Every few days all our systems stop sending logs

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
User avatar
jmichaelson
Posts: 140
Joined: Wed Aug 23, 2023 1:02 pm

Re: Every few days all our systems stop sending logs

Post by jmichaelson »

Yeah that seems like a big problem with Logstash, and even though Elasticsearch is the big memory user, it does make me wonder if Logstash isn't running out of memory to use somehow.

As for supporting Centos 7, what you read is correct going forward. Centos 7 itself is going end of life on June 30th. I'd definitely recommend upgrading the system.

If you have a separate file system mounted under /usr/local/nagioslogserver/elasticsearch/data, you *should* be able to mount it on the new system after you get it installed. If it isn't, make a copy of the entire file system to use as a reference point later.

As always, keep a backup copy of everything just in case, of course. You *may* have to reach out to your CSM to deal with license activation.

If you're unable to successfully mount the data directory, keep it anyway. We will be shipping a new version of Nagios Log Server using Opensearch instead of Elasticsearch 1.7.6, and with that will come a migration tool to migrate your data from your existing instance, which will require that instance to be running.

Let me know if you have any problems with re-mounting the data, as I'm becoming quite familiar with the intricacies of it at the moment.
Please let us know if you have any other questions or concerns.

-Jason
User avatar
jmichaelson
Posts: 140
Joined: Wed Aug 23, 2023 1:02 pm

Re: Every few days all our systems stop sending logs

Post by jmichaelson »

Incidentally, I've opened up an internal issue to automatically create an alert for host freshness, instead of leaving it blank. I can't promise that we'll ever do anything about it but its there.
Please let us know if you have any other questions or concerns.

-Jason
ssunga
Posts: 39
Joined: Wed Aug 09, 2023 10:38 am

Re: Every few days all our systems stop sending logs

Post by ssunga »

dscrimpsher wrote: I noticed that the OS I am using is no longer on the supported list for NLS. The server OS is CentOS Linux release 7.9.2009. I wonder if I might be better off starting over. I am by no means a expert managing linux systems, but i do pretty well with what i have learned over the years and it also helps when there are good instructions to follow.
Is it possible to install a clean OS on the boot drive and then somehow reattach the /data drive when installing NLS? I would like to retain the historical data I already have in NLS if it is possible.

Hey @dscrimpsher,

If you're going through with migrating your previous data to a new server, the following resources are likely to be helpful:

Backing Up and Restoring-Migrating NLS 2024
https://answerhub.nagios.com/support/s/ ... 4-27fa9972

Migrating Nagios Log Server to a different Server
https://answerhub.nagios.com/support/s/ ... r-30aca6d0

The sections on snapshots and system backups would be particularly useful in your case, where you want to keep historical data but move to a non-deprecated OS.

Let us know if those weren't quite what you were looking for, or if there are other concerns.
Post Reply