Azure Ubuntu 16.04虚拟机部署Graylog后外部访问问题咨询
Hey there, let's walk through fixing this external access issue—since you've confirmed the service runs locally and curl works, we just need to address the network and configuration barriers blocking external traffic. Here's what to check step by step:
1. Update Graylog's Listening Configuration
Right now, your web_listen_uri and rest_listen_uri are bound to 127.0.0.1, which only allows connections from the VM itself. You need to adjust these to listen on all network interfaces (or the VM's private IP) to accept external requests:
- Open the Graylog config file with your editor of choice:
sudo nano /etc/graylog/server/server.conf - Update these two lines:
Usingweb_listen_uri = http://0.0.0.0:9000/ rest_listen_uri = http://0.0.0.0:12900/0.0.0.0tells Graylog to listen on all available network interfaces. Alternatively, you can use your VM's private Azure IP if you prefer more restrictive binding. - Save the file and restart the Graylog service:
sudo service graylog-server restart - Verify the service is still running:
sudo service graylog-server status
2. Open Port 9000 on Ubuntu's Local Firewall
Ubuntu 16.04 uses ufw by default—make sure it's allowing incoming traffic on port 9000 (the Graylog Web UI port):
- Allow the port:
sudo ufw allow 9000/tcp - Confirm the rule is active:
sudo ufw status
You should see a line like9000/tcp ALLOW Anywhere
If you're using iptables instead of ufw, run these commands to add and save the rule:
sudo iptables -A INPUT -p tcp --dport 9000 -j ACCEPT sudo iptables-save > /etc/iptables/rules.v4
3. Configure Azure Network Security Group (NSG)
This is the most common gotcha with Azure VMs—even if the local firewall is open, Azure's NSG blocks incoming traffic by default. Here's how to fix it:
- Go to the Azure Portal, navigate to your Ubuntu VM.
- Under the Networking tab, find the associated Network Security Group (NSG) and click into it.
- Select Inbound security rules > Add.
- Fill in the details:
- Source:
Any(or restrict to specific IPs if you want tighter security) - Source port ranges:
* - Destination:
Any - Destination port ranges:
9000 - Protocol:
TCP - Action:
Allow - Priority: Choose a number lower than the default "Deny All" rule (e.g., 100)
- Name:
Allow-Graylog-Web-9000
- Source:
- Save the rule.
4. Test External Access Correctly
Make sure you're using the right address to access the Web UI:
- Use your VM's public IP address (found in the Azure Portal under the VM's Overview tab) or its public DNS name.
- The correct URL should be:
http://<your-vm-public-ip>:9000
If It Still Doesn't Work
Check the Graylog server logs for any configuration errors:
tail -f /var/log/graylog-server/server.log
Look for lines about port binding failures or permission issues—this will help narrow down any remaining problems.
内容的提问来源于stack exchange,提问作者C.Nivs

