin/svloggelfd -H 127.0.0.1:12201 -s graylog-server -e | svlogd -tt /var/log/graylog/server
```

### Disabling nginx Loging forward to Graylog

Just cahnge `/opt/graylog/sv/nginx/log/run` to:
```bash
#!/bin/sh
#exec /opt/graylog/embedded/bin/svloggelfd -H 127.0.0.1:12201 -s nginx -e | svlogd -tt /var/log/graylog/nginx
exec svlogd -tt /var/log/graylog/nginx
```
and restart Graylog (see below)

### Controllig Graylog from command line

```bash
graylog-ctl status
graylog-ctl stop
graylog-ctl start
```

### Timezone

Use `sudo date` to change the default settings for date/time (UTC+0).

Changing timezone :
* Edit /etc/timezone and change to the desired timezone (like Europe/Bucharest)
* Run sudo dpkg-reconfigure --frontend noninteractive tzdata

This is not enough; Graylog web interface will still disply events with time in Etc/UTC timezone.

So:
* Check the startup script for graylog-web (semething like `exec chpst -P -U graylog -u graylog /opt/graylog/web/bin/graylog-web-interface -Dconfig.file=/opt/graylog/conf/graylog-web-interface.conf -Dhttp.port=9000 -Dhttp.address=0.0.0.0 -Dpidfile.path=/var/opt/graylog/web.pid -Dlogger.file=/opt/graylog/conf/web-logger.xml`
* Now edit the configuration file (`/opt/graylog/conf/graylog-web-interface.conf`) and change the timezone property according to your needs
* This might not be enough: admin user has a fixed UTC timezone configuration so you will have to create a new user and assign the desired timezone or none (so the default just configured before will be used)

### Debugging

This is not about bugs but just inspecting the implementation code to clarify things not captured in official documentation

#### Server

* Change startup script (`/opt/graylog/sv/graylog-server/run`) to
```bash
#!/bin/sh
exec 2>&1

umask 077

if [ -f "/opt/graylog/embedded/share/graylog/installation-source.sh" ]; then
    . "/opt/graylog/embedded/share/graylog/installation-source.sh"
fi

export JAVA_HOME=/opt/graylog/embedded/jre
# export GRAYLOG_SERVER_JAVA_OPTS="-Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"
export GRAYLOG_SERVER_JAVA_OPTS="-Xdebug -Xnoagent -Xrunjdwp:transport=dt_socket,server=y,suspend=n,address=4242 -Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"

# check if mongodb is up
timeout 600 bash -c "until curl -s http://127.0.0.1:27017; do sleep 1; done"
exec chpst -P -U graylog -u graylog /opt/graylog/embedded/bin/authbind $JAVA_HOME/bin/java $GRAYLOG_SERVER_JAVA_OPTS -jar -Dlog4j.configuration=file:///opt/graylog/conf/log4j.xml -Djava.library.path=/opt/graylog/server/lib/sigar/ -Dgraylog2.installation_source=${GRAYLOG_INSTALLATION_SOURCE:=unknown} /opt/graylog/server/graylog.jar server -f /opt/graylog/conf/graylog.conf
```
* Download tag 1.3.3 of graylog-server from github
* Open pom.xml in your favorite Java IDE
* Attach to <graylog-server-fqdn>, port 4242
* Happy inspecting!

#### Web interface

Debugging web interface is a little bit tricky since it is written in Scala-Play without a maven based project, so:

* Change the startup script (`/opt/graylog/sv/graylog-web/run`) to:
```bash
#!/bin/sh
exec 2>&1

umask 077
export JAVA_HOME=/opt/graylog/embedded/jre

rm -f /var/opt/graylog/web.pid
exec chpst -P -U graylog -u graylog /opt/graylog/web/bin/graylog-web-interface -jvm-debug 4243 -Dconfig.file=/opt/graylog/conf/graylog-web-interface.conf -Dhttp.port=9000 -Dhttp.address=0.0.0.0 -Dpidfile.path=/var/opt/graylog/web.pid -Dlogger.file=/opt/graylog/conf/web-logger.xml
```
* Notice the `-jvm-debug 4243` extra parameter
* Configure your favourite Java IDE to use the source path also from `graylog2-web-interface-1.3.3\app` (download tag 1.3.3 of deprecated web interface sources)
* Some functionality refers to classes in `graylog2-rest-client` module of graylog server project  (like `org.graylog2.restclient.lib.DateTools` containing method `getUserTimeZone`).
* Search is performed in `renderSearch` method of `controllers.SearchController` class.
* Render template is `graylog2-web-interface-1.3.3\app\views\search\index.scala.html`
* Java script dealing with rendering dates according to the user's timezone is done in `app\assets\javascripts\moment-helper.js` while `gl2UserTimeZone` is defined in `app\views\partials\navbar.scala.html`

No comments :

Post a Comment