I understand now why you have this issue, your server can not keep up. If you trying to do this with one node, you need to increase these settings, this process the logs basically creates thread from the amount of CPU’s installed on that node. Its advisable for each buffer number = the CPU core on the Graylog server
This should and would indicate I have at least 12 CPU cores on my graylog server, this is stated in the Documentation. If you have the resource you could try to increase those, preferably the processbuffer_processors = 7 one.
ok. thanks for your advise @gsmith
if i decide to build a cluster,there could be more data than 350GB(maybe 600G or more because i have not set receivng all network devices),
so could you please give some advise about this cluster scale?3 garylog servers/mongdb/es or 5 garylog servers/mongdb/es or more?