Sign inSign up

phantomski/graylog

By phantomski

•Updated over 1 year ago

arm64v8.0 version (Raspberry Pi 4 / 400 / CM4, Odroid C2/C4/N2+) of official Graylog 4.3.15

Image
Monitoring & observability
2

10K+

phantomski/graylog repository overview

⁠Custom Graylog Docker image for arm64v8 (Raspberry Pi4) architecture

⁠What is this?

Latest stable version of official Graylog image that works on arm64 (ARMv8.0-A) instruction set chipsets, like those used on RaspberryPi 4 / 400 / CM4, with all required dependencies, is 4.3.15. That version is no longer maintained with the latest fixes and dependencies, especially for Java.

As an up-to-date alternative, I've provided this image. It is a custom arm64v8.0 compatible fork of official Graylog2/graylog-docker Docker repository built on/for Raspberry Pi 4 / Ubuntu 24.04.2 LTS in Docker 28.0.1 | containerd 1.7.25 | runc 1.2.4

It is probably compatible with other arm64 Arm Cortex architecture based systems on CPUs from Rockchip, Realtek, Broadcom, Synaptics, Amlogic and others (Odroid C2 | C4 | N2+, ROCK Pi 4 | S | E, Banana Pi BPI-M6 | BPI-M2S | BPI-M2 PRO | BPI-M5 | BPI-M4, Orange Pi 5 | 5B | 800, Pine A64+ | A64 LTS | ROCK64 | ROCKPro64 | PINE H64 | Quartz64, Asus TinkerBoard, Firefly ROC-RK3588S-PC, Apple M1/M2 Macs, Amazon EC2 on AWS Graviton, AMD Opteron A1100, Nvidia Tegra X1, Microsoft Project Volterra, etc.)

⁠GitHub repository

https://github.com/phantomski77/graylog-docker⁠

⁠GitHub fork README.md

docker/oss-arm64/README.md⁠

⁠Rationale

The reason for this custom build is that Graylog versions 5.0+ require MongoDB minimum version 5.0.7.

ARM Cortex-A76 chips like Broadcom BCM2712 in Raspberry Pi 5 / 500 / CM5 or Rockchip RK3588 in Radxa ROCK Pi 5B / Turing RK1 are ARMv8.2-A architecture. They can run those higher versions of MongoDB and thus Graylog without problem.

ARM Cortex-A72 chips like Broadcom BCM2711 in Raspberry Pi 4 / 400 / CM4 are ARMv8.0-A architecture.

Unfortunately MongoDB v4.4.18 is the last one that supports ARMv8.0-A, anything above (including v4.4.19) needs at least ARMv8.2-A or better. This limits Graylog to version 4.3.15.

As the Graylog 4.x versions are not regularly maintained anymore, to support Raspberry Pi 4 users, I'm trying to keep the 4.3.15 version as much up to date as possible myself. This includes latest Java versions and patches, upstream Graylog changes applicable for 4.x and the underlying Linux (Ubuntu) distribution used for the images.

⁠Bit of a history

For quite some time, the official graylog/graylog Docker images of versions 3 and 4 based on Graylog2/graylog-docker GitHub repo⁠ unfortunately didn't have specific arm64v8 builds, causing the obvious crashes while attempting to run amd64 / x86-64 images on this architecture. This was largely due to unavailability of the arch specific upstream base images for Debian and Java JVM and also lack of more enthusiastic support from the Graylog team. In order to use this great piece of software on very popular Raspberry Pi 4, I have modified the official Dockerfile and few supporting files with the latest available and compatible arm64v8 dependencies and removed some deprecated or incompatible JVM tags. The resulting images were running quite well and stable for a few years on my HomeLab IT setup and judging by number of pulls - for others as well.

The situation eventually changed and arm64 version became finally available directly from Graylog here on Docker Hub - although only as a separate build, still based by default on JVM 8, although JVM 11 and later higher versions were available as a build parameter option if you build images yourself.

Unfortunately with the introduction of Graylog 5.x it all changed again, as it relies on higher versions of MongoDB and OpenSearch. Raspberry 4 and similar platforms were left behind, again.

⁠Latest update (19/03/2025)

I have tried to build the Graylog image using the latest Java SE 23 JDK JRE 23.0.2+7 with latest Ubuntu 24.04.2 LTS both for Java and Graylog. Despite Graylog 4.x being oficially only provided with Java major versions 9 and later 11, version 23 runs without any issues, I might say even better, at least in terms of resources utilisation. It also provides more recent CVE and bug fixes, making the image more secure.

⁠Future

I am gradually moving to more modern arm64 systems (Apple Silicon, Raspberry Pi 5), so this might very likely be the last compliant version I'll be attempting to build. If you want to keep these updates coming, please kindly generate an Issue on GitHub⁠ and I'll do my best to respond.

It seems quite possible, that these manually created images will be the only way how to maintain Raspberry Pi specific edge versions of this project with reasonably current updates. MongoDB is irrevocably moving towards rPi incompatible ARMv8.2-A or higher instruction set - the limitation that used to be from 5.0 onwards, but they've now released patched v4.4.19 which has the same restriction. Most up to date combination of latest Graylog v5.x, OpenSearch v2.x and JDK v19.x thus seems increasingly less likely on ARMv8.0 as Graylog 5.x now mandates Mongo v5+. If that's the limitation you're facing as well, I'd suggest eventually migrating onto something with ARM Cortex-A75 or better, which support ARMv8.2-A instruction set, like the amazing Rockchip RK3588S or the new Raspberry Pi 5. Alternatively, move to amd64 / x64 platforms.

⁠Dependencies

⁠Necessary supporting containers
  • ElasticSearch 7.10.2 - Docker image docker.elastic.co/elasticsearch/elasticsearch-oss:7.10.2 (don't use higher versions than 7.10.x - see Graylog docs⁠)
    or preferably instead:
  • OpenSearch 1.3.20 - Docker image opensearchproject/opensearch:1.3.20 (don't use versions 2.x or higher as they're not compatible with Graylog 4.3.x - see Graylog ElasticSearch to OpenSearch migration guide⁠) \
  • MongoDB 4.4.18 - Docker image mongo:4.4.18 (don't use higher versions than 4.4.18 when you're running this on Raspberry Pi - MongoDB versions 4.4.19, 5.x, 6.x, 7.x and above require ARMv8.2-A instruction set, which rPi CPUs unfortunately don't support)
⁠In-built base images

Ubuntu 24.04.2 LTS Noble Numbat - Docker image ubuntu:noble
Java Eclipse Temurin SE 23 JDK JRE 23.0.2+7 - Docker image eclipse-temurin:23-jre-noble

⁠Quick start example

sudo docker network create -d bridge Graylog
sudo docker run --name graylog-mongo -v graylog-mongoDB:/data/db --net=Graylog -d mongo:4.4.18
sudo docker run --name graylog-elastic \
    -e "http.host=0.0.0.0" \
    -e "discovery.type=single-node" \
    -e "ES_JAVA_OPTS=-Xms512m -Xmx512m" \
    -v graylog-elastic:/usr/share/elasticsearch/data \
    --net=Graylog -d docker.elastic.co/elasticsearch/elasticsearch-oss:7.10.2
sudo docker run --name graylog -p 9000:9000 -p 12201:12201 -p 1514:1514 -p 5555:5555/udp \
    -v graylog-data:/usr/share/graylog/data \
    -e GRAYLOG_HTTP_EXTERNAL_URI="http://your_docker_host_url:9000/" \
    -e GRAYLOG_ROOT_PASSWORD_SHA2=8c6976e5b5410415bde908bd4dee15dfb167a9c873fc4bb8a81f6f2ab448a918 \
    --net=Graylog \
    --link graylog-mongo:mongo --link graylog-elastic:elasticsearch \
    -d phantomski/graylog

Compared with the Graylog's own example, this will in addition create new shared bridge Graylog network in Docker and connect all 3 containers to it. This is recommended method to facilitate communication between containers, unlike legacy --link feature that’s deprecated and will be eventually removed by Docker. It is also safer than using host bridge network. This example also creates persistent bind mount volumes to keep the data and configuration between future upgrades of all three containers. It will also setup default user admin with password admin in the config file. These are now a mandatory requirement, default as blank in the latest version graylog.conf config file. If you want to setup your own password, use this command first:

echo -n "Enter Password: " && head -1 </dev/stdin | tr -d '\n' | sha256sum | cut -d" " -f1

and then paste the resulting SHA-256 hash instead of default one in the command above for GRAYLOG_ROOT_PASSWORD_SHA2 variable. Alternatively, if you've the container running already (or want to change password later), stop the graylog container, change the SHA-256 hash in root_password_sha2 line in the graylog.conf configuration file in /usr/share/graylog/data container directory (mapped to /var/lib/docker/volumes/graylog-data/_data/config bind mount volume if using the example above in Ubuntu) and start the container again.

⁠More robust and advanced Docker Compose example

services:

  mongoDB:
    image: mongo:4.4.18
    container_name: graylog-mongo
    restart: unless-stopped
    environment:
      TZ: "Europe/London"
    volumes:
      - type: volume
        source: graylog-mongoDB
        target: /data/db
    networks:
      Graylog:
        aliases:
          - mongo

  opensearch:
    image: opensearchproject/opensearch:1.3.20
    container_name: graylog-opensearch
    restart: unless-stopped
    ports:
      - 9200:9200
      - 9600:9600
    environment:
      cluster.name: "opensearch-cluster"
      node.name: "opensearch-node1"
      OPENSEARCH_JAVA_OPTS: "-Xms1g -Xmx1g"
      DISABLE_INSTALL_DEMO_CONFIG: "true"
      DISABLE_SECURITY_PLUGIN: "true"
      bootstrap.memory_lock: "true"
      discovery.type: "single-node"
      http.host: "0.0.0.0"
      action.auto_create_index: "false"
      TZ: "Europe/London"
    ulimits:
      memlock:
        soft: -1
        hard: -1
      nofile:
        soft: 65536
        hard: 65536
    volumes:
      - /etc/timezone:/etc/timezone:ro
      - type: volume
        source: graylog-opensearch
        target: /usr/share/opensearch/data
    networks:
      Graylog:
        aliases:
          - opensearch

  graylog:
    image: phantomski/graylog:4.3.15-arm64-java23
    container_name: graylog
    restart: unless-stopped
    ports:
      # Graylog WebGUI and REST API:
      - 9001:9000
      # Syslog TCP:
      - 1514:1514
      # Syslog UDP:
      - 1514:1514/udp
      # GELF TCP:
      - 12201:12201
      # GELF UDP:
      - 12201:12201/udp
      # Syslog Raw/Plaintext UDP
      - 5555:5555/udp
      # Prometheus metrics
      - 9833:9833
    environment:
      GRAYLOG_NODE_ID_FILE: "/usr/share/graylog/data/config/node-id"
      GRAYLOG_HTTP_BIND_ADDRESS: "0.0.0.0:9000"
      GRAYLOG_HTTP_EXTERNAL_URI: "http://localhost:9000" # Change to your domain / local Graylog machine URL
      GRAYLOG_ELASTICSEARCH_HOSTS: "http://opensearch:9200"
      GRAYLOG_MONGODB_URI: "mongodb://mongo:27017/graylog"
      TZ: "Europe/London"
    entrypoint: "/usr/bin/tini -- wait-for-it opensearch:9200 --  /docker-entrypoint.sh"
    volumes:
      - type: volume
        source: graylog-data
        target: /usr/share/graylog/data
    networks:
      - Graylog
    depends_on:
      mongoDB:
        condition: "service_started"
      opensearch:
        condition: "service_started"

networks:
  Graylog: 
    name: Graylog
volumes:
  graylog-mongoDB:
    name: graylog-mongoDB
    external: true
  graylog-opensearch:
    name: graylog-opensearch
  graylog-data:
    name: graylog-data
    external: true

More installation and configuration details and example compose files in the Official Graylog documentation here⁠

⁠Please note

Until recently, standard Graylog was by default still using openjdk v8 (openjdk:8-jre-slim-buster). That means, some JVM options are also not available and were causing JVM fail to start or are obsolete. These are removed from Dockerfile:

  • -XX:+UseCGroupMemoryLimitForHeap
  • -XX:+UseConcMarkSweepGC
  • -XX:+CMSConcurrentMTEnabled
  • -XX:+CMSClassUnloadingEnabled
  • -XX:+UseParNewGC

Due to different JVM version used, the resulting image is not guaranteed to run well and is not yet thoroughly tested, although is fully functional and working according to official documentation. Official JVM 23 implementation tests are currently ongoing with good results.

Tag summary

Content type

Image

Digest

sha256:207c60b57…

Size

344.9 MB

Last updated

over 1 year ago

docker pull phantomski/graylog