opc40772 / pfsense-graylog

Pfsense Logs Parsed by Graylog
GNU General Public License v3.0
82 stars 117 forks source link

Had data pouring in from PFSense -> Graylog -> Grafana, then everything stopped. #13

Open SKFish opened 5 years ago

SKFish commented 5 years ago

When running the Query Inspector, data returns as normal. When looking at the dashboard, I get No Data Available in every panel or when letting the query go for more than 6 hours in history, I get a Failed To Parse Query when I pull up the Dashboard now. I had tons of firewall events coming in and all of a sudden they stopped. Please help? Green elasticsearch cluster, and all.

Please include this information:

What Grafana version are you using? 5.4.3

What datasource are you using? Elasticsearch

What OS are you running grafana on? Windows 10

What did you do? Had data coming in, and all stopped all of a sudden. Started to get Fauled to Parse Query in Dashboard, but the query inspector gets a complete status with tons of data for each panel

What was the expected result? Data showing up in the Dashboard

What happened instead? N/A, 0 Events, Failed to Parse Query, etc.

Query: iface:$iface AND src_ip:$src_ip

Query Inspector Response: response: Object responses:Array[1] 0:Object took:1 timed_out:false _shards:Object total:8 successful:8 skipped:0 failed:0 hits:Object total:0 max_score:0 hits:Array[0] aggregations:Object 2:Object buckets:Array[901] status:200