thanks savant: hey the XDELETE fails when i try to clear out old indexes, any tips
smola has quit
savant
stop the cluster, delete the files on disk, start the cluster
sqlnoob has quit
why does the delete fail
sounds like a question for #elasticsearch
wilmoore has quit
thumpba
savant: 'curl: (56) Recv failure: Connection reset by peer'
sqlnoob joined the channel
bodgix joined the channel
theharshest
anyone facing - "Failed to tls handshake with xxxxxx x509: certificate signed by unknown authority" ?
in logstash-forwarder nodes logs
sqlnoob has quit
thumpba
savant: i also have 2 dir /var/lib/elasticsearch/elasticsearch/nodes/0 and /var/lib/elasticsearch/logstash/ should i clear out both?
sqlnoob joined the channel
sqlnoob has quit
jerryitt joined the channel
sqlnoob joined the channel
sqlnoob has quit
chenryn has quit
WrathChylde joined the channel
dvogt has quit
dvogt joined the channel
blitzm has quit
VanderH0ff
hey, my logstash has stopped receiving logs, i restarted logstash, elasticsearch, and redis. so far nothing has helped. logstash logs are clean, redis is spitting out "Can't save in background: fork: Cannot allocate memory"
hoowe joined the channel
jjfalling_off joined the channel
jjfalling_off is now known as jjfalling
whack
theharshest: haven't fixed that yet, but should have something soon.
theharshest: re: cert issues, you might need to tell lsf about your CA
sqlnoob joined the channel
theharshest
whack: what param for that?
scalp42 joined the channel
ssl ca?
WrathChylde has quit
kimchy has quit
rcampbel3 joined the channel
kimchy joined the channel
whack: I'm getting that issue after setting "ssl ca"
davidski
VanderH0ff: redis is your problem then. Have you enabled vm overcommit?
VanderH0ff
yeah, just did, that solved part of the problem
now im trying to get my ids logs back
if i run logstash from the commandline it works fine
but i dont see the new logs in kibana
whack
theharshest: no idea, could be a bug, does your ssl ca file have all the chains for your CA?
ie, if the remote logstash is down, will it wait until it comes back up and send everything properly?
savant
yes
tombar has quit
rdobbs has quit
dvogt has quit
abestanw_ joined the channel
mrlesmithjr has quit
whack
abestanw_: yes, that's one of the goals of the project (reliable transport)
kimchy has quit
Flusher has quit
Flusher joined the channel
abestanway has quit
dvogt joined the channel
dvogt has quit
theMightyjD has quit
WrathChylde has quit
_Bryan_ joined the channel
WrathChylde joined the channel
dvogt joined the channel
MartinCleaver joined the channel
VanderH0ff
Im still having an issue trouble shooting my problem, i have a security onion ids, it sends the logs to my elk box via logstash in a redis list, it is sending, but i dont see them in kibana
is there any logs i need to check
cokegen has quit
sqlnoob has quit
kimchy joined the channel
cokegen joined the channel
abestanw_ has quit
glotzerhotze2014 joined the channel
hoowe has quit
glotzerhotze2014
hi folks, how can i compile logstash-forwarder for arm-architecture?