Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Believe this is now broken in Graylog 3.x #14

Open
JSylvia007 opened this issue Mar 11, 2019 · 19 comments
Open

Believe this is now broken in Graylog 3.x #14

JSylvia007 opened this issue Mar 11, 2019 · 19 comments

Comments

@JSylvia007
Copy link

This is now broken due to changes in Graylog 3.x (and a critical support package dropping support for underscores).

Graylog2/graylog2-server#5704
thekrakken/java-grok#108
https://community.graylog.org/t/upgrade-of-graylog-from-2-5-x-to-3-x-results-in/9368

@Berzerker
Copy link

Agree, tried to get this working with 3.0, but I got stuck a few times. An update for 3.0 would be great.

@JSylvia007
Copy link
Author

I think it will begin working again when graylog 3.0.1 is released.

@devzwf
Copy link

devzwf commented Apr 5, 2019

with 3.0.1 released , is this work again ?

@JSylvia007
Copy link
Author

with 3.0.1 released , is this work again ?

Yup! I just updated without any changes and it starting working again.

@devzwf
Copy link

devzwf commented Apr 5, 2019

when trying to install content pack i have :

Error
Installing content pack failed with status: Error: cannot POST http://<IP Removed>:9600/api/system/content_packs/1057ded6-9d12-4c8e-8c0c-789a19ff61d2/0/installations (500). Could not install content pack with ID: 1057ded6-9d12-4c8e-8c0c-789a19ff61d2

@JSylvia007
Copy link
Author

Unfortunately, I needed to manually hack it to get it installed. Once it is installed, it works, but there were multiple changes that I needed to make. Unfortunately, it varies for each person's install of Graylog/Grafana, etc.

@devzwf
Copy link

devzwf commented Apr 5, 2019

where should i start ? :)
i will check the log

@JSylvia007
Copy link
Author

Good Luck my friend. I believe I looked at the graylog server log and started to fix the issues one-by-one in the JSON file and then attempted a re-import. I did this for EACH issue I came across. I remember it took me a whole weekend to get this sorted out and installed.

@devzwf
Copy link

devzwf commented Apr 5, 2019

Thanks i goona try and start with the lookup one , or i will install by 2.5 and them update we will see, will be fun :)

@devzwf
Copy link

devzwf commented Apr 14, 2019

just want to report back
I was able to make this work with graylog 3.0.1 + grafana 6.1.1+ elasticsearch 6.7.1
lots of poking and error try.... thanks to snapshot :)

I am not fully statisfied yet of the result (geoip still flaky) , still need some polish but it is working

@mauroprojetos
Copy link

Could someone share and file to work with graylog 3.1?

@derekslenk
Copy link

Could someone share and file to work with graylog 3.1?

Or point to the log files to look at?

@devzwf
Copy link

devzwf commented Apr 26, 2019

I will try to write the step i used (not easy , like i said was a lot of poking but i will give the basic direction)

@derekslenk
Copy link

I will try to write the step i used (not easy , like i said was a lot of poking but i will give the basic direction)

Many thanks

@CluelessTechnologist
Copy link

I will try to write the step i used (not easy , like i said was a lot of poking but i will give the basic direction)

Sorry to bother you but did you ever finish this updated step by step?

@CluelessTechnologist
Copy link

Can someone up the updated json file?

@ghost
Copy link

ghost commented Jun 28, 2019

Also trying to get this to work. @devzwf any pointers would be awesome!

@devopstales
Copy link

devopstales commented Jul 4, 2019

I created an updated version of this content pack for graylog3. You can find the instrucions HERE
@devzwf @mauroprojetos @derekslenk @CluelessTechnologist @Frogger72

@GraysonPeddie
Copy link

Please pardon me for bringing up this old thread but I cannot install pfSense content pack in Graylog 3 and I tried to click in the link for an updated version of the content pack but I got a 404 not found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

8 participants