Best practice for graylog server

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.
Don’t forget to select tags to help index your topic!

1. Describe your incident:
request for best practice

2. Describe your environment:

  • OS Information:
    Linux
  • Package Version:
    5.2.0 graylog, mogodb 6, opensearch 2.12

32core cpu (8core*4thread)
64gb ram

  • Service logs, configurations, and environment variables:

3. What steps have you already taken to try and solve the problem?

4. How can the community help?
Hi guys, can anyone tell, which best practice would be best for my config?

i have graylog server 32cpu+64gb ram

also we have many cef sources, which generate about 30k events per second, and about 400gb per day

also, if you may - please give me correct config for graylog.cfg and maybe for java machine,

thanks in advance

Helpful Posting Tips: Tips for Posting Questions that Get Answers [Hold down CTRL and link on link to open tips documents in a separate tab]

Hi guys, can someone help me?

Hey @igoriceg

With that many logs per day , I would create a cluster.
https://go2docs.graylog.org/5-2/setting_up_graylog/multi-node_setup.html?Highlight=cluster

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.