How to Install and Configure Graylog on CentOS Stream 9: Building a Centralized Log Management System

CentOS tutorial - IT technology blog
CentOS tutorial - IT technology blog

The Problem: The Nightmare of SSHing into Every Server to Troubleshoot

Your infrastructure is running on 10 servers: 3 Nginx web nodes, 2 backend API clusters, a PostgreSQL database, and 2 gateways. At 3 PM, users start complaining about persistent 502 errors during checkout. You find yourself opening a dozen terminal tabs simultaneously, typing tail -f /var/log/nginx/error.log on each machine to grep for request IDs. This process is both chaotic and prone to missing critical issues.

When your infrastructure scales to 30 or 50 servers, this manual approach completely falls apart. Without centralized logging, your Mean Time to Resolution (MTTR) can stretch from minutes into hours. You need to aggregate all log data into a single location and search it instantly with a single query.

Graylog Cluster Architecture

Graylog acts as a centralized data ingestion hub. The system collects logs from every corner of your infrastructure, parses structured fields, and stores them in an indexed data warehouse.

A complete Graylog cluster consists of three main components:

  • MongoDB: Stores system configurations, user information, alert streams, and dashboard metadata. It does not store actual log contents.
  • OpenSearch: The core engine for log storage and full-text search queries. The speed of filtering through millions of log lines directly depends on the amount of RAM allocated to OpenSearch.
  • Graylog Server: The central processing engine. This service receives logs from clients via Syslog/GELF/Beats, parses the incoming data, forwards it to OpenSearch, and serves the Web UI.

Step-by-Step Guide to Deploying Graylog on CentOS Stream 9

Step 1: Prepare the Environment and Install Java OpenJDK

Both Graylog and OpenSearch run on the JVM. On CentOS Stream 9, you can directly use OpenJDK 17 available in the default repository:

sudo dnf update -y
sudo dnf install -y java-17-openjdk-headless pwgen wget curl lsof

Step 2: Install MongoDB 6.0

Graylog 6.x requires MongoDB 6.0 or newer. Add the MongoDB repository configuration file:

cat <<EOF | sudo tee /etc/yum.repos.d/mongodb-org.repo
[mongodb-org-6.0]
name=MongoDB Repository
baseurl=https://repo.mongodb.org/yum/redhat/9/mongodb-org/6.0/x86_64/
gpgcheck=1
enabled=1
gpgkey=https://www.mongodb.org/static/pgp/server-6.0.asc
EOF

sudo dnf install -y mongodb-org
sudo systemctl daemon-reload
sudo systemctl enable --now mongod

Check the MongoDB service status using systemctl status mongod to ensure it is in the active (running) state.

Step 3: Install and Configure OpenSearch 2.x

Add the official OpenSearch repository:

cat <<EOF | sudo tee /etc/yum.repos.d/opensearch.repo
[opensearch-2.x]
name=OpenSearch 2.x Repository
baseurl=https://artifacts.opensearch.org/releases/bundle/opensearch/2.x/yum
gpgcheck=1
gpgkey=https://artifacts.opensearch.org/publickeys/opensearch.pgp
enabled=1
EOF

sudo dnf install -y opensearch

Open /etc/opensearch/opensearch.yml and configure it for a single-node setup:

cluster.name: graylog-cluster
node.name: node-1
path.data: /var/lib/opensearch
path.logs: /var/log/opensearch
network.host: 127.0.0.1
http.port: 9200
discovery.type: single-node
action.auto_create_index: false
plugins.security.disabled: true

For a server with 8GB of RAM, adjust the JVM heap size in /etc/opensearch/jvm.options to -Xms4g and -Xmx4g (roughly 50% of system RAM) to optimize server performance. Then start the service:

sudo systemctl daemon-reload
sudo systemctl enable --now opensearch

Step 4: Install and Configure Graylog Server

Install the Graylog 6.0 repository and package:

sudo rpm -Uvh https://packages.graylog2.org/repo/packages/graylog-6.0-repository_latest.rpm
sudo dnf install -y graylog-server

Graylog requires two secret keys to start up:

  • password_secret: Used to encrypt user session cookies.
  • root_password_sha2: The SHA-256 hash of the admin account password.

Quickly generate these two values via the terminal:

# Generate a random 96-character secret key
pwgen -N 1 -s 96

# Hash the admin password (replace AdminPassword@2026 with your own password)
echo -n "AdminPassword@2026" | sha256sum | cut -d" " -f1

Open /etc/graylog/server/server.conf and paste the corresponding values:

password_secret = <generated_pwgen_secret>
root_password_sha2 = <generated_sha256_hash>
http_bind_address = 0.0.0.0:9000

Save the file and enable Graylog:

sudo systemctl daemon-reload
sudo systemctl enable --now graylog-server

Step 5: Configure the Firewall and Verify the Web UI

Open port 9000 for the Web interface and port 1514 UDP for receiving logs from client machines using Firewalld:

sudo firewall-cmd --add-port=9000/tcp --permanent
sudo firewall-cmd --add-port=1514/udp --permanent
sudo firewall-cmd --reload

Open your browser and navigate to http://<SERVER_IP>:9000. Log in using the username admin and the plaintext password you hashed in Step 4.

Step 6: Create an Input and Configure Clients to Forward Logs

Configure a log ingestion input via the Graylog Web UI:

  1. Navigate to System > Inputs.
  2. Select Syslog UDP from the dropdown menu and click Launch new input.
  3. Enter Title: Linux Syslog Input, Port: 1514, Bind address: 0.0.0.0, then click Save.

Switch to the client servers you want to monitor. Add an rsyslog configuration to forward logs to the Graylog server:

echo "*.* @<GRAYLOG_SERVER_IP>:1514;RSYSLOG_SyslogProtocol23Format" | sudo tee /etc/rsyslog.d/50-graylog.conf
sudo systemctl restart rsyslog

Return to the Search tab in Graylog, and you will see log messages streaming in from the client in real time.

Conclusion

A centralized logging system frees you from the tedious routine of hunting for errors across individual terminal sessions. Alongside metrics visualized in Grafana, Graylog and OpenSearch ensure all logs—from authentication and kernel events to application errors—are neatly consolidated, ready for rapid troubleshooting and automated alerting via Telegram or Slack.

Share: