Graylog Primer
This post applies to Graylog version 1.3.3.
Initial Server Install
This is straightforward: download the virtual appliance, import and start. That's it!
Graylog Collector
This post applies to version 0.4.2.
- Download graylog-collector-0.4.2.zip archieve and explode it in target directory
- Rename
collector.conf.example
to collector.conf
; Modify it according to your needs (there are plenty of samples in Graylog documentation)
- Install/start the service running
bin\graylog-collector-service.bat install GraylogCollector
and bin\graylog-collector-service.bat start GraylogCollector
Now we have a server side problem: by default there are two pre-installed inputs :appliance-gelf-udp
and appliance-syslog-udp
while the client Collector supports (for GELF at least) only TCP. So we have to create another input according to our configuration (port
mainly).
If everything worked according to the plan we should see now in the Search section our events and every second a nginx
sourced event (very annoying).
Server insights
Startup scripts
/opt/graylog/service
contains symbolic links to all stratup directories. In /etc/init/graylog-runsvdir.conf
there is executed exec /opt/graylog/embedded/bin/runsvdir-start
which in turn runs exec env - PATH=$PATH runsvdir -P /opt/graylog/service 'log:
.
Every directory pointed by the symbolic links mentioned before contains a run
script. For instance in /opt/graylog/sv/graylog-server/
we have
#!/bin/sh
exec 2>&1
umask 077
if [ -f "/opt/graylog/embedded/share/graylog/installation-source.sh" ]; then
. "/opt/graylog/embedded/share/graylog/installation-source.sh"
fi
export JAVA_HOME=/opt/graylog/embedded/jre
export GRAYLOG_SERVER_JAVA_OPTS="-Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"
# check if mongodb is up
timeout 600 bash -c "until curl -s http://127.0.0.1:27017; do sleep 1; done"
exec chpst -P -U graylog -u graylog /opt/graylog/embedded/bin/authbind $JAVA_HOME/bin/java $GRAYLOG_SERVER_JAVA_OPTS -jar -Dlog4j.configuration=file:///opt/graylog/conf/log4j.xml -Djava.library.path=/opt/graylog/server/lib/sigar/ -Dgraylog2.installation_source=${GRAYLOG_INSTALLATION_SOURCE:=unknown} /opt/graylog/server/graylog.jar server -f /opt/graylog/conf/graylog.conf
Logging
Logging is started through log\run
. See svloggelfd
documentation on github as well as linux svlogd
manual. Notice that UDP is used by svloggelfd
.
Actual logs are saved in /var/log/graylog/...
according to svlogd
rules while svloggelfd
sends all data to Graylog UDP input.
Sample log\run
content:
#!/bin/sh
exec /opt/graylog/embedded/bin/svloggelfd -H 127.0.0.1:12201 -s graylog-server -e | svlogd -tt /var/log/graylog/server
Disabling nginx Loging forward to Graylog
Just cahnge /opt/graylog/sv/nginx/log/run
to:
#!/bin/sh
#exec /opt/graylog/embedded/bin/svloggelfd -H 127.0.0.1:12201 -s nginx -e | svlogd -tt /var/log/graylog/nginx
exec svlogd -tt /var/log/graylog/nginx
and restart Graylog (see below)
Controllig Graylog from command line
graylog-ctl status
graylog-ctl stop
graylog-ctl start
Timezone
Use sudo date
to change the default settings for date/time (UTC+0).
Changing timezone :
- Edit /etc/timezone and change to the desired timezone (like Europe/Bucharest)
- Run sudo dpkg-reconfigure --frontend noninteractive tzdata
This is not enough; Graylog web interface will still disply events with time in Etc/UTC timezone.
So:
- Check the startup script for graylog-web (semething like
exec chpst -P -U graylog -u graylog /opt/graylog/web/bin/graylog-web-interface -Dconfig.file=/opt/graylog/conf/graylog-web-interface.conf -Dhttp.port=9000 -Dhttp.address=0.0.0.0 -Dpidfile.path=/var/opt/graylog/web.pid -Dlogger.file=/opt/graylog/conf/web-logger.xml
- Now edit the configuration file (
/opt/graylog/conf/graylog-web-interface.conf
) and change the timezone property according to your needs
- This might not be enough: admin user has a fixed UTC timezone configuration so you will have to create a new user and assign the desired timezone or none (so the default just configured before will be used)
Debugging
This is not about bugs but just inspecting the implementation code to clarify things not captured in official documentation
Server
- Change startup script (
/opt/graylog/sv/graylog-server/run
) to
#!/bin/sh
exec 2>&1
umask 077
if [ -f "/opt/graylog/embedded/share/graylog/installation-source.sh" ]; then
. "/opt/graylog/embedded/share/graylog/installation-source.sh"
fi
export JAVA_HOME=/opt/graylog/embedded/jre
# export GRAYLOG_SERVER_JAVA_OPTS="-Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"
export GRAYLOG_SERVER_JAVA_OPTS="-Xdebug -Xnoagent -Xrunjdwp:transport=dt_socket,server=y,suspend=n,address=4242 -Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"
# check if mongodb is up
timeout 600 bash -c "until curl -s http://127.0.0.1:27017; do sleep 1; done"
exec chpst -P -U graylog -u graylog /opt/graylog/embedded/bin/authbind $JAVA_HOME/bin/java $GRAYLOG_SERVER_JAVA_OPTS -jar -Dlog4j.configuration=file:///opt/graylog/conf/log4j.xml -Djava.library.path=/opt/graylog/server/lib/sigar/ -Dgraylog2.installation_source=${GRAYLOG_INSTALLATION_SOURCE:=unknown} /opt/graylog/server/graylog.jar server -f /opt/graylog/conf/graylog.conf
- Download tag 1.3.3 of graylog-server from github
- Open pom.xml in your favorite Java IDE
- Attach to <graylog-server-fqdn>, port 4242
- Happy inspecting!
Web interface
Debugging web interface is a little bit tricky since it is written in Scala-Play without a maven based project, so:
- Change the startup script (
/opt/graylog/sv/graylog-web/run
) to:
#!/bin/sh
exec 2>&1
umask 077
export JAVA_HOME=/opt/graylog/embedded/jre
rm -f /var/opt/graylog/web.pid
exec chpst -P -U graylog -u graylog /opt/graylog/web/bin/graylog-web-interface -jvm-debug 4243 -Dconfig.file=/opt/graylog/conf/graylog-web-interface.conf -Dhttp.port=9000 -Dhttp.address=0.0.0.0 -Dpidfile.path=/var/opt/graylog/web.pid -Dlogger.file=/opt/graylog/conf/web-logger.xml
- Notice the
-jvm-debug 4243
extra parameter
- Configure your favourite Java IDE to use the source path also from
graylog2-web-interface-1.3.3\app
(download tag 1.3.3 of deprecated web interface sources)
- Some functionality refers to classes in
graylog2-rest-client
module of graylog server project (like org.graylog2.restclient.lib.DateTools
containing method getUserTimeZone
).
- Search is performed in
renderSearch
method of controllers.SearchController
class.
- Render template is
graylog2-web-interface-1.3.3\app\views\search\index.scala.html
- Java script dealing with rendering dates according to the user's timezone is done in
app\assets\javascripts\moment-helper.js
while gl2UserTimeZone
is defined in app\views\partials\navbar.scala.html
# Graylog Primer
This post applies to Graylog version 1.3.3.

## Initial Server Install

This is straightforward: download the virtual appliance, import and start. That's it!

## Graylog Collector

This post applies to version 0.4.2.

* Download graylog-collector-0.4.2.zip archieve and explode it in target directory
* Rename `collector.conf.example` to `collector.conf`; Modify it according to your needs (there are plenty of samples in Graylog documentation)
* Install/start the service running `bin\graylog-collector-service.bat install GraylogCollector` and `bin\graylog-collector-service.bat start GraylogCollector`

Now we have a server side problem: by default there are two pre-installed inputs :`appliance-gelf-udp` and `appliance-syslog-udp` while the client Collector supports (for GELF at least) only TCP. So we have to create another input according to our configuration (`port` mainly).

If everything worked according to the plan we should see now in the Search section our events and every second a `nginx` sourced event (very annoying).

## Server insights

### Startup scripts

`/opt/graylog/service` contains symbolic links to all stratup directories. In `/etc/init/graylog-runsvdir.conf` there is executed `exec /opt/graylog/embedded/bin/runsvdir-start` which in turn runs `exec env - PATH=$PATH runsvdir -P /opt/graylog/service 'log:`.

Every directory pointed by the symbolic links mentioned before contains a `run` script. For instance in `/opt/graylog/sv/graylog-server/` we have

```bash
#!/bin/sh
exec 2>&1

umask 077

if [ -f "/opt/graylog/embedded/share/graylog/installation-source.sh" ]; then
    . "/opt/graylog/embedded/share/graylog/installation-source.sh"
fi

export JAVA_HOME=/opt/graylog/embedded/jre
export GRAYLOG_SERVER_JAVA_OPTS="-Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"

# check if mongodb is up
timeout 600 bash -c "until curl -s http://127.0.0.1:27017; do sleep 1; done"
exec chpst -P -U graylog -u graylog /opt/graylog/embedded/bin/authbind $JAVA_HOME/bin/java $GRAYLOG_SERVER_JAVA_OPTS -jar -Dlog4j.configuration=file:///opt/graylog/conf/log4j.xml -Djava.library.path=/opt/graylog/server/lib/sigar/ -Dgraylog2.installation_source=${GRAYLOG_INSTALLATION_SOURCE:=unknown} /opt/graylog/server/graylog.jar server -f /opt/graylog/conf/graylog.conf
```

### Logging

Logging is started through `log\run`. See `svloggelfd` documentation on github as well as linux `svlogd` manual. Notice that UDP is used by `svloggelfd`.

Actual logs are saved in `/var/log/graylog/...` according to `svlogd` rules while `svloggelfd` sends all data to Graylog UDP input.

Sample `log\run` content:
```bash
#!/bin/sh
exec /opt/graylog/embedded/bin/svloggelfd -H 127.0.0.1:12201 -s graylog-server -e | svlogd -tt /var/log/graylog/server
```

### Disabling nginx Loging forward to Graylog

Just cahnge `/opt/graylog/sv/nginx/log/run` to:
```bash
#!/bin/sh
#exec /opt/graylog/embedded/bin/svloggelfd -H 127.0.0.1:12201 -s nginx -e | svlogd -tt /var/log/graylog/nginx
exec svlogd -tt /var/log/graylog/nginx
```
and restart Graylog (see below)

### Controllig Graylog from command line

```bash
graylog-ctl status
graylog-ctl stop
graylog-ctl start
```

### Timezone

Use `sudo date` to change the default settings for date/time (UTC+0).

Changing timezone :
* Edit /etc/timezone and change to the desired timezone (like Europe/Bucharest)
* Run sudo dpkg-reconfigure --frontend noninteractive tzdata

This is not enough; Graylog web interface will still disply events with time in Etc/UTC timezone.

So:
* Check the startup script for graylog-web (semething like `exec chpst -P -U graylog -u graylog /opt/graylog/web/bin/graylog-web-interface -Dconfig.file=/opt/graylog/conf/graylog-web-interface.conf -Dhttp.port=9000 -Dhttp.address=0.0.0.0 -Dpidfile.path=/var/opt/graylog/web.pid -Dlogger.file=/opt/graylog/conf/web-logger.xml`
* Now edit the configuration file (`/opt/graylog/conf/graylog-web-interface.conf`) and change the timezone property according to your needs
* This might not be enough: admin user has a fixed UTC timezone configuration so you will have to create a new user and assign the desired timezone or none (so the default just configured before will be used)

### Debugging

This is not about bugs but just inspecting the implementation code to clarify things not captured in official documentation

#### Server

* Change startup script (`/opt/graylog/sv/graylog-server/run`) to
```bash
#!/bin/sh
exec 2>&1

umask 077

if [ -f "/opt/graylog/embedded/share/graylog/installation-source.sh" ]; then
    . "/opt/graylog/embedded/share/graylog/installation-source.sh"
fi

export JAVA_HOME=/opt/graylog/embedded/jre
# export GRAYLOG_SERVER_JAVA_OPTS="-Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"
export GRAYLOG_SERVER_JAVA_OPTS="-Xdebug -Xnoagent -Xrunjdwp:transport=dt_socket,server=y,suspend=n,address=4242 -Xms1g -Xmx1500m -XX:NewRatio=1 -XX:PermSize=128m -XX:MaxPermSize=256m -server -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackTraceInFastThrow"

# check if mongodb is up
timeout 600 bash -c "until curl -s http://127.0.0.1:27017; do sleep 1; done"
exec chpst -P -U graylog -u graylog /opt/graylog/embedded/bin/authbind $JAVA_HOME/bin/java $GRAYLOG_SERVER_JAVA_OPTS -jar -Dlog4j.configuration=file:///opt/graylog/conf/log4j.xml -Djava.library.path=/opt/graylog/server/lib/sigar/ -Dgraylog2.installation_source=${GRAYLOG_INSTALLATION_SOURCE:=unknown} /opt/graylog/server/graylog.jar server -f /opt/graylog/conf/graylog.conf
```
* Download tag 1.3.3 of graylog-server from github
* Open pom.xml in your favorite Java IDE
* Attach to <graylog-server-fqdn>, port 4242
* Happy inspecting!

#### Web interface

Debugging web interface is a little bit tricky since it is written in Scala-Play without a maven based project, so:

* Change the startup script (`/opt/graylog/sv/graylog-web/run`) to:
```bash
#!/bin/sh
exec 2>&1

umask 077
export JAVA_HOME=/opt/graylog/embedded/jre

rm -f /var/opt/graylog/web.pid
exec chpst -P -U graylog -u graylog /opt/graylog/web/bin/graylog-web-interface -jvm-debug 4243 -Dconfig.file=/opt/graylog/conf/graylog-web-interface.conf -Dhttp.port=9000 -Dhttp.address=0.0.0.0 -Dpidfile.path=/var/opt/graylog/web.pid -Dlogger.file=/opt/graylog/conf/web-logger.xml
```
* Notice the `-jvm-debug 4243` extra parameter
* Configure your favourite Java IDE to use the source path also from `graylog2-web-interface-1.3.3\app` (download tag 1.3.3 of deprecated web interface sources)
* Some functionality refers to classes in `graylog2-rest-client` module of graylog server project  (like `org.graylog2.restclient.lib.DateTools` containing method `getUserTimeZone`).
* Search is performed in `renderSearch` method of `controllers.SearchController` class.
* Render template is `graylog2-web-interface-1.3.3\app\views\search\index.scala.html`
* Java script dealing with rendering dates according to the user's timezone is done in `app\assets\javascripts\moment-helper.js` while `gl2UserTimeZone` is defined in `app\views\partials\navbar.scala.html`
No comments :
Post a Comment